Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
awesome-ctf — CTF 框架、库、资源和软件精选列表 | Kitploit
工具/GitHubGitHub/apsdehal/awesome-ctf
漏洞利用逆向工程取证分析Web安全密码学CTF渗透测试学习与教育精选资源
GitHubapsdehal/awesome-ctf

awesome-ctf

CTF 框架、库、资源和软件精选列表

查看仓库
11.7k1.6k6年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

Awesome CTF Build Status Awesome

精心整理的 夺旗赛 (CTF) 框架、库、资源、软件和教程列表。本列表旨在帮助初学者和经验丰富的CTF玩家在一个地方找到与CTF相关的所有内容。

贡献

请先快速查阅 贡献指南。

如果你知道某个工具未在此列出,欢迎提交拉取请求。

为什么?

收集并记住CTF中使用的所有工具需要时间。本仓库帮助将这些分散的工具集中在一个地方。

目录

  • Awesome CTF

    • 创建
      • 取证
      • 平台
      • 隐写
      • Web
    • 解决
      • 攻击
      • 暴力破解
      • 密码学
      • 漏洞利用
      • 取证
      • 网络
      • 逆向
      • 服务
      • 隐写
      • Web
  • 资源

    • 操作系统
    • 入门包
    • 教程
    • 战争游戏
    • 网站
    • Wiki
    • 题解集合

创建

用于创建CTF挑战的工具

  • Kali Linux CTF Blueprints - 关于构建、测试和自定义你自己的夺旗赛挑战的在线书籍。

取证

用于创建取证挑战的工具

  • Dnscat2 - 通过DNS进行主机通信。
  • Kroll Artifact Parser and Extractor (KAPE) - 分流程序。
  • Magnet AXIOM - 以工件为中心的DFIR工具。
  • Registry Dumper - 转储你的注册表。

平台

可用于托管CTF的项目

  • CTFd - 来自ISISLab(NYU Tandon)的托管Jeopardy风格CTF的平台。
  • echoCTF.RED - 开发、部署和维护你自己的CTF基础设施。
  • FBCTF - 来自Facebook的托管夺旗赛竞赛的平台。
  • Haaukins - 一个高度可访问且自动化的安全教育虚拟化平台。
  • HackTheArch - CTF计分平台。
  • Mellivora - 用PHP编写的CTF引擎。
  • MotherFucking-CTF - 糟糕的轻量级CTF托管平台。无需JS。
  • NightShade - 一个简单的安全CTF框架。
  • OpenCTF - 盒中CTF。最少设置要求。
  • PicoCTF - 用于运行picoCTF的平台。托管任何CTF的绝佳框架。
  • PyChallFactory - 用于创建/管理/打包Jeopardy风格CTF挑战的小型框架。
  • RootTheBox - 黑客游戏(CTF计分板与游戏管理器)。
  • Scorebot - 来自Legitbs(Defcon)的CTF平台。
  • SecGen - 安全场景生成器。创建随机易受攻击的虚拟机。

隐写

用于创建隐写挑战的工具

请查看解决部分的隐写。

Web

用于创建Web挑战的工具

JavaScript混淆器

  • Metasploit JavaScript Obfuscator
  • Uglify

解决

用于解决CTF挑战的工具

攻击

用于执行各种攻击的工具

  • Bettercap - 执行中间人攻击(MITM)的框架。
  • Yersinia - 攻击第2层的各种协议。

密码学

用于解决密码学挑战的工具

  • CyberChef - 用于分析和解码数据的Web应用。
  • FeatherDuster - 一个自动化的模块化密码分析工具。
  • Hash Extender - 一个用于执行哈希长度扩展攻击的实用工具。
  • padding-oracle-attacker - 一个用于执行填充Oracle攻击的CLI工具。
  • PkCrack - 一个用于破解PkZip加密的工具。
  • QuipQuip - 一个在线破解替换密码或维吉尼亚密码(无密钥)的工具。
  • RSACTFTool - 一个使用各种攻击恢复RSA私钥的工具。
  • RSATool - 在已知p和q的情况下生成私钥。
  • XORTool - 一个分析多字节XOR密码的工具。

暴力破解器

用于各种暴力破解(密码等)的工具

  • Hashcat - 密码破解器
  • Hydra - 一个并行化的登录破解器,支持多种攻击协议
  • John The Jumbo - John the Ripper的社区增强版本。
  • John The Ripper - 密码破解器。
  • Nozzlr - Nozzlr是一个真正模块化且对脚本友好的暴力破解框架。
  • Ophcrack - 基于彩虹表的Windows密码破解器。
  • Patator - Patator是一个多用途暴力破解器,采用模块化设计。
  • Turbo Intruder - Burp Suite扩展,用于发送大量HTTP请求。

