Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
PentestingEverything preview

PentestingEverything

GitHubm14r41/pentestingeverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

api-securitycloud-securityctf+9
2.1k
1 day ago
shells preview

shells

GitHub4ndr34z/shells

Script for generating revshells

command-and-controlctfeducation+9
4871 year ago
CVE-2022-24227-updated preview

CVE-2022-24227-updated

GitHubcyber-wo0dy/cve-2022-24227-updated

CVE-2022-24227 [Updated]: BoltWire v8.00 vulnerable to "Stored Cross-site Scripting (XSS)"

ctfeducationexploitation+3
2 years ago
cheatengine-mcp-bridge preview

cheatengine-mcp-bridge

GitHubmiscusi-peek/cheatengine-mcp-bridge

Connect Cursor, Copilot & Claude AI directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using…

ai-assisted-reversingbinary-analysiscode-analysis+7
1.4k25 days ago
Research_Successful_Errors preview

Research_Successful_Errors

GitHubvladko312/research_successful_errors

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming…

code-analysisctfeducation+6
1226 months ago
machscope preview

machscope

GitHubsadopc/machscope

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

binary-analysiscode-analysisctf+8
1026 months ago
vulnrepro-benchmark preview

vulnrepro-benchmark

GitHubfarhadalimohammadi-dir/vulnrepro-benchmark

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

ai-securitycode-analysisctf+7
93 months ago
ReactOOPS-WriteUp preview

ReactOOPS-WriteUp

GitHubthestingr/reactoops-writeup

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

code-analysisctfeducation+8
78 months ago
wp2shell-Wordpress-TOWN preview

wp2shell-Wordpress-TOWN

GitHublucifer0xf/wp2shell-wordpress-town

Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining…

code-analysisctfeducation+3
21 month ago
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection preview

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

GitHubhunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

Proof-of-concept exploit for CVE-2026-58116 demonstrating remote code execution in LLaMA-Factory WebUI via trust_remote_code model path injection.…

code-analysisctfeducation+5
2 months ago
bordair-detector preview

bordair-detector

GitHubjosh-blythe/bordair-detector

Two-stage prompt-injection and jailbreak detector: regex gates plus a quantised DeBERTa-v3 ONNX classifier, with image, document, and audio support.…

adversarial-attackai-securitycode-analysis+5
1 month ago
wordpress-batch-rce-lab preview

wordpress-batch-rce-lab

GitHubzenithgenius/wordpress-batch-rce-lab

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.

code-analysisctfeducation+6
11 month ago
CVE-2025-11844-smolagents preview

CVE-2025-11844-smolagents

GitHubsparshbiswas-ai/cve-2025-11844-smolagents

Educational sandbox and dynamic proof-of-concept scanner for CVE-2025-11844 XPath injection in Hugging Face smolagents library, enabling local data…

code-analysisctfeducation+3
3 months ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
4 months ago
CVE-2025-55182-poc preview

CVE-2025-55182-poc

GitHubducducuc111/cve-2025-55182-poc

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution via prototype chain vulnerability in React Server Components.…

code-analysisctfeducation+5
9 months ago
CVE-2024-12877-Exploit preview

CVE-2024-12877-Exploit

GitHubsoltanali0/cve-2024-12877-exploit

Educational CVE-2024-12877 exploit demo for PHP Object Injection in GiveWP WordPress plugin. Includes root cause analysis, regex bypass techniques,…

code-analysisctfeducation+6
11 year ago
CVE-2024-21520-Demo preview

CVE-2024-21520-Demo

GitHubch4n3-yoon/cve-2024-21520-demo

Educational repository demonstrating XSS vulnerabilities in Django Rest Framework applications. Contains intentionally vulnerable code to teach…

code-analysisctfeducation+3
2 years ago
GOATCasino preview

GOATCasino

GitHubnccgroup/goatcasino

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

code-analysisctfeducation+3
1207 years ago
Previous123Next