Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
Crucix preview

Crucix

GitHubcalesthio/crucix

Your personal intelligence agent. Watches the world from multiple data sources and pings you when something changes.

curated-resourceseducationinformation-gathering+3
12.0k
4 months ago
iOS-Bluetooth-Ethernet-Exploit preview

iOS-Bluetooth-Ethernet-Exploit

GitHubf4r3sx0/ios-bluetooth-ethernet-exploit

iOS Bluetooth PAN vulnerability that opens USB port 62078 and displays Ethernet icon without any adapter (€0). Apple sells a €89.95 adapter for the…

bluetooth-securityeducationexploitation+8
73 months ago
allsafe-android preview

allsafe-android

GitHubt0thkr1s/allsafe-android

Intentionally vulnerable Android application.

android-securitydynamic-analysis-sandboxingeducation+7
4341 year ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
14 months ago
pulsegram preview

pulsegram

GitHubtaurusomar/pulsegram

Python-based keylogger with Telegram bot integration for capturing keystrokes, clipboard content, and screenshots in authorized security testing…

data-exfiltrationeducationred-teaming
161 year ago
RCE-CVE-2017-0199-detection-analysis preview

RCE-CVE-2017-0199-detection-analysis

GitHubahmed-tarek22752/rce-cve-2017-0199-detection-analysis

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

command-and-controldigital-forensicseducation+8
124 days ago
Cyber-Defenders-lab- preview

Cyber-Defenders-lab-

GitHubabiral-timalsina/cyber-defenders-lab-

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

digital-forensicseducationincident-response+3
1 month ago
How-to-Patch-CVE-2025-32709 preview

How-to-Patch-CVE-2025-32709

GitHubadnansiyat/how-to-patch-cve-2025-32709

Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots,…

configuration-auditingeducationincident-response+3
1 year ago
cve-lfi-lab preview

cve-lfi-lab

GitHubthecyberfairy/cve-lfi-lab

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

ctfeducationincident-response+5
1 year ago
htb-ctf-walkthroughs preview

htb-ctf-walkthroughs

GitLabrootsecnz/htb-ctf-walkthroughs

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

ctfeducationexploitation+6
7 months ago
log4shell preview

log4shell

GitHubsanasimran1403-jpg/log4shell

Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence…

educationexploitationpapers-research+1
1 month ago
ROOT-ZTE-X1001 preview

ROOT-ZTE-X1001

GitHubsloden1977-lang/root-zte-x1001

Magisk root guide for ZTE Blade X1001 (Android 15, Unisoc UMS9230) using CVE-2022-38694 exploit. Contributions and screenshots welcome.

android-securityeducationexploitation+2
3 months ago
CVE-2025-52204 preview

CVE-2025-52204

GitHubj0qq3r/cve-2025-52204

Coordinated disclosure of CVE-2025-52204: reflected XSS and HTML injection in Znuny OTRS customer.pl endpoint. Includes technical summary, affected…

educationpapers-researchvulnerability-analysis+2
6 months ago
Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution preview

Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution

GitHubtolu12wani/demonstration-of-cve-2023-38831-via-reverse-shell-execution

This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task…

educationexploitationpayload-generation+3
1 year ago
IT19115276 preview

IT19115276

GitHubkiruthikan99/it19115276

SNP Assignment 1 Report - Linux box exploitation ( Vulnerability CVE-2014-0038)

educationexploitationlabs-practice+2
6 years ago