Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
htb-labs-connected preview

htb-labs-connected

GitHubdiegorivas1/htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

ctfeducationexploitation+7
2 days ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9626 days ago
cmdchamp preview

cmdchamp

GitHubmellen9999/cmdchamp

bash CLI trainer — 30 levels from ls to privilege escalation

ctfeducationforensics+8
126 days ago
Ropper preview

Ropper

GitHubsashs/ropper

Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64,…

binary-analysisbinary-exploitationctf+3
2.1k7 days ago
Cybersec preview

Cybersec

GitHubamitr12/cybersec

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…

command-and-controlctfeducation+9
910 days ago
CICD-Goat-Vapt-Writeup preview

CICD-Goat-Vapt-Writeup

GitHubdheeraj-jayaswal/cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

ctfdevsecopseducation+5
124 days ago
CVE-2026-43494-PinTheft-PoC preview

CVE-2026-43494-PinTheft-PoC

GitHubletsr00t/cve-2026-43494-pintheft-poc

Proof-of-concept for CVE-2026-43494 (PinTheft): Linux kernel local privilege escalation exploiting an RDS zerocopy reference-count bug with io_uring…

binary-exploitationctfeducation+4
11 month ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubbayu06802/cve-2026-48908

Proof-of-concept exploit for CVE-2026-48908, an unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload, with adaptive payload…

ctfeducationexploitation+4
1 month ago
CVE-2024-3829 preview

CVE-2024-3829

GitHubfabse-hack/cve-2024-3829

Python exploit for CVE-2024-3829 targeting Qdrant snapshot import/export, enabling file read, file write, and reverse shell execution via symlink…

ctfexploitationpayload-development+3
12 months ago
CVE-2026-54337-PoC preview

CVE-2026-54337-PoC

GitHub4qu4r1um/cve-2026-54337-poc

CVE-2026-54337 - Unauthenticated File Write/Overwrite PoC for fireshare <= 1.16.3

ctfeducationexploitation+3
2 months ago
CVE-2026-46215-POC preview

CVE-2026-46215-POC

GitHub0xcyberstan/cve-2026-46215-poc

Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

binary-exploitationctfeducation+4
112 months ago
CVE-2026-44881_exploit preview

CVE-2026-44881_exploit

GitHub0xdak/cve-2026-44881_exploit

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

cloud-securitycontainer-securityctf+7
2 months ago
TwoMillion-Machine-Writeup preview

TwoMillion-Machine-Writeup

GitHubanxs3c/twomillion-machine-writeup

From deobfuscating code.js to root, CVE-2023-0386

ctfeducationexploitation+7
2 months ago
Popcorn-TJNULL-OSCP- preview

Popcorn-TJNULL-OSCP-

GitHubr3fr4kt/popcorn-tjnull-oscp-

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

ctfeducationexploitation+7
2 months ago
CVE-2026-5718-Lab preview

CVE-2026-5718-Lab

GitHubrootdirective-sec/cve-2026-5718-lab

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

ctfeducationexploitation+3
13 months ago
CVE-2026-3844-Lab preview

CVE-2026-3844-Lab

GitHubrootdirective-sec/cve-2026-3844-lab

Local Docker lab for reproducing CVE-2026-3844, an unauthenticated arbitrary file upload to RCE in the WordPress Breeze Cache plugin. Compares…

ctfeducationexploitation+3
3 months ago
ChamiloLMS-CVE-2023-4220 preview

ChamiloLMS-CVE-2023-4220

GitHubspeatx/chamilolms-cve-2023-4220

CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.

ctfeducationexploitation+5
3 months ago
Scanning preview

Scanning

GitHubaidilzlkfli/scanning

Analysis of network scan results, service vulnerabilities, OS fingerprinting, and critical Nessus findings including Ghostcat (CVE-2020-1938).

ctfeducationexploitation+6
3 months ago
Previous12345Next