Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1083 results
Veridiff preview

Veridiff

GitHubveridiff/veridiff

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

binary-analysisbinary-exploitationcode-analysis+7
1
2 days ago
rp2350_hacking_challenge preview

rp2350_hacking_challenge

GitHubraspberrypi/rp2350_hacking_challenge

Raspberry Pi RP2350 hacking challenge: extract a 128-bit OTP secret protected by secure boot and OTP lock, with setup scripts and firmware for Pico 2…

cryptographyctfeducation+5
2021 year ago
CVE-2026-76461 preview

CVE-2026-76461

GitHubs3v3n-jg/cve-2026-76461

Intentionally vulnerable Python lab demonstrating unsafe YAML deserialization leading to code execution, with three difficulty levels, exploit…

ctfeducationexploitation+3
12 days ago
cve-2025-57819-freepbx-range preview

cve-2025-57819-freepbx-range

GitHubshivammittal2403/cve-2025-57819-freepbx-range

Isolated educational FreePBX-compatible cyber range for CVE-2025-57819 (CWE-89/CWE-288). Docker lab — not official Sangoma FreePBX.

ctfeducationincident-response+4
2 days ago
cve-2026-59827-metabase-cyber-range preview

cve-2026-59827-metabase-cyber-range

GitHubshivammittal2403/cve-2026-59827-metabase-cyber-range

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking…

ctfdynamic-analysis-sandboxingeducation+6
2 days ago
cve-2026-80428-ctf preview

cve-2026-80428-ctf

GitHubshivammittal2403/cve-2026-80428-ctf

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

container-securityctfdynamic-analysis-sandboxing+5
3 days ago
CPLHF preview

CPLHF

GitHubwhereisxuezugi/cplhf

Modular Bash toolkit that hardens Debian/Ubuntu systems for CyberPatriot competitions, automating account, firewall, SSH, PAM, and service hardening…

configuration-auditingctfdefensive-tools+6
36 days ago
HTB-NanoCorp-CVE-2024-0670 preview

HTB-NanoCorp-CVE-2024-0670

GitHubtaktak0x/htb-nanocorp-cve-2024-0670

PowerShell exploit for CVE-2024-0670 that abuses CheckMK Agent MSI repair to escalate privileges to SYSTEM on the NanoCorp Hack The Box machine.

ctfeducationexploitation+4
2 months ago
thm-Moniker-Link-cve-2024-21413-writeup preview

thm-Moniker-Link-cve-2024-21413-writeup

GitHubshauryarathore357-hub/thm-moniker-link-cve-2024-21413-writeup

TryHackMe room walkthrough of CVE-2024-21413, covering the Outlook Moniker Link Protected View bypass, NTLM hash leaking, and credential capture with…

ctfeducationexploitation+6
5 days ago
CVE-2026-76461 preview

CVE-2026-76461

GitHubhorkimhab/cve-2026-76461

Educational security research repository for learning, testing, and researching CVE vulnerabilities and defensive practices in isolated lab…

ctfeducationexploitation+3
4 days ago
CVE-2025-64512_PoC preview

CVE-2025-64512_PoC

GitHubjinook-kim/cve-2025-64512_poc

Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

ctfeducationexploitation+5
4 days ago
CVE-2025-5548-FreeFloat-FTP-Lab preview

CVE-2025-5548-FreeFloat-FTP-Lab

GitHubm4rc0s-s3c/cve-2025-5548-freefloat-ftp-lab

Laboratorio académico de análisis y explotación de CVE-2025-5548 en FreeFloat FTP Server 1.0.

binary-exploitationctfdebuggers+6
4 days ago
ReArk preview

ReArk

GitHublkimuk/reark

An intelligent reverse engineering analysis tool designed for multiple target platforms, currently supporting HarmonyOS (HAP/APP/ABC) and Android…

ai-assisted-reversingandroid-securitybinary-analysis+6
3159 days ago
Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526- preview

Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-

GitHubshirouuu/gitea-template-sync-path-traversal-privilege-escalation-cve-2026-38526-

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

ctfeducationexploitation+7
5 days ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
6 days ago
context-segmentation preview

context-segmentation

GitHub9xeb/context-segmentation

Multi-agent automated context management for long horizon tasks in local AI Agents

ai-securityctfeducation+3
12 months ago
Interpreter-HackTheBox preview

Interpreter-HackTheBox

GitHubledksv/interpreter-hackthebox

HackTheBox Interpreter walkthrough: CVE-2023-43208 Mirth Connect deserialization RCE, PBKDF2 hash cracking, and eval() injection privilege escalation…

ctfeducationexploitation+7
3 months ago
cctv preview

cctv

GitHubledksv/cctv

HackTheBox CCTV walkthrough chaining CVE-2024-51482 ZoneMinder SQL injection, bcrypt hash cracking, and CVE-2025-60787 motionEye RCE to obtain root.

ctfeducationexploitation+6
6 days ago
Previous12…61Next