Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
122 results
DOMPurify preview

DOMPurify

GitHubcure53/dompurify

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

api-securitycode-analysisdefensive-tools+3
17.4k
22h 43m ago
webvm preview

webvm

GitHubleaningtech/webvm

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

cloud-securityctfdevsecops+3
17.4k2 days ago
fuzzilli preview

fuzzilli

GitHubgoogleprojectzero/fuzzilli

A JavaScript Engine Fuzzer

binary-analysiseducationfuzzing+2
2.3k3 days ago
APTs-Adversary-Simulation preview

APTs-Adversary-Simulation

GitHubs3n4t0r-0x0/apts-adversary-simulation

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

adversarial-attackcommand-and-controleducation+9
1.1k3 days ago
openwrt preview

openwrt

GitHubopenwrt/openwrt

Linux operating system for embedded devices with writable filesystem, package management, and build framework. Enables custom firmware creation for…

educationembedded-systems-securityfirmware-analysis+7
28.5k4 days ago
OSCP Notes and Custom Dashboard preview

OSCP Notes and Custom Dashboard

GitLabwattocyber/oscp-notes-2026

OSCP notes vault + exam cockpit dashboard: merged technique notes, variable-filled command decks, machines, creds, and runbook for exam day. MIT.

curated-resourceseducationinformation-gathering+7
6 days ago
TagTinker preview

TagTinker

GitHubi12bp8/tagtinker

Flipper Zero app for infrared electronic shelf-label (ESL) protocol research, featuring custom image transmission, NFC tag scanning, and a web-based…

educationembedded-systems-securityfirmware-analysis+5
2.0k6 days ago
security-baseline-ubuntu preview

security-baseline-ubuntu

GitHubeugexo/security-baseline-ubuntu

Production-grade Security Baseline & Hardening Guide for Ubuntu 24.04/26.04 LTS. Kernel isolation, Emergency Panic Button, custom AppArmor/Firejail…

configuration-auditingdata-recoverydigital-forensics+6
97 days ago
CVE-2026-15826-CVE-2026-15748 preview

CVE-2026-15826-CVE-2026-15748

GitHubhorkimhab/cve-2026-15826-cve-2026-15748

Multithreaded Python scanner for CVE-2026-15826 and CVE-2026-15748; checks target lists, supports verbose logging, configurable threads, and custom…

educationpenetration-testingvulnerability-analysis+1
1 month ago
CVE-2024-7344 preview

CVE-2024-7344

GitHubthemalwareguardian/cve-2024-7344

Technical research on a UEFI Secure Boot bypass caused by an unsafe custom PE loader, including root-cause analysis, exploitation workflow, and an…

binary-analysiseducationexploitation+4
1 month ago
CVE-2021-41773-Apache-Lab preview

CVE-2021-41773-Apache-Lab

GitHubs-amnajafri/cve-2021-41773-apache-lab

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

educationexploitationlabs-practice+4
1 month ago
printnightmare-detection-lab preview

printnightmare-detection-lab

GitHubjoertx07/printnightmare-detection-lab

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

adversarial-attackeducationexploitation+6
1 month ago
CVE-2026-21011-Log4j-style-JNDI-Injection-in-Custom-Logger-Simulated- preview

CVE-2026-21011-Log4j-style-JNDI-Injection-in-Custom-Logger-Simulated-

GitHubgeorge0papasotiriou/cve-2026-21011-log4j-style-jndi-injection-in-custom-logger-simulated-

Simulates CVE-2026-21011, a Log4j-style JNDI injection in a custom logger: parses ${jndi:...} patterns and demonstrates LDAP-triggered remote code…

educationexploitationvulnerability-analysis+1
1 month ago
CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder preview

CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder

GitHubgeorge0papasotiriou/cve-2026-11105-stack-buffer-overflow-in-custom-base64-decoder

CVE-2026-11105 PoC demonstrating a stack buffer overflow in a custom Base64 decoder; crafted oversized input overwrites stack memory and enables…

binary-exploitationeducationexploitation+2
1 month ago
CVE-2026-13152 preview

CVE-2026-13152

GitHubminhhk68/cve-2026-13152

CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).

educationexploitationpenetration-testing+4
11 month ago
sjcam preview

sjcam

GitHubkeowu/sjcam

Reverse engineering research and custom firmware for Allwinner V3-based IoT cameras, including firmware parsers, an AVIOCTRL client, and a…

educationembedded-systems-securityexploitation+7
82 months ago
CVE-2026-2002-poc preview

CVE-2026-2002-poc

GitHubtypedefabcd1234ntd/cve-2026-2002-poc

CVE-2026-2002 writeup and Proof-of-concept

code-analysiseducationexploitation+3
112 months ago
wazuh-home-soc preview

wazuh-home-soc

GitHuborevic21/wazuh-home-soc

Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS…

educationexploitationids-ips-evasion+6
2 months ago
Previous1234567Next