Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
127 results
flare-vm preview

flare-vm

GitHubmandiant/flare-vm

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

binary-analysisdebuggersdigital-forensics+10
9.0k
2 months ago
CVE-2026-39808 preview

CVE-2026-39808

GitHubhorkimhab/cve-2026-39808

CVE-2026-39808 - Fortinet Sandbox - Draft

dynamic-analysis-sandboxingeducationexploitation+3
2 months ago
CVE-2026-39813 preview

CVE-2026-39813

GitHubhorkimhab/cve-2026-39813

CVE-2026-39813 - Fortinet Sandbox - Draft

dynamic-analysis-sandboxingeducationexploitation+3
2 months ago
appsandbox preview

appsandbox

GitHubjamesstringer90/appsandbox

Easily create full virtual machines that are sandboxed for development or computer use models.

devsecopsdynamic-analysis-sandboxingscripting-automation+1
6512 months ago
DIY-CVE-2026-42945-POC preview

DIY-CVE-2026-42945-POC

GitHubhulina9900-boop/diy-cve-2026-42945-poc

Proof-of-concept exploit environment for CVE-2026-42945 targeting nginx 1.30.0 on Ubuntu 22.04 with PHP-FPM, packaged as a Docker-based local testing…

dynamic-analysis-sandboxingexploitationpenetration-testing+2
2 months ago
CVE-2024-1441 preview

CVE-2024-1441

GitHubalmkuznetsov/cve-2024-1441

Reproduces fuzzing and crash analysis for CVE-2024-1441 using AFL++ and CASR, with detailed setup and commands for libvirt.

binary-analysisdynamic-analysis-sandboxingexploitation+2
2 years ago
agent-scan preview

agent-scan

GitHubsnyk/agent-scan

Security scanner for AI agents, MCP servers and agent skills.

ai-securitycode-analysisdynamic-analysis-sandboxing+3
3.0k1 day ago
clawk preview

clawk

GitHubclawkwork/clawk

Give coding agents a disposable Linux VM, not your laptop

cloud-securitycontainer-securitydevsecops+3
1.0k23 days ago
TraceTree preview

TraceTree

GitHubtejasprasad2008-afk/tracetree

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

container-securitydevsecopsdynamic-analysis-sandboxing+6
4214 days ago
fastjson-jsontype-rce-lab preview

fastjson-jsontype-rce-lab

GitHubdinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

dynamic-analysis-sandboxingeducationexploitation+5
2061 month ago
dd preview

dd

GitHubricccrd/dd

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

binary-analysiscontainer-securitydevsecops+3
25911h 11m ago
readme2demo preview

readme2demo

GitHubalphacrack/readme2demo

Verified tutorials and demo videos from your README. An AI agent runs it in a hardened Docker sandbox and replays it in a fresh container before…

devsecopsdynamic-analysis-sandboxingeducation+2
817 days ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
61 month ago
React2Shell preview

React2Shell

GitHubphanhoangkhang/react2shell

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

dynamic-analysis-sandboxingeducationexploitation+6
18 days ago
livewire-honeypot preview

livewire-honeypot

GitHubhelgesverre/livewire-honeypot

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

command-and-controldynamic-analysis-sandboxingexploitation+6
63 months ago
cve-2023-4863-analysis preview

cve-2023-4863-analysis

GitHubshcesama/cve-2023-4863-analysis

Educational analysis of CVE-2023-4863 (libwebp heap buffer overflow) with Blue Team detection tools, static WebP scanner, defensive Java validator,…

binary-analysisdefensive-toolsdynamic-analysis-sandboxing+5
23 months ago
Kaspersky_CVE-2024-3094 preview

Kaspersky_CVE-2024-3094

GitHubvesjolyjd/kaspersky_cve-2024-3094

Security review of CVE-2024-3094 (XZ Utils backdoor) including threat modeling, static/dynamic code analysis, fuzzing with AFL++, and a…

code-analysisdynamic-analysis-sandboxingeducation+7
4 months ago
CVE-2026-42945-nginx-rift-poc preview

CVE-2026-42945-nginx-rift-poc

GitHubf2u0a0d3/cve-2026-42945-nginx-rift-poc

PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab,…

binary-exploitationdynamic-analysis-sandboxingeducation+6
13 months ago
Previous12…8Next