Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
exchange_webshell_detection preview
Archived

exchange_webshell_detection

GitHubcert-lv/exchange_webshell_detection

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

forensicsincident-responseioc-management+3
99
5 years ago
DracOS preview

DracOS

GitHubscreetsec/dracos

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

educationexploitationforensics+8
589 years ago
openclaw-security-monitor preview

openclaw-security-monitor

GitHubadibirzu/openclaw-security-monitor

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

defensive-toolseducationforensics+9
481 month ago
Onapsis_CVE-2025-31324_Scanner_Tools preview

Onapsis_CVE-2025-31324_Scanner_Tools

GitHubonapsis/onapsis_cve-2025-31324_scanner_tools
exploitationforensicsincident-response+3
121 year ago
CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal preview

CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

GitHubadityabhatt3010/cve-2025-8088-winrar-zero-day-path-traversal

An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.

educationexploitationforensics+6
120 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubvaelwolf/cve-2022-1388

-- FOR EDUCATIONAL USE ONLY -- Proof-of-Concept RCE for CVE-2022-1388, plus some added functionality for blue and red teams

educationexploitationforensics+4
73 years ago
damn-vulnerable-log4j-app preview

damn-vulnerable-log4j-app

GitHubsnapattack/damn-vulnerable-log4j-app

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

digital-forensicseducationexploitation+3
54 years ago
wp2shell-scan preview

wp2shell-scan

GitHubinstawp/wp2shell-scan

Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

defensive-toolsforensicsincident-response+5
51 month ago
CVE-2025-53690-Analysis preview

CVE-2025-53690-Analysis

GitHubm0d0ri205/cve-2025-53690-analysis

This is CVE-2025-53690 Analysis Documents.

educationexploitationforensics+6
311 months ago
CVE-2025-66478 preview

CVE-2025-66478

GitHubexptechtw/cve-2025-66478
container-securityeducationexploitation+6
28 months ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190
command-and-controldefensive-toolseducation+8
13 years ago
onetwoseven-writeup preview

onetwoseven-writeup

GitHubdopaminauta/onetwoseven-writeup

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

ctfeducationexploitation+7
117 days ago
TryHack3M-Bricks-Heist preview

TryHack3M-Bricks-Heist

GitHubh0w1tzxr/tryhack3m-bricks-heist

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

ctfeducationexploitation+6
7 months ago
joomla-cve-2015-8562-exploit-and-linux-forensic-analysis preview

joomla-cve-2015-8562-exploit-and-linux-forensic-analysis

GitHubdrolley919/joomla-cve-2015-8562-exploit-and-linux-forensic-analysis
digital-forensicsexploitationforensics+3
2 months ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubahmetramazank/cve-2024-4577
educationexploitationforensics+5
1 year ago
CVE-2026-48908-joomla-sp-page-builder-detection preview

CVE-2026-48908-joomla-sp-page-builder-detection

GitHubg0thamrabb1t/cve-2026-48908-joomla-sp-page-builder-detection

Laboratory validation of CVE-2026-48908 in Joomla SP Page Builder, covering unauthorized icon upload, PHP file write, code execution as www-data,…

educationexploitationforensics+6
1 month ago
CVE-2026-48282-coldfusion-rds-detection preview

CVE-2026-48282-coldfusion-rds-detection

GitHubg0thamrabb1t/cve-2026-48282-coldfusion-rds-detection

Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS, covering arbitrary CFM file write, code execution as the ColdFusion service user,…

educationexploitationforensics+5
1 month ago
-SOC342---CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-and-RCE preview

-SOC342---CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-and-RCE

GitHubbossnick98/-soc342---cve-2025-53770-sharepoint-toolshell-auth-bypass-and-rce

An activity to train analysis skills and reporting

educationexploitationforensics+5
1 year ago
Previous12Next