Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
17 results
CheatSheetHost preview

CheatSheetHost

GitHubjimmyader/cheatsheethost

A locally hosted page for cheat sheets. Currently being used for reverse engineering and hosted in labs so I can limit or forgo (lock down firewall)…

ctfcurated-resourcesdebuggers+3
155 months ago
How-To-Secure-A-Linux-Server preview

How-To-Secure-A-Linux-Server

GitHubimthenachoman/how-to-secure-a-linux-server

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

authenticationconfiguration-auditingcurated-resources+7
31.4k7 days ago
SSRF-Testing preview

SSRF-Testing

GitHubcujanovic/ssrf-testing

SSRF (Server Side Request Forgery) testing resources

cloud-securitycurated-resourceseducation+6
2.5k1 year ago
React2Shell-Library preview

React2Shell-Library

GitHubwebsecuritylabs/react2shell-library

A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as…

curated-resourceseducationexploitation+6
78 months ago
CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector preview

CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector

GitHubadityabhatt3010/cve-2025-59287-when-your-patch-server-becomes-the-attack-vector

CVE-2025-59287 — Critical unauthenticated RCE in Windows Server Update Services (WSUS) via unsafe deserialization of an AuthorizationCookie, enabling…

curated-resourceseducationexploitation+5
1010 months ago
CVE-2025-55182-Researching-process preview

CVE-2025-55182-Researching-process

GitHubcybersecurity-enthusiasts-ce/cve-2025-55182-researching-process

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

curated-resourceseducationexploitation+6
4 months ago
CVE-2025-55182-Researching-process preview

CVE-2025-55182-Researching-process

GitHubtechwithorgito/cve-2025-55182-researching-process

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

curated-resourceseducationexploitation+6
3 months ago
susvibes-jupyter-server-cve-2026-35397 preview

susvibes-jupyter-server-cve-2026-35397

GitHubhiteshgorana/susvibes-jupyter-server-cve-2026-35397

Benchmark task for reimplementing a masked path-resolution fix in Jupyter Server, with functional and hidden security tests to evaluate…

code-analysiscurated-resourceseducation+3
4 months ago
awesome-malware-analysis preview

awesome-malware-analysis

GitHubrshipp/awesome-malware-analysis

Defund the Police.

curated-resourceseducationforensics+10
14.2k2 years ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

adversarial-attackai-securitycurated-resources+6
1.5k1 day ago
misp-galaxy preview

misp-galaxy

GitHubmisp/misp-galaxy

Clusters and elements to attach to MISP events or attributes (like threat actors)

adversarial-attackcurated-resourcesioc-management+5
6392 days ago
blind-ssrf-chains preview

blind-ssrf-chains

GitHubassetnote/blind-ssrf-chains

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

cloud-securitycurated-resourceseducation+5
9914 years ago
shodan preview

shodan

GitHublothos612/shodan

Shodan Dorks

curated-resourcesdatabase-securityinformation-gathering+7
5953 years ago
pentest-pivoting preview

pentest-pivoting

GitHubt3l3machus/pentest-pivoting

A compact guide to network pivoting for penetration testings / CTF challenges.

ctfcurated-resourceseducation+5
2272 years ago
RSC-Detect-CVE-2025-55182 preview

RSC-Detect-CVE-2025-55182

GitHubvijay-shirhatti/rsc-detect-cve-2025-55182

RSC Detect CVE 2025 55182

curated-resourceseducationinformation-gathering+3
218 months ago
CVE-2026-50522 preview

CVE-2026-50522

GitHubchpratik/cve-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

curated-resourceseducationincident-response+3
1 month ago
Writing-Sample-1 preview

Writing-Sample-1

GitHubtpower2112/writing-sample-1

CVE-2021-44228 Log4j Summary

configuration-auditingcurated-resourceseducation+3
13 years ago