漏洞利用

用于解决漏洞利用挑战的工具

  • DLLInjector - 在进程中注入DLL。
  • libformatstr - 简化格式化字符串漏洞利用。
  • Metasploit - 渗透测试软件。
    • 速查表
  • one_gadget - 一个用于查找单个gadget execve('/bin/sh', NULL, NULL) 调用的工具。
    • gem install one_gadget
  • Pwntools - 用于编写漏洞利用的CTF框架。
  • Qira - QEMU交互式运行时分析器。
  • ROP Gadget - ROP漏洞利用框架。
  • V0lt - 安全CTF工具包。

取证

用于解决取证挑战的工具

  • Aircrack-Ng - 破解802.11 WEP和WPA-PSK密钥。
    • apt-get install aircrack-ng
  • Audacity - 分析声音文件(mp3, m4a等)。
    • apt-get install audacity
  • Bkhive and Samdump2 - 转储SYSTEM和SAM文件。
    • apt-get install samdump2 bkhive
  • CFF Explorer - PE编辑器。
  • Creddump - 转储Windows凭据。
  • DVCS Ripper - 撕取Web可访问的(分布式)版本控制系统。
  • Exif Tool - 读取、写入和编辑文件元数据。
  • Extundelete - 用于从可挂载映像恢复丢失的数据。
  • Fibratus - 用于探索和跟踪Windows内核的工具。
  • Foremost - 使用标头提取特定类型的文件。
    • apt-get install foremost
  • Fsck.ext4 - 用于修复损坏的文件系统。
  • Malzilla - 恶意软件搜寻工具。
  • NetworkMiner - 网络取证分析工具。
  • PDF Streams Inflater - 查找并提取PDF文件中压缩的zlib文件。
  • - 验证PNG的完整性,并以人类可读的形式转储所有块级信息。

注册表查看器

  • OfflineRegistryView - 一个简单的Windows工具,允许你从外部驱动器读取脱机注册表文件,并以.reg文件格式查看所需的注册表项。
  • Registry Viewer® - 用于查看Windows注册表。

网络

用于解决网络挑战的工具

  • Masscan - 大规模IP端口扫描器,TCP端口扫描器。
  • Monit - 一个Linux工具,用于检查网络上的主机(以及其他非网络活动)。
  • Nipe - Nipe是一个使Tor网络成为默认网关的脚本。
  • Nmap - 一个开源网络发现和安全审计工具。
  • Wireshark - 分析网络转储。
    • apt-get install wireshark
  • Zeek - 一个开源网络安全监控器。
  • Zmap - 一个开源网络扫描器。

逆向

用于解决逆向挑战的工具

  • Androguard - 逆向工程Android应用程序。
  • Angr - 平台无关的二进制分析框架。
  • Apk2Gold - 又一个Android反编译器。
  • ApkTool - Android反编译器。
  • Barf - 二进制分析与逆向工程框架。
  • Binary Ninja - 二进制分析框架。
  • BinUtils - 二进制工具集合。
  • BinWalk - 分析、逆向工程和提取固件映像。
  • Boomerang - 将x86/SPARC/PowerPC/ST-20二进制文件反编译为C。
  • ctf_import – 跨平台运行去除符号的二进制文件的基本函数。
  • cwe_checker - cwe_checker在二进制可执行文件中查找易受攻击的模式。
  • demovfuscator - 一个正在进行中的、用于解除movfuscated二进制文件混淆的工具。
  • Frida - 动态代码注入。
  • GDB - GNU项目调试器。
  • GEF - GDB插件。
  • Ghidra - 开源逆向工程工具套件。类似于IDA Pro。
  • Hopper - 用于OSX和Linux的逆向工程工具(反汇编器)。
  • IDA Pro - 最常用的逆向工程软件。
  • Jadx - 反编译Android文件。
  • Java Decompilers - 一个用于Java和Android APK的在线反编译器。
  • Krakatau - Java反编译器和反汇编器。
  • Objection - 运行时移动设备探索。
  • PEDA - GDB插件(仅支持python2.7)。

JavaScript反混淆器

  • Detox - 一个JavaScript恶意软件分析工具。
  • Revelo - 分析混淆的JavaScript代码。

SWF分析器

  • RABCDAsm - 实用工具集合,包括ActionScript 3汇编器/反汇编器。
  • Swftools - 用于处理SWF文件的实用工具集合。
  • Xxxswf - 一个用于分析Flash文件的Python脚本。

