Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
Reports preview

Reports

GitHubj4ck3lsyn-gen2/reports

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

binary-exploitationcurated-resourcesexploitation+8
2
1 month ago
wp2shell-scan preview

wp2shell-scan

GitHubinstawp/wp2shell-scan

Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

defensive-toolsforensicsincident-response+5
51 month ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

command-and-controldefensive-toolseducation+8
13 years ago
Arbitrary-File-Read-CVE-2024-24919 preview

Arbitrary-File-Read-CVE-2024-24919

GitHubluismateo1/arbitrary-file-read-cve-2024-24919

Walkthrough of detecting, investigating, and responding to a CVE-2024-24919 path traversal attack, including log analysis, threat intel checks, and…

educationexploitationincident-response+3
1 year ago
CitrixBleed-2-CVE-2025-5777-PoC- preview

CitrixBleed-2-CVE-2025-5777-PoC-

GitHubmingshenhk/citrixbleed-2-cve-2025-5777-poc-

Comprehensive PoC and detection toolkit for CVE-2025-5777 (CitrixBleed 2), an out-of-bounds memory read in NetScaler ADC/Gateway. Includes exploit…

defensive-toolseducationexploitation+7
171 year ago
Blackash-CVE-2025-53770 preview

Blackash-CVE-2025-53770

GitHubyosasasutsut/blackash-cve-2025-53770

Technical analysis and detection guidance for CVE-2025-53770, a critical unauthenticated RCE vulnerability in Microsoft SharePoint Server exploited…

exploitationforensicsincident-response+3
1 year ago
five-nights-at-follina-s preview

five-nights-at-follina-s

GitHubjeffreybxu/five-nights-at-follina-s

A Fullstack Academy Cybersecurity project examining the full cycle of the Follina (CVE-2022-30190) vulnerability, from exploit to detection and…

defensive-toolseducationexploitation+4
24 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubernestak/cve-2022-30190

Official guidance and workarounds for CVE-2022-30190, a remote code execution vulnerability in the Microsoft Support Diagnostic Tool (MSDT)…

defensive-toolseducationexploitation+3
4 years ago
CVE-2020-14882-weblogicRCE preview

CVE-2020-14882-weblogicRCE

GitHubcorelight/cve-2020-14882-weblogicrce

Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750

exploitationincident-responseintrusion-detection+3
75 years ago
CVE-2025-53770-Scanner preview

CVE-2025-53770-Scanner

GitHubzephrfish/cve-2025-53770-scanner

ToolShell scanner - CVE-2025-53770 and detection information

defensive-toolsexploitationincident-response+6
181 year ago
CrushFTP-AS2-Bypass-Research-CVE-2025-54309 preview

CrushFTP-AS2-Bypass-Research-CVE-2025-54309

GitHubsmileyface101/crushftp-as2-bypass-research-cve-2025-54309

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

authenticationdefensive-toolseducation+6
8 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHub0xblackash/cve-2026-48907

Advisory and detection guidance for CVE-2026-48907, a critical unauthenticated RCE in JCE Joomla content editor, with affected versions, IOCs, and…

exploitationincident-responsepenetration-testing+3
32 months ago
LogJackFix preview

LogJackFix

GitHubponeyclairdelune/logjackfix

A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.

defensive-toolsexploitationincident-response+3
4 years ago