Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1056 results
DEVVORTEX preview

DEVVORTEX

GitHubr3fr4kt/devvortex

HackTheBox Devvortex walkthrough covering subdomain fuzzing, Joomla API enumeration, template-based web shell, bcrypt hash cracking, and Apport-CLI…

ctfeducationinformation-gathering+7
6h 36m ago
CyberSecurity-Pentest-Lab preview

CyberSecurity-Pentest-Lab

GitHubgermarr93/cybersecurity-pentest-lab

CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab

ctfeducationexploitation+6
21h 58m ago
dot-CFG-challenge preview

dot-CFG-challenge

GitHubgmh5225/dot-cfg-challenge

C++ challenge repository exploring Control Flow Guard (CFG) bypass techniques for Windows binary exploitation research.

binary-analysisbinary-exploitationctf+3
3 years ago
secdim-assurance-drift-challenge preview

secdim-assurance-drift-challenge

GitHubfranklincg/secdim-assurance-drift-challenge

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

api-securityauthentication-authorizationctf+5
1 day ago
Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation preview

Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation

GitHubrhimavanth32-max/metasploitable2-reconnaissance-and-unrealircd-backdoor-exploitation

End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

ctfeducationexploitation+7
1 day ago
TryHackMe-Blue-MS17-010 preview

TryHackMe-Blue-MS17-010

GitHubporcumarcooo/tryhackme-blue-ms17-010

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

ctfdefensive-toolseducation+4
1 day ago
Writeups preview

Writeups

GitHubserotav/writeups

Collection of detailed and optimized(?) write-ups for various CTF challenges

binary-exploitationctfeducation+5
84 days ago
how_to_become_a_malware_analyst preview

how_to_become_a_malware_analyst

GitHubpinksawtooth/how_to_become_a_malware_analyst

Curated guide to becoming a malware analyst, covering essential knowledge, reverse engineering, analysis tools, and LLM-assisted learning with…

binary-analysisctfcurated-resources+7
2794 days ago
BLUE-WRITEUP-CVE-2017-0144 preview

BLUE-WRITEUP-CVE-2017-0144

GitHubquincyomoruyi6-lang/blue-writeup-cve-2017-0144

Conducted a complete security assessment of an unpatched Windows 7 target ("Blue") to demonstrate the impact of legacy service vulnerabilities in an…

ctfeducationexploitation+7
12 days ago
HTB_Helix_CVE-2023-34468 preview

HTB_Helix_CVE-2023-34468

GitHubluiskrnr/htb_helix_cve-2023-34468

Writeup of the Hackthebox Helix machine, detailing exploitation of CVE-2023-34468 and penetration testing steps.

ctfeducationexploitation+2
2 days ago
CVE-2024-2961-XXE-Exploit preview

CVE-2024-2961-XXE-Exploit

GitHubqinglove777/cve-2024-2961-xxe-exploit

CVE-2024-2961 (CNEXT) PHP file-read to RCE exploit adapted to an XXE/CTF channel

binary-exploitationctfexploitation+3
3 days ago
CVE-2026-30225-OliveTin-RCE preview

CVE-2026-30225-OliveTin-RCE

GitHubhackerking24/cve-2026-30225-olivetin-rce

Proof-of-concept exploit for OliveTin unauthenticated RCE (CVE-2026-30225) via insecure guest defaults and unvalidated argument types, enabling root…

ctfeducationexploitation+5
3 days ago
ctf-tracker preview

ctf-tracker

GitHubxxdndxx/ctf-tracker

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

ctfeducationexploitation+6
25 days ago
CVE-2026-29782-OpenSTAManager-RCE preview

CVE-2026-29782-OpenSTAManager-RCE

GitHubhackerking24/cve-2026-29782-openstamanager-rce

Proof-of-concept exploit for CVE-2026-29782, chaining SQL injection and PHP object injection to achieve remote code execution in OpenSTAManager.…

ctfeducationexploitation+2
3 days ago
CVE-2026-44578-next-js-ssrf preview

CVE-2026-44578-next-js-ssrf

GitHubisaca0315/cve-2026-44578-next-js-ssrf

este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah

cloud-securityctfexploitation+4
5 days ago
CVE-2026-64849-poc-lab preview

CVE-2026-64849-poc-lab

GitHubisaca0315/cve-2026-64849-poc-lab

este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah

ctfeducationexploitation+4
5 days ago
HackTheBox-Connected preview

HackTheBox-Connected

GitHubikmalhanaan/hackthebox-connected

Detailed penetration testing writeup for HackTheBox 'Connected' machine, covering exploitation of FreePBX CVE-2025-57819 (SQLi to RCE) and privilege…

ctfeducationexploitation+5
19 days ago
FreePBX-SQLi-Exploit-Privilege-escalation preview

FreePBX-SQLi-Exploit-Privilege-escalation

GitHubitsc1sco/freepbx-sqli-exploit-privilege-escalation

This walkthrough documents the complete compromise of the HTB machine Connected.

code-analysisctfeducation+5
125 days ago
Previous12…59Next