Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Security Virtualization

Tools for creating and managing isolated environments (VMs, containers) for security testing and malware analysis.

Kitploit recommended

Top tools

10 selected
flare-vm preview#1

flare-vm

GitHubmandiant/flare-vm
8.9k3 months ago
distro preview#2

distro

GitHubremnux/distro
1171 month ago
commando-vm preview#3

commando-vm

GitHubmandiant/commando-vm
7.8k11 months ago
securityonion preview#4

securityonion

GitHubsecurity-onion-solutions/securityonion
4.9k18 days ago
cuckoo3 preview#6

cuckoo3

GitHubcert-ee/cuckoo3
8179 months ago
metasploitable3 preview#7

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
vulhub preview#8

vulhub

GitHubvulhub/vulhub
21.1k12 days ago
GOAD preview#9

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
DetectionLab preview#10

DetectionLab

GitHubclong/detectionlab
5.0k3 years ago
qubes-core-admin preview#11

qubes-core-admin

GitHubqubesos/qubes-core-admin
1473 days ago
NewestRelevanceMost popularRecently updated
215 results
deny-af-alg-bpf preview

deny-af-alg-bpf

GitHubvatson112/deny-af-alg-bpf

eBPF LSM program that blocks AF_ALG socket creation to mitigate CVE-2026-31431, with userspace daemon logging denied attempts via ring buffer.

defensive-toolsvulnerability-analysissecurity-virtualization
14 months ago
CUAHarm preview

CUAHarm

GitHubdb-ol/cuaharm

Benchmark for evaluating safety risks of computer-using agents, with 104 realistic misuse scenarios across seven malicious categories, supporting…

vulnerability-analysissecurity-virtualizationpenetration-testing+3
11 year ago
kali-linux-docker preview

kali-linux-docker

GitHubnu11secur1ty/kali-linux-docker

kali-linux-docker

vulnerability-scannerscontainer-securityexploit-frameworks+8
16 years ago
cve-2022-0847-poc-dockerimage preview

cve-2022-0847-poc-dockerimage

GitHubmingqizhang7710/cve-2022-0847-poc-dockerimage

Docker image packaging a proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel privilege escalation vulnerability.

privilege-escalationcontainer-securityvulnerability-analysis+3
1 year ago
webvm preview

webvm

GitHubaxlan/webvm

Virtual Machine for the Web

security-virtualizationnetwork-securityctf+3
8 months ago
CVE-2026-2441_PoC preview

CVE-2026-2441_PoC

GitHubatiilla/cve-2026-2441_poc

Proof-of-concept exploit for CVE-2026-2441, demonstrating the vulnerability and providing a working exploit for security testing and validation.

vulnerability-analysisexploitationweb-application-exploitation+2
7 months ago
external_libcap-Android10_r33_CVE-2023-2603 preview

external_libcap-Android10_r33_CVE-2023-2603

GitHubpazhanivelmani/external_libcap-android10_r33_cve-2023-2603

POSIX.1e capability library for Android 10, addressing CVE-2023-2603 with tools for setting and getting process capabilities to manage privilege…

android-securityprivilege-escalationvulnerability-analysis+3
1 year ago
Graylog2__graylog2-server_CVE-2023-41044_5-1-2 preview

Graylog2__graylog2-server_CVE-2023-41044_5-1-2

GitHubshoucheng3/graylog2__graylog2-server_cve-2023-41044_5-1-2

Open source log management platform for centralized log aggregation, real-time analysis, and security event monitoring with customizable dashboards…

security-virtualizationthreat-intelligenceintrusion-detection+3
9 months ago
SpeculativeExecutionAssessment preview

SpeculativeExecutionAssessment

GitHubgregaskew/speculativeexecutionassessment

Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754

vulnerability-scannersvulnerability-analysisconfiguration-auditing+3
6 years ago
cve-2024-32019-PoC preview

cve-2024-32019-PoC

GitHubayub0x7/cve-2024-32019-poc

Checks Netdata ndsudo SUID PATH privilege escalation exposure for CVE-2024-32019 and validates patches without weaponized exploitation.

defensive-toolsprivilege-escalationvulnerability-analysis+3
1 year ago
CVE-2026-40897 preview

CVE-2026-40897

GitHubyym8538/cve-2026-40897

Proof-of-concept exploit for CVE-2026-40897, a Math.js expression parser sandbox bypass enabling remote code execution via crafted payloads and a…

vulnerability-analysisexploitationweb-application-exploitation+3
11 month ago
CVE-2026-49869 preview

CVE-2026-49869

GitHubeqstlab/cve-2026-49869

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…

vulnerability-analysisexploitationweb-application-exploitation+6
11 day ago
redStackPRO preview

redStackPRO

GitHubdevzero-security/redstackpro

A canvas for red team infrastructure and cyber ranges. Compose a topology, export runnable Terraform and Ansible, and deploy it yourself. Your cloud…

cloud-infrastructure-securitypenetration-testing-frameworksscripting-automation+8
6122h 13m ago
security-harness preview

security-harness

GitHubdmdhrumilmistry/security-harness

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

static-analysisvulnerability-scannersstatic-code-analysis+9
223 days ago
CVE-2026-48356 preview

CVE-2026-48356

GitHubabraxas/cve-2026-48356

Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.

payload-generationvulnerability-analysisexploitation+5
4 days ago
reSolver preview

reSolver

GitHubtheqmaks/resolver

This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.

scripting-automationweb-application-exploitationapi-security-testing+5
147 months ago
CVE-2026-52782 preview

CVE-2026-52782

GitHubabraxas/cve-2026-52782

Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive…

vulnerability-analysisexploitationweb-application-exploitation+5
4 days ago
Red-Team-GOAD-Lab-Proxmox preview

Red-Team-GOAD-Lab-Proxmox

GitHubpho5nix/red-team-goad-lab-proxmox

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

defensive-toolspost-exploitationsecurity-virtualization+7
283 days ago
Previous1…101112Next