Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
162 results
cve-2022-1471-jira-lab preview

cve-2022-1471-jira-lab

GitHubaykhan019/cve-2022-1471-jira-lab

Offline CVE-2022-1471 lab: SnakeYAML unsafe deserialization to RCE; compares vulnerable 1.x vs fixed 2.x using a harmless local payload.

educationexploitationlabs-practice+1
6 days ago
CVE-2026-66804-CrossDevice-Service-EoP preview

CVE-2026-66804-CrossDevice-Service-EoP

GitHubrat5ak/cve-2026-66804-crossdevice-service-eop

CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM

educationexploitationpenetration-testing+3
248 days ago
CVE-2025-59528-PoC preview

CVE-2025-59528-PoC

GitHubloaxert/cve-2025-59528-poc

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

api-security-testingeducationexploitation+3
11 days ago
google-ctf preview

google-ctf

GitHubgoogle/google-ctf

Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

ctfcurated-resourceseducation+1
5.0k6 months ago
DC30_Workshop preview

DC30_Workshop

GitHubmainframed/dc30_workshop

DEFCON 30 Mainframe buffer overlow workshop container

binary-exploitationeducationexploitation+4
962 years ago
MSRPC-to-ATTACK preview

MSRPC-to-ATTACK

GitHubjonny-jhnson/msrpc-to-attack

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK

curated-resourcesdefensive-toolseducation+3
3493 years ago
DEFCON-CICD-pipelines-workshop preview

DEFCON-CICD-pipelines-workshop

GitHubwavestone-cdt/defcon-cicd-pipelines-workshop
cloud-securitycontainer-escapecontainer-security+8
943 years ago
ExecASLR-ekoparty preview

ExecASLR-ekoparty

GitHubes0j/execaslr-ekoparty
adversarial-attackbinary-exploitationeducation+4
723 years ago
SharpExchange preview

SharpExchange

GitHubceramicskate0/sharpexchange

C# Tool to interact with MS Exchange based on MS docs

data-exfiltrationeducationinformation-gathering+4
1023 years ago
Damn_Vulnerable_C_Program preview

Damn_Vulnerable_C_Program

GitHubhardik05/damn_vulnerable_c_program

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

educationfuzzinglabs-practice+1
7271 year ago
Mindmap preview

Mindmap

GitHubignitetechnologies/mindmap

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give…

curated-resourceseducationlearning-paths-courses+2
9.2k1 month ago
obsidian-osint-templates preview

obsidian-osint-templates

GitHubwebbreacher/obsidian-osint-templates

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

curated-resourceseducationinformation-gathering+2
8022 months ago
TJ-OPT preview

TJ-OPT

GitHubtjnull/tj-opt

This repo contains my pentesting template that I have used in PWK and for current assessments. The template has been formatted to be used in Obsidian

curated-resourceseducationexploitation+2
2521 year ago
PMD preview

PMD

GitHubrad9800/pmd
binary-analysiseducationlabs-practice+6
1591 year ago
defcon33_silence_kill_edr preview

defcon33_silence_kill_edr

GitHubarosenmund/defcon33_silence_kill_edr
adversarial-attackeducationlabs-practice+6
3461 year ago
GhostlyHollowingViaTamperedSyscalls2 preview

GhostlyHollowingViaTamperedSyscalls2

GitHubmaldev-academy/ghostlyhollowingviatamperedsyscalls2

Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection

educationids-ips-evasionpayload-development+2
757 months ago
macos_xprotect preview

macos_xprotect

GitHubyo-yo-yo-jbo/macos_xprotect
binary-analysisdefensive-toolseducation+1
31 month ago
cve-2022-24785-poc-lab preview

cve-2022-24785-poc-lab

GitHubanomalousvectors/cve-2022-24785-poc-lab

Moment.js vuln lab

educationlabs-practicevulnerability-analysis+2
11 year ago
Previous12…9Next