Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
229 results
Vulnerability-Disclosure-Policy preview

Vulnerability-Disclosure-Policy

GitHubenablesecurity/vulnerability-disclosure-policy

How Enable Security handles security vulnerabilities

curated-resourceseducationincident-response+2
10
1 year ago
CVE-2025-10585-The-Chrome-V8-Zero-Day preview

CVE-2025-10585-The-Chrome-V8-Zero-Day

GitHubadityabhatt3010/cve-2025-10585-the-chrome-v8-zero-day

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

educationexploitationpapers-research+3
1311 months ago
Analysis preview

Analysis

GitHubmanishrawat21/analysis

Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

educationincident-responselog-analysis
64 months ago
CVE-2026-71300 preview

CVE-2026-71300

GitHuboscerd/cve-2026-71300

Proof-of-concept reproducer for Apache Camel camel-atmosphere-websocket dispatch header injection (CVE-2026-71300), demonstrating how an injected…

educationexploitationpapers-research+2
19 days ago
ai-email-threat-research preview

ai-email-threat-research

GitHubscottalt/ai-email-threat-research

A cybersecurity research game measuring how humans detect AI-generated phishing emails. Built as a retro terminal experience.

ai-securityctfeducation+4
83 months ago
Fern Pattern Scanner preview

Fern Pattern Scanner

GitLabgitlab-da/tutorials/security-and-governance/custom-scanner-integration/fern-pattern-scanner

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

code-analysisdevsecopseducation+3
52 years ago
CVE-2022-42889-POC preview

CVE-2022-42889-POC

GitHubakshayithape-devops/cve-2022-42889-poc

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

educationexploitationlabs-practice+3
53 years ago
Log4Shell-demo preview

Log4Shell-demo

GitHubmschmnet/log4shell-demo

Demo to show how Log4Shell / CVE-2021-44228 vulnerability works

educationexploitationlabs-practice+3
74 years ago
reproducer-okio-cve-2023-3635 preview

reproducer-okio-cve-2023-3635

GitHubjoshuaasmith/reproducer-okio-cve-2023-3635

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

android-securityeducationmobile-security+2
18 days ago
dh-CVE_2016_2098 preview

dh-CVE_2016_2098

GitHubhderms/dh-cve_2016_2098

Proof of concept showing how CVE-2016-2098 leads to remote code execution

educationexploitationpenetration-testing+2
310 years ago
SAPGateBreaker-Exploit preview

SAPGateBreaker-Exploit

GitHubbecodoexploit-mrcat/sapgatebreaker-exploit

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

educationexploitationpenetration-testing+3
31 year ago
Weblogic_Wsat_RCE preview

Weblogic_Wsat_RCE

GitHubkbsec/weblogic_wsat_rce

POC for CVE-2017-10271. Since java.lang.ProcessBuilder was the original vector for RCE, there are multiple signature based rules that block this…

educationexploitationpayload-development+3
47 years ago
nextjs-middleware-bypass-demo preview

nextjs-middleware-bypass-demo

GitHubfourcube/nextjs-middleware-bypass-demo

Demonstrates a middleware bypass vulnerability (CVE-2025-29927) in Next.js, showing how to exploit the x-middleware-subrequest header to access…

educationpenetration-testingvulnerability-analysis+2
51 year ago
CVE-2026-11107-Insecure-Direct-Object-Reference-with-Predictable-UUIDv1 preview

CVE-2026-11107-Insecure-Direct-Object-Reference-with-Predictable-UUIDv1

GitHubgeorge0papasotiriou/cve-2026-11107-insecure-direct-object-reference-with-predictable-uuidv1

Educational CVE-2026-11107 demo with vulnerable Flask API and exploit script, showing how predictable UUIDv1 identifiers enable insecure direct…

educationexploitationvulnerability-analysis+2
1 month ago
CVE-2022-46364-Proof-of-the-concept preview

CVE-2022-46364-Proof-of-the-concept

GitHubcybermaksx/cve-2022-46364-proof-of-the-concept

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

educationexploitationinformation-gathering+3
35 months ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubthebl4ckph4nt0m/cve-2024-0044

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13. This repo demonstrates how to exploit…

android-securityeducationexploitation+3
21 year ago
Digital-Signature-Forgery-Attack preview

Digital-Signature-Forgery-Attack

GitHubdemining/digital-signature-forgery-attack

How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX

cryptographyctfcurated-resources+3
41 year ago
redteam-ai-benchmark preview

redteam-ai-benchmark

GitLabtoxy4ny/redteam-ai-benchmark

Red Team AI Benchmark: Evaluating LLMs for authorized offensive-security tasks. Red Team AI Benchmark is a CLI model-evaluation benchmark. It…

ai-securityeducationlabs-practice+3
22 months ago
Previous1234…13Next