Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
securityonion preview

securityonion

GitHubsecurity-onion-solutions/securityonion

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

anomaly-detectionanti-botdefensive-tools+9
4.9k
17 days ago
AppleDOS preview

AppleDOS

GitHubfarisv/appledos

Messing Apple devices on the network with CVE-2018-4407 (heap overflow in bad packet handling)

educationexploitationnetwork-security+2
257 years ago
Packet-Sniffer preview

Packet-Sniffer

GitHubeonraider/packet-sniffer

Raw socket-based network packet sniffer that captures and disassembles TCP/IP packets from network interfaces for security analysis and educational…

educationinformation-gatheringnetwork-security+1
7864 days ago
polymorph preview

polymorph

GitHubshramos/polymorph

Polymorph is a real-time network packet manipulation framework with support for almost all existing protocols

educationnetwork-securitypacket-sniffing-analysis+2
4971 year ago
CVE-2022-21907 preview

CVE-2022-21907

GitHubkamal-marouane/cve-2022-21907

Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash.

educationexploitationlabs-practice+2
12 years ago
PcapXray preview

PcapXray

GitHubsrixivas/pcapxray

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

ctfdns-analysiseducation+7
1.9k5 months ago
PacketPatch preview

PacketPatch

GitHubxuyw-seu/packetpatch

Practical black-box adversarial packet generation against encrypted traffic classification with minimal overhead and full packet recoverability.

adversarial-attackai-securityeducation+6
83 months ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
CVE-2025-55315-Scanner-Monitor preview

CVE-2025-55315-Scanner-Monitor

GitHubjlinebau/cve-2025-55315-scanner-monitor

Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitors

educationnetwork-securitypacket-sniffing-analysis+3
211 months ago
log4j-pcap-activity preview

log4j-pcap-activity

GitHubapipia/log4j-pcap-activity

A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)

ctfeducationexploitation+3
14 years ago
Cyber-Defenders-lab- preview

Cyber-Defenders-lab-

GitHubabiral-timalsina/cyber-defenders-lab-

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

digital-forensicseducationincident-response+3
1 month ago
FuxiOS preview

FuxiOS

GitHubl3onkers/fuxios

Modernized Python 3 exploit PoC for CVE-2016-4631 targeting iOS devices. Features network scanning, malformed IP/TCP payload generation, and packet…

educationexploitationios-security+3
11 year ago
CVE-2021-27289 preview

CVE-2021-27289

GitHubthemalwareguardian/cve-2021-27289

CVE-2021-27289: Playback Protection Bypass on Ksix Zigbee devices

educationexploitationhardware-iot-security+3
11 year ago
CVE-2026-6060-QUIC-Handshake-Amplification-via-Address-Validation-Bypass preview

CVE-2026-6060-QUIC-Handshake-Amplification-via-Address-Validation-Bypass

GitHubgeorge0papasotiriou/cve-2026-6060-quic-handshake-amplification-via-address-validation-bypass

Educational Python PoC for a QUIC address-validation bypass that triggers handshake amplification, including vulnerable server simulation and attack…

adversarial-attackeducationexploitation+2
1 month ago
CVE-2026-2222-MQTT-Broker-CONNECT-Packet-Heap-Overflow preview

CVE-2026-2222-MQTT-Broker-CONNECT-Packet-Heap-Overflow

GitHubgeorge0papasotiriou/cve-2026-2222-mqtt-broker-connect-packet-heap-overflow

Demonstrates CVE-2026-2222 heap overflow in MQTT CONNECT packet handling with a simulated vulnerable broker and proof-of-concept exploit code for…

binary-exploitationeducationexploitation+2
1 month ago
nhi-zero-trust-bypass preview

nhi-zero-trust-bypass

GitHubalexsvobo/nhi-zero-trust-bypass

Demonstrates a real-world zero-trust bypass by exploiting BIND CVE-2025-40775 to disrupt DNS, break secret rotation, and expose static credentials in…

cloud-securitydns-analysiseducation+5
51 year ago
-CTT-NSP-Convergent-Time-Theory---Network-Stack-Projection-CVE-2026-24858- preview

-CTT-NSP-Convergent-Time-Theory---Network-Stack-Projection-CVE-2026-24858-

GitHubsimoesctt/-ctt-nsp-convergent-time-theory---network-stack-projection-cve-2026-24858-

A Proof-of-Concept demonstrating the application of 3D Navier-Stokes CTT formulations to packet flow optimization and defensive bypass.

educationexploitationids-ips-evasion+1
8 months ago
CVE-2022-45059-demo preview

CVE-2022-45059-demo

GitHubmartinvks/cve-2022-45059-demo

Interactive demo of CVE-2022-45059 Varnish Cache request smuggling vulnerability. Includes Spring Boot web app, vulnerable proxy, automated victim…

educationexploitationlabs-practice+3
2 years ago
Previous12Next