Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1163 results
Zerodapi preview

Zerodapi

GitHub0dai-ml/zerodapi

0dAPI Official Docs

ai-securityeducationexploit-frameworks+5
12 years ago
Dejavu preview

Dejavu

GitHubbhdresh/dejavu

DejaVU - Open Source Deception Framework

cloud-securitydefensive-toolsids-ips-evasion+7
4331 year ago
reverse-shell-generator preview

reverse-shell-generator

GitHub0dayctf/reverse-shell-generator

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

ctfexploitationpayload-development+6
4.1k4 months ago
training-security-awareness preview

training-security-awareness

GitHubransomleak/training-security-awareness

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

ai-securityeducationemail-security+5
1841 month ago
WebGoat preview

WebGoat

GitHubwebgoat/webgoat

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

ctfeducationlabs-practice+4
9.3k19 days ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubeqstlab/cve-2026-33017

Langflow RCE

code-analysiseducationexploitation+3
915 days ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubdungsocool/cve-2024-23897

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

educationexploitationlabs-practice+2
1 month ago
loboguara preview

loboguara

GitHubolivsec/loboguara

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…

data-exfiltrationdns-subdomain-enumerationinformation-gathering+6
731 year ago
CVE-2025-57819-POC preview

CVE-2025-57819-POC

GitHubneobee714/cve-2025-57819-poc

FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

code-analysiseducationexploitation+2
1 month ago
pentestagent preview

pentestagent

GitHubgh05tcrew/pentestagent

AI agent framework for black-box security testing with autonomous multi-agent orchestration, built-in pentesting tools, and MCP integration for bug…

ai-securityctfeducation+8
3.0k5 days ago
wp2shell preview

wp2shell

GitHubcrypto-cat/wp2shell

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

code-analysiseducationexploitation+2
31 month ago
Bad secure rails app preview

Bad secure rails app

GitLabvivian.maes/bad-secure-rails-app
code-analysiseducationmisconfiguration+3
1 month ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
9237 months ago
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
51413 days ago
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k17 days ago
CVE-2026-62183 preview

CVE-2026-62183

GitHubnicpwns/cve-2026-62183

Apache Syncope: User self-service privilege escalation

code-analysiseducationexploitation+3
11 month ago
sprig-mvc-demo-patch preview

sprig-mvc-demo-patch

GitHubfirst-roman/sprig-mvc-demo-patch

This demo application partially covers the vulnerability CVE-2024-38828

educationmisconfigurationvulnerability-analysis+1
1 year ago
awesome-ctf-resources preview

awesome-ctf-resources

GitHubdevploit/awesome-ctf-resources

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

cryptographyctfcurated-resources+6
7912 months ago
Previous12…65Next