Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
pacu preview

pacu

GitHubrhinosecuritylabs/pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

cloud-infrastructure-securitycloud-securitydata-exfiltration+7
5.3k
5 months ago
CyberStrike preview

CyberStrike

GitHubcyberstrikeus/cyberstrike

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

ai-securitycloud-securityeducation+9
2.5k20h 24m ago
pentest-ai-agents preview

pentest-ai-agents

GitHub0xsteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

ai-securitycloud-securityeducation+8
2.2k18 days ago
SCOPE preview

SCOPE

GitHubtayontech/scope

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

ai-securitycloud-infrastructure-securitycloud-security+8
542 months ago
cve-2026-31431 preview

cve-2026-31431

GitHubseanrickerd/cve-2026-31431

Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers…

binary-exploitationcloud-infrastructure-securitycontainer-security+4
124 months ago
poc-2025-9074 preview

poc-2025-9074

GitHubxwpdx0/poc-2025-9074

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

cloud-infrastructure-securitycommand-and-controlcontainer-security+7
48 months ago
copy_fail preview

copy_fail

GitHubspensercai/copy_fail

Rust exploit PoC for Linux kernel LPE CVE-2026-31431 (AF_ALG page-cache write) plus eBPF runtime defense blocking AF_ALG socket creation via LSM or…

binary-exploitationdefensive-toolsexploitation+4
34 months ago
copy-fail-CVE-2026-31431 preview

copy-fail-CVE-2026-31431

GitHubwuzuowei/copy-fail-cve-2026-31431

Exploit for CVE-2026-31431, a Linux kernel authencesn vulnerability enabling local privilege escalation to root and container escape via AF_ALG and…

container-escapeexploitationexploit-frameworks+2
4 months ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
8 months ago
openclarity preview
Archived

openclarity

GitHubopenclarity/openclarity

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

cloud-infrastructure-securitycloud-securitycontainer-security+7
1.5k3 months ago
metasploitable3 preview

metasploitable3

GitHubrapid7/metasploitable3

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

dynamic-analysis-sandboxingeducationexploit-frameworks+4
5.7k1 year ago
copyfail-exploit preview

copyfail-exploit

GitHubxeloxa/copyfail-exploit

Copy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.

binary-exploitationcontainer-escapeexploitation+3
254 months ago
abaddon preview
Archived

abaddon

GitHubwavestone-cdt/abaddon

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

cloud-infrastructure-securitycommand-and-controlexploit-frameworks+5
3313 years ago
Cerberus-React2Shell-Scanner-Exploit preview

Cerberus-React2Shell-Scanner-Exploit

GitHubcerberusmrxi/cerberus-react2shell-scanner-exploit

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

command-and-controleducationexploit-frameworks+9
212 days ago
Previous12Next