Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
480 results
gha-lab-fb6df3d456 preview

gha-lab-fb6df3d456

GitHubpvharmo2/gha-lab-fb6df3d456

Authorized security-research lab reproducing CVE-2025-46820 (GHSA-cwj7-6v67-2cm4): GITHUB_TOKEN persisted into publicly downloadable CI artifacts in…

cloud-securitycurated-resourceseducation+2
2 days ago
gha-lab-2f775f277c preview

gha-lab-2f775f277c

GitHubpvharmo2/gha-lab-2f775f277c

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

cloud-securitycurated-resourcesdevsecops+2
2 days ago
gha-lab-becf103a54 preview

gha-lab-becf103a54

GitHubpvharmo2/gha-lab-becf103a54

Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration…

cloud-securitycurated-resourceseducation+2
3 days ago
gha-lab-40e23db109 preview

gha-lab-40e23db109

GitHubpvharmo2/gha-lab-40e23db109

Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in…

cloud-securitydevsecopseducation+2
4 days ago
Microsoft-Sentinel-SecOps preview

Microsoft-Sentinel-SecOps

GitHubeshlomo1/microsoft-sentinel-secops

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

cloud-securityincident-responselog-analysis+1
2671 month ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
9 days ago
CVE-2026-41940-Detection preview

CVE-2026-41940-Detection

GitHubunfold-security/cve-2026-41940-detection

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

cloud-securityintrusion-detectionlog-analysis+2
14 months ago
CVE-2026-34940 preview

CVE-2026-34940

GitHubromain-deperne/cve-2026-34940

OS Command Injection in KubeAI via Model URL in Ollama startup probe — CVSS 8.7

cloud-securitycontainer-securityexploitation+3
4 months ago
CVE-2026-33980 preview

CVE-2026-33980

GitHubromain-deperne/cve-2026-33980

KQL Injection in adx-mcp-server via table_name parameter — CVSS 8.8

cloud-securitycode-analysisdatabase-security+3
4 months ago
copy-fail-CVE-2026-31431 preview

copy-fail-CVE-2026-31431

GitHubrio128128/copy-fail-cve-2026-31431

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

binary-exploitationcloud-securitycontainer-security+6
4 months ago
cve-2026-24514-Kubernetes-Dos preview

cve-2026-24514-Kubernetes-Dos

GitHubmbanyamer/cve-2026-24514-kubernetes-dos

Proof-of-concept exploit for CVE-2026-24514, a memory exhaustion denial-of-service in ingress-nginx validating admission webhook, allowing…

cloud-securitycontainer-securityexploitation+2
6 months ago
CVE-2026-4660-PoC preview

CVE-2026-4660-PoC

GitHubgouldnicholas/cve-2026-4660-poc

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

cloud-securitydevsecopsexploitation+3
4 months ago
copy-fail-blocker preview

copy-fail-blocker

GitHubcozystack/copy-fail-blocker

BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide

cloud-securitycontainer-securitydefensive-tools+2
344 months ago
CVE-2026-29955 preview

CVE-2026-29955

GitHubb0b0haha/cve-2026-29955

Proof-of-concept for CVE-2026-29955, a command injection vulnerability in KubePlus kubeconfiggenerator allowing remote code execution and…

cloud-securitycontainer-securityexploitation+3
5 months ago
CVE-2026-29954 preview

CVE-2026-29954

GitHubb0b0haha/cve-2026-29954

Proof-of-concept demonstrating SSRF and HTTP header injection in KubePlus ResourceComposition, enabling cloud metadata access and IAM credential…

cloud-securityexploitationpenetration-testing+2
5 months ago
spinnaker-poc preview

spinnaker-poc

GitHubzeropathai/spinnaker-poc

POCs for CVE-2026-32604 and CVE-2026-32613 which allow post-auth RCE and credential theft in Spinnaker

cloud-securityexploitationpenetration-testing+3
4 months ago
triton-cve-2025-23320 preview

triton-cve-2025-23320

GitHubthere-was-a-bird/triton-cve-2025-23320

Docker-based proof-of-concept demonstrating CVE-2025-23320 in NVIDIA Triton inference server, exploiting shared memory key leakage to trigger an…

cloud-securitycontainer-securityexploitation+3
10 months ago
Dirty-Frag-Kubernetes-PoC preview

Dirty-Frag-Kubernetes-PoC

GitHubpercivalll/dirty-frag-kubernetes-poc

Proof-of-concept demonstrating container escape on Amazon EKS by exploiting Dirty Frag (CVE-2026-43284) kernel page-cache corruption via shared image…

cloud-securitycontainer-escapeexploitation+3
184 months ago
Previous12…27Next