服务

互联网上可用的各种有用服务

  • CSWSH - 跨站WebSocket劫持测试器。
  • Request Bin - 允许你检查发送到特定URL的HTTP请求。

隐写

用于解决隐写挑战的工具

  • AperiSolve - Aperi'Solve是一个对图像进行层分析的平台(开源)。
  • Convert - 在格式间转换图像并应用滤镜。
  • Exif - 显示JPEG文件中的EXIF信息。
  • Exiftool - 读取和写入文件中的元信息。
  • Exiv2 - 图像元数据操作工具。
  • Image Steganography - 将文本和文件嵌入图像中,可选加密。易于使用的UI。
  • Image Steganography Online - 这是一个客户端的JavaScript工具,用于将图像隐写地隐藏在另一个图像的低位中。
  • ImageMagick - 用于操作图像的工具。
  • Outguess - 通用隐写工具。
  • Pngtools - 用于与PNG相关的各种分析。
    • apt-get install pngtools
  • SmartDeblur - 用于去模糊和修复失焦图像。
  • Steganabara - 用Java编写的隐写分析工具。
  • SteganographyOnline - 在线隐写编码器和解码器。
  • Stegbreak - 对JPG图像发起暴力字典攻击。
  • StegCracker - 用于发现文件中隐藏数据的隐写暴力破解工具。
  • stegextract - 检测图像中的隐藏文件和文本。
  • Steghide - 将数据隐藏在各种类型的图像中。
  • StegOnline - 执行广泛的图像隐写操作,例如隐藏/揭示隐藏在比特中的文件(开源)。
  • Stegsolve - 对图像应用各种隐写技术。

Web

用于解决Web挑战的工具

  • BurpSuite - 一个用于测试网站安全性的图形化工具。
  • Commix - 自动化的全能OS命令注入和利用工具。
  • Hackbar - 用于轻松进行Web漏洞利用的Firefox插件。
  • OWASP ZAP - 拦截代理,用于重放、调试和模糊HTTP请求和响应。
  • Postman - 用于调试网络请求的Chrome扩展。
  • Raccoon - 一个高性能的进攻性安全工具,用于侦察和漏洞扫描。
  • SQLMap - 自动SQL注入和数据库接管工具。 pip install sqlmap
  • W3af - Web Application Attack and Audit Framework.
  • XSSer - Automated XSS testor.

Resources

Where to discover about CTF

Operating Systems

Penetration testing and security lab Operating Systems

  • Android Tamer - Based on Debian.
  • BackBox - Based on Ubuntu.
  • BlackArch Linux - Based on Arch Linux.
  • Fedora Security Lab - Based on Fedora.
  • Kali Linux - Based on Debian.
  • Parrot Security OS - Based on Debian.
  • Pentoo - Based on Gentoo.
  • URIX OS - Based on openSUSE.
  • Wifislax - Based on Slackware.

Malware analysts and reverse-engineering

  • Flare VM - Based on Windows.
  • REMnux - Based on Debian.

Starter Packs

Collections of installer scripts, useful tools

  • CTF Tools - Collection of setup scripts to install various security research tools.
  • LazyKali - A 2016 refresh of LazyKali which simplifies install of tools and configuration.

Tutorials

Tutorials to learn how to play CTFs

  • CTF Field Guide - Field Guide by Trails of Bits.
  • CTF Resources - Start Guide maintained by community.
  • How to Get Started in CTF - Short guideline for CTF beginners by Endgame
  • Intro. to CTF Course - A free course that teaches beginners the basics of forensics, crypto, and web-ex.
  • IppSec - Video tutorials and walkthroughs of popular CTF platforms.
  • LiveOverFlow - Video tutorials on Exploitation.
  • MIPT CTF - A small course for beginners in CTFs (in Russian).

