Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
216 results
CVE-2018-16763_fuel_cms_exploit preview

CVE-2018-16763_fuel_cms_exploit

GitHubgh0stuncle/cve-2018-16763_fuel_cms_exploit

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

ctfeducationexploitation+3
26 days ago
metasploit-pentest-report preview

metasploit-pentest-report

GitHubronankongala/metasploit-pentest-report

Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings…

ctfcurated-resourceseducation+7
22 days ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

container-escapectfcurated-resources+9
29 days ago
HiddenSteps preview

HiddenSteps

GitHubjgalego/hiddensteps

HiddenSteps — a local-first personal workflow intelligence platform

ctfcurated-resourcesdata-exfiltration+8
51 month ago
fastjson-rce-lab preview

fastjson-rce-lab

GitHubwhy-success/fastjson-rce-lab

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)

ctfeducationlabs-practice+2
41 month ago
heartbleed preview

heartbleed

GitHubcheese-hub/heartbleed

Educational Docker-based lab demonstrating the Heartbleed bug (CVE-2014-0160) with hacker, victim, and server containers for hands-on exploitation…

container-securityctfeducation+4
27 years ago
lehack-2026-challenge preview

lehack-2026-challenge

GitHubsynacktiv/lehack-2026-challenge

Sources of Synacktiv's challenge for leHack 2026

ctfdigital-forensicseducation+3
22 months ago
CVE-2025-55319-PoC preview

CVE-2025-55319-PoC

GitHubnephila016/cve-2025-55319-poc

PoC for CVE-2025-55319

command-and-controlctfexploitation+5
2 months ago
VQ-RefluxCore preview

VQ-RefluxCore

GitHubvulnquest58/vq-refluxcore

is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with…

binary-exploitationctfeducation+5
1 month ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubstr1keboo/cve-2025-49132

This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.

ctfeducationexploitation+3
47 months ago
LFI-Destruction preview

LFI-Destruction

GitHubrevshellxd/lfi-destruction

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

ctfeducationexploitation+8
47 months ago
CVE-2026-46331-pedit-cow preview

CVE-2026-46331-pedit-cow

GitHubmarwahhadi/cve-2026-46331-pedit-cow

Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331)

binary-exploitationctfeducation+2
2 months ago
CVE-2024-10924-Bypass-MFA-Wordpress-LAB preview

CVE-2024-10924-Bypass-MFA-Wordpress-LAB

GitHubd1se0/cve-2024-10924-bypass-mfa-wordpress-lab

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

authenticationctfeducation+5
41 year ago
WHS4_CVE-2021-4034 preview

WHS4_CVE-2021-4034

GitHubkrleejihyeong/whs4_cve-2021-4034

Educational PoC and analysis of CVE-2021-4034 (PwnKit) local privilege escalation vulnerability in polkit's pkexec, with a Docker-based lab for…

binary-exploitationctfeducation+5
2 months ago
HTB-TwoMillion-machine preview

HTB-TwoMillion-machine

GitHubabedallarawashdeh/htb-twomillion-machine

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

api-security-testingctfeducation+4
1 month ago
kernel-exploit-dirtycow preview

kernel-exploit-dirtycow

GitHubgonzabot/kernel-exploit-dirtycow

Lab — Privilege Escalation via Dirty Cow CVE-2016-5195 | 4Geeks Academy

binary-exploitationctfeducation+4
2 months ago
CVE-2025-4138_tarfile_filter_bypass preview

CVE-2025-4138_tarfile_filter_bypass

GitHubthefizzyfish/cve-2025-4138_tarfile_filter_bypass

CVE-2025-4138 - Python Arbitrary file write outside extraction directory

ctfexploitationpayload-generation+3
37 months ago
ghostlock-vagrant-box preview

ghostlock-vagrant-box

GitHubdaniyal48/ghostlock-vagrant-box

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed…

ctfeducationexploitation+3
12 months ago
Previous1…9101112Next