Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
JavaSecLab preview

JavaSecLab

GitHubwhgojp/javaseclab

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

code-analysisctfdevsecops+6
883
3 months ago
agentic-workflow-injection preview

agentic-workflow-injection

GitHubsushant-me/agentic-workflow-injection

Reproducible vulnerable and fixed GitHub Actions fixtures for agentic workflow injection (CVE-2026-44246), with measured detector coverage and…

ai-securitydevsecopseducation+4
19 days ago
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

code-analysisdevsecopseducation+4
21 days ago
CVE-2026-0303 preview

CVE-2026-0303

GitHubyonliud/cve-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

code-analysisdevsecopseducation+5
25 days ago
gha-lab-5511dc3f73 preview

gha-lab-5511dc3f73

GitHubpvharmo2/gha-lab-5511dc3f73

Authorized security-research lab reproducing CVE-2026-45131 (pwn request in .github/workflows/pull-request.yaml) — snapshot of…

cloud-securitydevsecopseducation+2
27 days ago
gha-lab-40e23db109 preview

gha-lab-40e23db109

GitHubpvharmo2/gha-lab-40e23db109

Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in…

cloud-securitydevsecopseducation+2
1 month ago
gha-lab-232af4821f preview

gha-lab-232af4821f

GitHubpvharmo2/gha-lab-232af4821f

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in…

devsecopseducationsupply-chain-security+1
1 month ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1825 days ago
csw-slides-2024 preview

csw-slides-2024

GitHubjduck/csw-slides-2024

Slides for Developing Secure Software in 2024 at CanSecWest

devsecopseducationlearning-paths-courses
41 year ago
CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline preview

CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline

GitHubgeorge0papasotiriou/cve-2026-11120-command-injection-via-git-url-in-ci-cd-pipeline

Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical…

devsecopseducationexploitation+1
2 months ago
CICD-Goat-Vapt-Writeup preview

CICD-Goat-Vapt-Writeup

GitHubdheeraj-jayaswal/cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

ctfdevsecopseducation+5
18 days ago
Teach-AppSec preview

Teach-AppSec

GitHubowasp/teach-appsec

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

devsecopseducationlearning-paths-courses
3 months ago
nuclei-templates-labs preview

nuclei-templates-labs

GitHubprojectdiscovery/nuclei-templates-labs

Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀

ctfcurated-resourcesdevsecops+8
1331 year ago
SecureCodingDojo preview

SecureCodingDojo

GitHubowasp/securecodingdojo

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

authenticationcode-analysisctf+6
61110 months ago
react2shell-security-toolkit preview

react2shell-security-toolkit

GitHubdelvygonzalez/react2shell-security-toolkit

Security toolkit to detect CVE-2025-55182 (React2Shell) vulnerability

code-analysisdevsecopseducation+2
110 months ago
unicode-control-characters-action preview

unicode-control-characters-action

GitHubpierdipi/unicode-control-characters-action

A GitHub Action to find Unicode control characters using the Red Hat diagnostic tool https://access.redhat.com/security/vulnerabilities/RHSB-2021-007…

code-analysisdevsecopseducation+3
3 years ago
OpsGuard-simulation preview

OpsGuard-simulation

GitHubshubham-01-star/opsguard-simulation

OpsGuard eliminates the "3 AM PagerDuty" nightmare, specifically protecting against threats like the recent CVE-2025-55184 (Next.js DoS)

cloud-securitydevsecopseducation+2
19 months ago
log4j-vuln-coverage-check preview

log4j-vuln-coverage-check

GitHubmeterianhq/log4j-vuln-coverage-check

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

code-analysisdevsecopseducation+3
3 years ago
Previous1234Next