Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
732 results
gha-lab-d14c91f1bb preview

gha-lab-d14c91f1bb

GitHubpvharmo2/gha-lab-d14c91f1bb

Security-research lab: reproduction of CVE-2025-58371 (GitHub Actions command injection via PR title in Discord PR Notifier), snapshot of…

curated-resourceseducationexploitation+1
23 days ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubj4ck3lsyn-gen2/cve-2025-53770

Lab & PoC

container-securityeducationexploitation+5
16 months ago
CVE-2025-34159 preview

CVE-2025-34159

GitHubeyodav/cve-2025-34159

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

cloud-securitycontainer-securityexploitation+5
1 year ago
WMIHACKER preview

WMIHACKER

GitHubrootclay/wmihacker

A Bypass Anti-virus Software Lateral Movement Command Execution Tool

command-and-controlexploitationlateral-movement+2
1.5k1 year ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubpeakcyber-security/cve-2025-14847

CVE-2025-14847 | MongoBleed vulnerability proof of concept project

database-securityeducationexploitation+3
28 months ago
LibPNG_OSS-Fuzz preview

LibPNG_OSS-Fuzz

GitHubenessar/libpng_oss-fuzz

Security research project on fuzzing libpng with OSS-Fuzz. Includes seed corpus analysis, custom read/write fuzzers, and a proof-of-concept exploit…

binary-analysiscode-analysiseducation+3
111 months ago
Detect-BlueKeep preview

Detect-BlueKeep

GitHubtranqtruong/detect-bluekeep

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

educationexploitationintrusion-detection+3
11 year ago
CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE preview

CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50364_csrf_add_category-phpgurukul-cve

Proof-of-concept CSRF exploit targeting CVE-2025-50364 in PHPGurukul Maid Hiring Management System v1.0 that adds arbitrary admin categories via a…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
gcat preview
Archived

gcat

GitHubbyt3bl33d3r/gcat

A PoC backdoor that uses Gmail as a C&C server

command-and-controlexploitationpayload-development+4
1.4k7 years ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4394 years ago
android-workprofile-exploit preview

android-workprofile-exploit

GitHubhasan-al-hussein/android-workprofile-exploit

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

android-securitydata-exfiltrationeducation+5
11 month ago
cve-2023-44487-demo preview

cve-2023-44487-demo

GitHubzanks08/cve-2023-44487-demo

Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)

educationexploitationintrusion-detection+5
11 year ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
2 months ago
CVE-2026-36981-Kernel-EoP-PoC preview

CVE-2026-36981-Kernel-EoP-PoC

GitHubcanomer/cve-2026-36981-kernel-eop-poc

Project Date : Feb 2026 / Memory corruption vulnerability within the kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel…

binary-exploitationdebuggersexploitation+4
24 months ago
CVE-2022-29170 preview

CVE-2022-29170

GitHubyijikeji/cve-2022-29170

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to…

cloud-securityexploitationmisconfiguration+2
3 years ago
CVE-2023-6401 preview

CVE-2023-6401

GitHubmekitoci/cve-2023-6401

CVE-2023-6401 is a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a malicious `dbghelp.dll` file in the…

binary-exploitationeducationexploitation+2
1 year ago
cve-2021-42013-apache preview

cve-2021-42013-apache

GitHubdream434/cve-2021-42013-apache

On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server…

educationexploitationpenetration-testing+2
1 year ago
weblogic-cve-2020-14882 preview

weblogic-cve-2020-14882

GitHubkkc73/weblogic-cve-2020-14882

This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilment of ACS EDU Program.

educationexploitationpapers-research+2
1 year ago
Previous1234…41Next