Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
216 results
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
1
2 months ago
cve-2019-17558-apache-solr-rce preview

cve-2019-17558-apache-solr-rce

GitHubrogerzeferino/cve-2019-17558-apache-solr-rce

CTF write-up documenting CVE-2019-17558 exploitation in Apache Solr, covering reconnaissance, Metasploit limitations, manual Velocity template…

ctfeducationexploitation+4
11 month ago
cve-2018-7600-drupalgeddon2-lab preview

cve-2018-7600-drupalgeddon2-lab

GitHubmeraj1312/cve-2018-7600-drupalgeddon2-lab

Educational lab demonstrating CVE-2018-7600 (Drupalgeddon2) Remote Code Execution using a Docker-based vulnerable Drupal 7.56 environment.

ctfeducationexploitation+5
15 months ago
BlueDoor preview

BlueDoor

GitHubsethwhy/bluedoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative…

ctfeducationexploitation+7
21 year ago
CVE-2026-29000 preview

CVE-2026-29000

GitHublucastran05/cve-2026-29000

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

authenticationctfeducation+3
3 months ago
Estudo-de-Caso-CVE-2024-21413 preview

Estudo-de-Caso-CVE-2024-21413

GitHubpedro-lucas-melo/estudo-de-caso-cve-2024-21413

Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

ctfeducationemail-security+6
5 months ago
Sandbox-Challenge-Spring4Shell-CVE-2022-22965- preview

Sandbox-Challenge-Spring4Shell-CVE-2022-22965-

GitHubfelisha-elmer/sandbox-challenge-spring4shell-cve-2022-22965-

Step-by-step walkthrough of exploiting CVE-2022-22965 (Spring4Shell) with Metasploit, deploying a C2 listener, and mitigating the vulnerability by…

command-and-controlctfeducation+6
4 months ago
Exploiting-a-vulnerability-using-reverse-shell preview

Exploiting-a-vulnerability-using-reverse-shell

GitHubdampedcoast/exploiting-a-vulnerability-using-reverse-shell

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

ctfeducationexploitation+5
3 months ago
blackbox-pentesting-infsecos preview

blackbox-pentesting-infsecos

GitHubsaqib-butt2/blackbox-pentesting-infsecos

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

command-and-controlctfexploitation+7
4 months ago
Spring4Shell-CTF preview

Spring4Shell-CTF

GitHubyuting-huang0/spring4shell-ctf

Spring4Shell (CVE-2022-22965) 漏洞環境搭建與 CTF 題目

ctfdynamic-analysis-sandboxingeducation+6
3 months ago
HTB-Pterodactyl-Writeup preview

HTB-Pterodactyl-Writeup

GitHubv0idw1re/htb-pterodactyl-writeup

HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM…

ctfeducationexploitation+9
5 months ago
Kali-Metasploitable preview

Kali-Metasploitable

GitHubivoalbacete/kali-metasploitable

Escaneo de vulnerabilidades, análisis de tráfico con Wireshark y explotación controlada del CVE-2011-2523 (vsftpd 2.3.4) en entorno de red segura.

ctfeducationexploitation+9
4 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
POC_CVE-2024-4322 preview

POC_CVE-2024-4322

GitHubmj-bin/poc_cve-2024-4322

POC_CVE-2024-4322

ctfeducationexploitation+3
4 months ago
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

ctfeducationexploitation+8
4 months ago
rust-cve-2025-55182-scanner preview

rust-cve-2025-55182-scanner

GitHubkaxm23/rust-cve-2025-55182-scanner

powerfull rust cve-2025-55182-scanner used for ctf & ethical purpose only

ctfexploitationpenetration-testing+3
5 months ago
CVE-2022-22980 preview

CVE-2022-22980

GitHubeliasdekiniweek/cve-2022-22980

Exploitation de CVE-2022-22980

command-and-controlctfeducation+3
17 months ago
CVE-2021-4034-POC preview

CVE-2021-4034-POC

GitHubcyb3rk1d/cve-2021-4034-poc

pwnkit

binary-exploitationctfeducation+3
11 year ago
Previous1…101112Next