Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
681 results
100DaysofYARA preview

100DaysofYARA

GitHubsquiblydoo/100daysofyara

Rules shared by the community from 100 Days of YARA 2026

curated-resourceseducationlabs-practice+3
5
5 months ago
CVE-2012-2982-Python-PoC preview

CVE-2012-2982-Python-PoC

GitHubcd6629/cve-2012-2982-python-poc

This was converted from a metasploit module as an exercise for OSCP studying

educationexploitationlabs-practice+3
55 years ago
firefox-rce-nssmil preview

firefox-rce-nssmil

GitHubsoham23/firefox-rce-nssmil

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

binary-exploitationctfeducation+3
11 month ago
From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps preview

From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps

GitHubmrk336/from-foothold-to-domain-admin-weaponizing-cve-2025-54918-in-real-world-devops

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

cloud-securityconfiguration-auditingdevsecops+7
411 months ago
MC-Log4j-Patcher preview

MC-Log4j-Patcher

GitHubkoupah/mc-log4j-patcher

A singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).

educationexploitationgeneral-purpose-utilities+2
44 years ago
delirium-ai-safety-benchmark preview

delirium-ai-safety-benchmark

GitLabtoxy4ny/delirium-ai-safety-benchmark

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…

adversarial-attackai-securityeducation+2
126 days ago
AgentCyTE preview

AgentCyTE

GitHubanantaakotal/agentcyte

Generates reproducible CORE network topologies from XML scenario files for cybersecurity training and experimentation. Provides Web GUI and CLI for…

educationlabs-practicenetwork-security+3
38 months ago
CVE-2023-3824 preview

CVE-2023-3824

GitHubjhonnybonny/cve-2023-3824

Vulnerability in PHP Phar files, due to buffer overflow, arises from insufficient length checks on file names within the Phar archive. Malicious…

binary-exploitationeducationexploitation+2
32 years ago
rootpacket-cve-2026-31431 preview

rootpacket-cve-2026-31431

GitHubkinryulabs/rootpacket-cve-2026-31431

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

container-escapecontainer-securitycryptography+5
21 month ago
shazhupan preview

shazhupan

GitHubpacketrat/shazhupan

Slides and IoCs from pig butchering research

curated-resourceseducationosint+2
52 years ago
redtail-ioc preview

redtail-ioc

GitHublukeslp/redtail-ioc

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…

curated-resourcesdigital-forensicseducation+6
21 month ago
Orbit Tracer preview

Orbit Tracer

GitLabrajus-agent/orbit-tracer

Orbit Tracer Security Agent for intelligent security remediation. Traces vulnerability blast radius using Orbit's knowledge graph, scores risk,…

ai-securitycode-analysisdevsecops+3
1 month ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
2 months ago
CVE-2026-6992-PoC preview

CVE-2026-6992-PoC

GitHubnicholas-howland/cve-2026-6992-poc

Vulnerability proof of concept reworked from https://github.com/utmost3/cve/issues/2 I take no credit for discovering the vulnerability. This is for…

binary-exploitationbluetooth-securityeducation+3
1 month ago
Hack-The-Box-Nexus-Findings-Report preview

Hack-The-Box-Nexus-Findings-Report

GitHubmmoobbeeiidat-design/hack-the-box-nexus-findings-report

HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in…

ctfeducationexploitation+6
1 month ago
Analysis-for-stage1-shellcode-loader-from-hacking- preview

Analysis-for-stage1-shellcode-loader-from-hacking-

GitHubspiralbl0ck/analysis-for-stage1-shellcode-loader-from-hacking-

Analysis for stage1 shellcode loader from hacking

binary-analysiseducationmalware-analysis+2
31 year ago
TwoMillion-Machine-Writeup preview

TwoMillion-Machine-Writeup

GitHubanxs3c/twomillion-machine-writeup

From deobfuscating code.js to root, CVE-2023-0386

ctfeducationexploitation+7
2 months ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
Previous1…8910…38Next