Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
windows-api-function-cheatsheets preview

windows-api-function-cheatsheets

GitHub7etsuo/windows-api-function-cheatsheets

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

binary-analysiscurated-resourcesmalware-analysis+3
1.5k
1 year ago
CVE-2023-4357-Chrome-XXE preview

CVE-2023-4357-Chrome-XXE

GitHubxcanwin/cve-2023-4357-chrome-xxe

[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.

ctfcurated-resourceseducation+3
2301 year ago
TABPE preview

TABPE

GitHubonhexgroup/tabpe

A monthly Windows PE baseline dataset for Cyber security researchers

binary-analysiscurated-resourceseducation+2
243 months ago
smart-tree preview

smart-tree

GitHub8b-is/smart-tree

Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…

curated-resourceseducationgeneral-purpose-utilities+3
26915 days ago
BurpSuite-collections preview

BurpSuite-collections

GitHubmr-xn/burpsuite-collections

有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using…

curated-resourceseducationpenetration-testing+2
4.0k1 month ago
IntruderPayloads preview

IntruderPayloads

GitHub1n3/intruderpayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

curated-resourceseducationfuzzing+3
4.0k5 years ago
Kernelhub preview

Kernelhub

GitHubascotbe/kernelhub

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

curated-resourceseducationexploitation+4
3.2k3 years ago
windows-api-function-cheatsheets preview

windows-api-function-cheatsheets

GitHubpaddycahil/windows-api-function-cheatsheets

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

curated-resourceseducationmalware-analysis+3
1232 years ago
kin preview

kin

GitHubfirelock-ai/kin

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

ai-securitycode-analysiscurated-resources+4
647h 20m ago
WebKitGTK-DND-Fix preview

WebKitGTK-DND-Fix

GitHubsirredbeard/webkitgtk-dnd-fix

Private research and validation for WebKitGTK file DnD restore (CVE-2025-13947 follow-up)

curated-resourceseducationvulnerability-analysis+1
21 days ago
openclaw-defender preview

openclaw-defender

GitHubnightfullstar/openclaw-defender

Multi-layer security framework for AI agent ecosystems. Provides pre-installation skill auditing, file integrity monitoring, runtime protection, and…

ai-securitycode-analysiscurated-resources+8
37 months ago
SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit preview

SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit

GitHubsastraadiwiguna-purpleeliteteaming/sastra-adi-wiguna-cve-2026-21858-holistic-audit

Technical audit and reproduction of CVE-2026-21858, an n8n RCE chain exploiting Content-Type confusion for arbitrary file read, session forgery, and…

curated-resourceseducationexploitation+4
8 months ago
soc-analyst-hub preview

soc-analyst-hub

GitHubcross-samuel1/soc-analyst-hub

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

curated-resourceseducationincident-response+6
6 months ago
Bug_Bounty_writeups preview

Bug_Bounty_writeups

GitHubalexbieber/bug_bounty_writeups

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

curated-resourceseducationvulnerability-analysis+1
8504 years ago
Anxun-isoon preview

Anxun-isoon

GitHubsoufianetahiri/anxun-isoon

I-SOON/Anxun leak related stuff

curated-resourcesosintthreat-intelligence
3412 years ago
CVE-2021-1675 preview

CVE-2021-1675

GitHublaresllc/cve-2021-1675

CVE-2021-1675 Detection Info

curated-resourceseducationexploitation+4
2143 years ago
BLACKHAT_Asia2023 preview

BLACKHAT_Asia2023

GitHubmr-xn/blackhat_asia2023

Black Hat Asia 2023 PDF Public

curated-resourceseducationpapers-research
5813 years ago
DraculaOS preview

DraculaOS

GitHubemrekybs/draculaos

Dracula OS is a Linux operating system meticulously designed for OSINT (Open Source Intelligence) and Cyber ​​Intelligence missions.

curated-resourceseducationemail-harvesting+9
9710 months ago
Previous123Next