Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
80.3k
16 days ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

cloud-securityctfcurated-resources+10
27.0k1 month ago
tbhm preview

tbhm

GitHubjhaddix/tbhm

Curated methodology and resource collection for web application bug bounty hunting, covering reconnaissance, vulnerability analysis, and exploitation…

curated-resourceseducationlearning-paths-courses+4
4.4k3 years ago
Web-Security-Learning preview

Web-Security-Learning

GitHubchybeta/web-security-learning

Curated learning path for web security, covering SQL injection, XSS, CSRF, SSRF, XXE, SSTI, and file inclusion with practical examples and CTF…

ctfcurated-resourceseducation+5
4.3k5 years ago
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

binary-exploitationcurated-resourceseducation+9
3.9k7 months ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

Curated cybersecurity learning library with tutorials, mindmaps, vulnerable code snippets, and methodology breakdowns across web pentesting, bug…

authentication-authorizationcurated-resourceseducation+7
5464 years ago
agent-skills preview

agent-skills

GitHubelastic/agent-skills

Curated library of AI agent skills for Elasticsearch, Kibana, Observability, and Security. Teaches agents correct API usage, cloud management, alert…

api-securityapi-security-testingcloud-infrastructure-security+6
5551 month ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
402 days ago
50-Days-Of-SQLi preview

50-Days-Of-SQLi

GitHubarpeetrathii/50-days-of-sqli

Learning and hunting SQL injection bugs for 50 continuous days

curated-resourceseducationlabs-practice+4
754 years ago
BSCP-EXAM-GUIDE-BY-N3OARI-2026 preview

BSCP-EXAM-GUIDE-BY-N3OARI-2026

GitHubn3oari/bscp-exam-guide-by-n3oari-2026

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

curated-resourceseducationlabs-practice+3
2814 days ago
OWASP-WSTG-Rag preview

OWASP-WSTG-Rag

GitHubzilbonn/owasp-wstg-rag

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

ai-securityapi-security-testingauthentication+8
228 months ago
CVE-2026-3854-lab preview

CVE-2026-3854-lab

GitHubroyaleybovich/cve-2026-3854-lab

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

ctfeducationexploitation+4
1021 days ago
CVE-2018-4416-exploit preview

CVE-2018-4416-exploit

GitHuberupmi/cve-2018-4416-exploit

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

binary-exploitationeducationexploitation+4
102 years ago
security-writeups preview

security-writeups

GitHubalzeaty1/security-writeups

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

ctfeducationlabs-practice+5
24 days ago
TCL-xss-Labs preview

TCL-xss-Labs

GitHubthe-cyber-ledger/tcl-xss-labs

An interactive, self-hosted XSS training platform with 33 progressively harder challenges

ctfeducationlabs-practice+5
15 months ago
CVE-2019-15588 preview

CVE-2019-15588

GitHubexp-docs/cve-2019-15588

Educational lab environment demonstrating CVE-2019-15588 RCE command injection vulnerability for hands-on exploitation practice and learning.

educationexploitationlearning-paths-courses+2
3 years ago
Juiceshopgl preview

Juiceshopgl

GitLabmbrandner-group/juiceshopgl

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

ctfeducationlabs-practice+5
1 year ago
Burp-Suite-Certified-Practitioner-Exam-Study preview

Burp-Suite-Certified-Practitioner-Exam-Study

GitHubbotesjuan/burp-suite-certified-practitioner-exam-study

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

curated-resourceseducationinformation-gathering+7
1.5k6 days ago
Previous12Next