Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
exploit-CVE-2016-10033 preview

exploit-CVE-2016-10033

GitHubopsxcq/exploit-cve-2016-10033

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

code-analysiseducationexploitation+6
408
3 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubdoocop/cve-2022-30190

Microsoft Office Word Rce 复现(CVE-2022-30190)

educationexploitationlabs-practice+3
594 years ago
DVAP preview

DVAP

GitHubsonuoffsec/dvap

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

ai-securityctfeducation+4
272 months ago
exim-rce-cve-2018-6789 preview

exim-rce-cve-2018-6789

GitHubmartinclauss/exim-rce-cve-2018-6789

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

binary-exploitationdebuggerseducation+3
111 month ago
Log4Shell-demo preview

Log4Shell-demo

GitHubmschmnet/log4shell-demo

Demo to show how Log4Shell / CVE-2021-44228 vulnerability works

educationexploitationlabs-practice+3
74 years ago
log4j-cve-2021-44228-sample preview

log4j-cve-2021-44228-sample

GitHubalpacamybags118/log4j-cve-2021-44228-sample

Sample docker-compose setup to show how this exploit works

educationexploitationlabs-practice+3
24 years ago
how-to-check-patch-secure-log4j-CVE-2021-44228 preview

how-to-check-patch-secure-log4j-CVE-2021-44228

GitHubanuvindhs/how-to-check-patch-secure-log4j-cve-2021-44228

A one-stop repo/ information hub for all log4j vulnerability-related information.

curated-resourceseducationinformation-gathering+3
24 years ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190
command-and-controldefensive-toolseducation+8
13 years ago
opsxcq-cve-2016-10033 preview

opsxcq-cve-2016-10033

GitHubawidardi/opsxcq-cve-2016-10033

To solve CTFS.me problem

ctfeducationexploitation+5
18 years ago
CVE-2019-15813 preview

CVE-2019-15813

GitHubwolf1892/cve-2019-15813

This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)

educationexploitationlabs-practice+3
15 years ago
ReactNext2Shell preview

ReactNext2Shell

GitHubfurkankayapinar/reactnext2shell

CVE-2025-55182 and CVE-2025-66478

educationexploitationlabs-practice+5
18 months ago
CVE-2022-30190-Follina-Lab preview

CVE-2022-30190-Follina-Lab

GitHubu1tr0nex/cve-2022-30190-follina-lab

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

command-and-controleducationexploitation+7
3 months ago
cve-2025-29927 preview

cve-2025-29927

GitHubgokul-krishnan-v-r/cve-2025-29927

Next.js and the corrupt middleware...TRY TO HACK IT..!

ctfeducationlabs-practice+3
1 year ago
CVE-2018-19518 preview

CVE-2018-19518

GitHubensimag-security/cve-2018-19518

some works on CVE-2018-19518

educationexploitationlabs-practice+2
7 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubyrkuo/cve-2022-30190
educationexploitationlabs-practice+3
3 years ago
jankybank preview

jankybank

GitHubeurogig/jankybank

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

ctfeducationexploitation+3
2 years ago
CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability

GitHubh4cknain/cve-2024-21413-microsoft-outlook-moniker-link-vulnerability
educationemail-securityexploitation+6
16 days ago
CVE-2022-4096 preview

CVE-2022-4096

GitHubaminetitrofine/cve-2022-4096

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

dns-analysiseducationexploitation+3
3 years ago
Previous12Next