Wargames

Always online CTFs

  • Backdoor - Security Platform by SDSLabs.
  • Crackmes - Reverse Engineering Challenges.
  • CryptoHack - Fun cryptography challenges.
  • echoCTF.RED - Online CTF with a variety of targets to attack.
  • Exploit Exercises - Variety of VMs to learn variety of computer security issues.
  • Exploit.Education - Variety of VMs to learn variety of computer security issues.
  • Gracker - Binary challenges having a slow learning curve, and write-ups for each level.
  • Hack The Box - Weekly CTFs for all types of security enthusiasts.
  • Hack This Site - Training ground for hackers.
  • Hacker101 - CTF from HackerOne
  • Hacking-Lab - Ethical hacking, computer network and security challenge platform.
  • Hone Your Ninja Skills - Web challenges starting from basic ones.
  • IO - Wargame for binary challenges.
  • Microcorruption - Embedded security CTF.
  • Over The Wire - Wargame maintained by OvertheWire Community.
  • PentesterLab - Variety of VM and online challenges (paid).
  • PicoCTF - All year round ctf game. Questions from the yearly picoCTF competition.
  • PWN Challenge - Binary Exploitation Wargame.
  • Pwnable.kr - Pwn Game.
  • Pwnable.tw - Binary wargame.

Self-hosted CTFs

  • Damn Vulnerable Web Application - PHP/MySQL web application that is damn vulnerable.
  • Juice Shop CTF - Scripts and tools for hosting a CTF on OWASP Juice Shop easily.

Websites

Various general websites about and on CTF

  • Awesome CTF Cheatsheet - CTF Cheatsheet.
  • CTF Time - General information on CTF occuring around the worlds.
  • Reddit Security CTF - Reddit CTF category.

Wikis

Various Wikis available for learning about CTFs

  • Bamboofox - Chinese resources to learn CTF.
  • bi0s Wiki - Wiki from team bi0s.
  • CTF Cheatsheet - CTF tips and tricks.
  • ISIS Lab - CTF Wiki by Isis lab.
  • OpenToAll - CTF tips by OTA CTF team members.

Writeups Collections

Collections of CTF write-ups

  • 0e85dc6eaf - Write-ups for CTF challenges by 0e85dc6eaf
  • Captf - Dumped CTF challenges and materials by psifertex.
  • CTF write-ups (community) - CTF challenges + write-ups archive maintained by the community.
  • CTFTime Scrapper - Scraps all writeup from CTF Time and organize which to read first.
  • HackThisSite - CTF write-ups repo maintained by HackThisSite team.
  • Mzfr - CTF competition write-ups by mzfr
  • pwntools writeups - A collection of CTF write-ups all using pwntools.
  • SababaSec - A collection of CTF write-ups by the SababaSec team
  • Shell Storm - CTF challenge archive maintained by Jonathan Salwan.
  • Smoke Leet Everyday - CTF write-ups repo maintained by SmokeLeetEveryday team.

LICENSE

CC0 :)

下载工具
Pngcheck
  • apt-get install pngcheck
  • ResourcesExtract - 从exe中提取各种文件类型。
  • Shellbags - 调查NT_USER.dat文件。
  • Snow - 空白隐写工具。
  • USBRip - 用于在GNU/Linux上跟踪USB设备工件(USB事件历史)的简单CLI取证工具。
  • Volatility - 调查内存转储。
  • Wireshark - 用于分析pcap或pcapng文件。
  • Pin - Intel的动态二进制插桩工具。
  • PINCE - GDB前端/逆向工程工具,专注于游戏破解和自动化。
  • PinCTF - 一个使用Intel Pin进行侧信道分析的工具。
  • Plasma - 一个交互式反汇编器,支持x86/ARM/MIPS,可以生成带有彩色语法的缩进伪代码。
  • Pwndbg - 一个GDB插件,提供一套实用工具以便更容易地使用GDB。
  • radare2 - 一个可移植的逆向框架。
  • Triton - 动态二进制分析(DBA)框架。
  • Uncompyle - 反编译Python 2.7二进制文件(.pyc)。
  • WinDbg - 微软分发的Windows调试器。
  • Xocopy - 一个可以复制具有执行权限但无读取权限的可执行文件的程序。
  • Z3 - 微软研究院的定理证明器。
  • Zsteg - PNG/BMP分析。
  • Pwnable.xyz - Binary Exploitation Wargame.
  • Reversin.kr - Reversing challenge.
  • Ringzer0Team - Ringzer0 Team Online CTF.
  • Root-Me - Hacking and Information Security learning platform.
  • ROP Wargames - ROP Wargames.
  • SANS HHC - Challenges with a holiday theme released annually and maintained by SANS.
  • SmashTheStack - A variety of wargames maintained by the SmashTheStack Community.
  • Viblo CTF - Various amazing CTF challenges, in many different categories. Has both Practice mode and Contest mode.
  • VulnHub - VM-based for practical in digital security, computer application & network administration.
  • W3Challs - A penetration testing training platform, which offers various computer challenges, in various categories.
  • WebHacking - Hacking challenges for web.