Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
67 results
screenpipe preview

screenpipe

GitHubscreenpipe/screenpipe

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

ctfcurated-resourceseducation+8
21.5k
1 day ago
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k3 days ago
Basileak preview

Basileak

GitHubowasp/basileak

Intentionally vulnerable LLM

ai-securityctfeducation+6
2819 days ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
720 days ago
oasis preview

oasis

GitHubkryptsec/oasis

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

ai-securityctfeducation+6
2921 days ago
Flutter-Reverse-Engineering-Labs preview

Flutter-Reverse-Engineering-Labs

GitHubbrnpl/flutter-reverse-engineering-labs

Hands-on challenges for learning how to reverse engineer Flutter applications.

android-securitybinary-analysisctf+6
5826 days ago
tryhackme-monikerlink-writeup preview

tryhackme-monikerlink-writeup

GitHubomarmahmoud1024/tryhackme-monikerlink-writeup

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

ctfeducationexploitation+4
1 month ago
windows-malware-behavioral-analysis preview

windows-malware-behavioral-analysis

GitHub0x0allenace/windows-malware-behavioral-analysis

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

digital-forensicsdynamic-analysis-sandboxingeducation+8
1 month ago
printnightmare-detection-mitigation-lab preview

printnightmare-detection-mitigation-lab

GitHubkaritamw/printnightmare-detection-mitigation-lab

Sanitised Windows security lab demonstrating Active Directory administration, host and network detection, and layered mitigation of CVE-2021-34527.

digital-forensicseducationidentity-access-management+5
1 month ago
cve-2021-41773-lab preview

cve-2021-41773-lab

GitHubkunalkhandelwal-dev/cve-2021-41773-lab

Educational FastAPI lab demonstrating CVE-2021-41773 directory traversal and local file inclusion, with a vulnerable server, patched code, and…

educationlabs-practicevulnerability-analysis+2
1 month ago
BoxPwnr preview

BoxPwnr

GitHub0ca/boxpwnr

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

ai-securityctfeducation+8
4501 month ago
CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh preview

CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh

GitHubrauljvc8/cve-2025-68616-detecting-and-patching-an-ssrf-in-weasyprint-with-wazuh

Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

educationincident-responseintrusion-detection+3
1 month ago
exim-rce-cve-2018-6789 preview

exim-rce-cve-2018-6789

GitHubmartinclauss/exim-rce-cve-2018-6789

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

binary-exploitationdebuggerseducation+3
111 month ago
redteam-ai-benchmark preview

redteam-ai-benchmark

GitLabtoxy4ny/redteam-ai-benchmark

Red Team AI Benchmark: Evaluating LLMs for authorized offensive-security tasks. Red Team AI Benchmark is a CLI model-evaluation benchmark. It…

ai-securityeducationlabs-practice+3
22 months ago
Triage-CVE-2021-44228-Log4Shell-Log4j- preview

Triage-CVE-2021-44228-Log4Shell-Log4j-

GitHubprobablysecure/triage-cve-2021-44228-log4shell-log4j-

Goal is to triage well known attack and learn how security teams quickly respond.

educationincident-responselabs-practice+1
2 months ago
Triage-CVE-2017-0144 preview

Triage-CVE-2017-0144

GitHubprobablysecure/triage-cve-2017-0144

Goal is to triage well known attacks and learn how security teams quickly respond.

educationincident-responselabs-practice+1
2 months ago
CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough preview

CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough

GitHubbenedictejepu/cve-2024-24945-nginx-rift---tryhackme-lab-walkthrough

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

binary-exploitationctfeducation+5
2 months ago
struts-uploader-vulnerability preview

struts-uploader-vulnerability

GitHubbaburkin/struts-uploader-vulnerability

Research of exploit options for CVE-2024-53667 and their remediation

educationexploitationlabs-practice+3
3 months ago
Previous1234Next