Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
164 results
From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps preview

From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps

GitHubmrk336/from-foothold-to-domain-admin-weaponizing-cve-2025-54918-in-real-world-devops

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

cloud-securityconfiguration-auditingdevsecops+7
4
11 months ago
redtail-ioc preview

redtail-ioc

GitHublukeslp/redtail-ioc

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…

curated-resourcesdigital-forensicseducation+6
21 month ago
Ghost-CMS-Code-Injection-Audit-CVE-2026-26980 preview

Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

GitHubkulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

code-analysisdefensive-toolsincident-response+3
3 months ago
Confluence-CVE-2022-26134 preview

Confluence-CVE-2022-26134

GitHubarchanchoudhury/confluence-cve-2022-26134

This repository talks about Zero-Day Exploitation of Atlassian Confluence, it's defense and analysis point of view from a SecOps or Blue Team…

educationexploitationforensics+6
44 years ago
shai-scan preview

shai-scan

GitHubdigi4care/shai-scan

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

code-analysisdevsecopsincident-response+6
3 months ago
panrapidcheck preview

panrapidcheck

GitHubhackinglz/panrapidcheck

Extract useful information from PANOS support file for CVE-2024-3400

forensicsincident-responseioc-management+3
21 year ago
airborn-IOS-CVE-2025-24252 preview

airborn-IOS-CVE-2025-24252

GitHubcakescats/airborn-ios-cve-2025-24252

iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252

digital-forensicseducationforensics+5
31 year ago
CVE-2019-19871-AuditGuide preview

CVE-2019-19871-AuditGuide

GitHubvdisec/cve-2019-19871-auditguide

Audit Guide for the Citrix ADC Vulnerability CVE-2019-19871. Collected from multiple sources and threat assessments. Will be updated as new methods…

curated-resourceseducationforensics+3
26 years ago
five-nights-at-follina-s preview

five-nights-at-follina-s

GitHubjeffreybxu/five-nights-at-follina-s

A Fullstack Academy Cybersecurity project examining the full cycle of the Follina (CVE-2022-30190) vulnerability, from exploit to detection and…

defensive-toolseducationexploitation+4
24 years ago
tarian preview

tarian

GitHubdevopstoday11/tarian

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

cloud-securitycontainer-securitydevsecops+2
24 years ago
YellowKey-WinRE-Remediation preview

YellowKey-WinRE-Remediation

GitHubeverest90909/yellowkey-winre-remediation

Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package…

configuration-auditingdefensive-toolsincident-response+2
13 months ago
pulse-meter preview

pulse-meter

GitHubrxwx/pulse-meter

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

exploitationforensicsincident-response+3
11 year ago
LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197 preview

LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197

GitHubarkha-corvus/letsdefend-soc235-atlassian-confluence-broken-access-control-0-day-cve-2023-22515-eventid-197

I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian…

educationincident-responselog-analysis+3
110 months ago
From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack preview

From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack

GitHubmrk336/from-eternalblue-to-cve-2025-2776-the-evolution-of-an-smb-attack

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

educationexploitationincident-response+4
11 months ago
How-to-Patch-CVE-2025-32709 preview

How-to-Patch-CVE-2025-32709

GitHubadnansiyat/how-to-patch-cve-2025-32709

Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots,…

configuration-auditingeducationincident-response+3
11 months ago
cve-lfi-lab preview

cve-lfi-lab

GitHubthecyberfairy/cve-lfi-lab

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

ctfeducationincident-response+5
1 year ago
xz-backdoor-scan preview

xz-backdoor-scan

GitHubjuul/xz-backdoor-scan

Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)

binary-analysisforensicsgeneral-purpose-utilities+3
2 years ago
log4shell-data preview

log4shell-data

GitHubhoneynet/log4shell-data

Data we are receiving from our honeypots about CVE-2021-44228

incident-responseinformation-gatheringintrusion-detection+3
4 years ago
Previous1…345…10Next