Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
CVE-2026-46215-POC preview

CVE-2026-46215-POC

GitHub0xcyberstan/cve-2026-46215-poc

Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

binary-exploitationctfeducation+4
11
3 months ago
SNet preview

SNet

GitHubhrmtz/snet

AI-guided CTF - Break into a real server with Claude Code as your trainer

ctfeducationexploitation+8
6 months ago
OverRide preview

OverRide

GitHubanyaschukin/override

Binary Exploitation and Reverse-Engineering (from assembly into C)

binary-exploitationctfeducation+2
725 years ago
Research_Successful_Errors preview

Research_Successful_Errors

GitHubvladko312/research_successful_errors

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming…

code-analysisctfeducation+6
1247 months ago
NOW preview

NOW

GitHubnirvanaon/now

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.

cryptographyctfeducation+5
923 months ago
Pegasus-Pentest-Arsenal preview

Pegasus-Pentest-Arsenal

GitHubsobri3195/pegasus-pentest-arsenal

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

api-security-testingctfeducation+9
586 months ago
osx-password-dumper preview

osx-password-dumper

GitHubjeanpeyremesmots/osx-password-dumper

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

ctfpassword-crackingpenetration-testing+2
531 year ago
RedRoot preview

RedRoot

GitHubagampreet-singh/redroot

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

ctfexploit-frameworksfuzzing+9
176 days ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubgiangdurian/cve-2026-63030-cve-2026-60137

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

ctfeducationexploitation+4
2 months ago
awesome-connected-things-sec preview

awesome-connected-things-sec

GitHubv33ru/awesome-connected-things-sec

A Curated list of Security Resources for all connected things

ctfcurated-resourceseducation+9
3.6k1 month ago
browser-pwn preview

browser-pwn

GitHubm1ghtym0/browser-pwn

An updated collection of resources targeting browser-exploitation.

binary-exploitationctfcurated-resources+4
8315 years ago
pwnedit preview

pwnedit

GitHubliveoverflow/pwnedit

CVE-2021-3156 - Sudo Baron Samedit

binary-exploitationctfdebuggers+5
2274 years ago
z80-sans preview

z80-sans

GitHubnevesnunes/z80-sans

OpenType font that disassembles Z80 instructions

binary-analysisctfeducation+3
5072 years ago
DVAP preview

DVAP

GitHubsonuoffsec/dvap

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

ai-securityctfeducation+4
293 months ago
Room-Walkthrough-Billing preview

Room-Walkthrough-Billing

GitHubadityabhatt3010/room-walkthrough-billing

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

ctfeducationexploitation+6
142 months ago
CVE-2026-4060-PoC preview

CVE-2026-4060-PoC

GitHubydking0911/cve-2026-4060-poc

Proof-of-concept for CVE-2026-4060: unauthenticated time-based blind SQL injection in Geo Mashup WordPress plugin via ORDER BY clause. Includes…

ctfeducationexploitation+3
4 months ago
process-injection-playground preview

process-injection-playground

GitHuboscerd/process-injection-playground

A collection of samples and material related to process injection

binary-exploitationctfeducation+3
110 months ago
ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend preview

ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend

GitHubcyprianatsyor/toolshell-cve-2025-53770-sharepoint-exploit-lab-letsdefend

Step-by-step walkthrough of exploiting CVE-2025-53770 (ToolShell) in a LetsDefend lab, covering RCE, web shell deployment, and incident response…

command-and-controlctfdigital-forensics+9
1 year ago