Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
104 results
cve-2024-36401-security-simulator preview

cve-2024-36401-security-simulator

GitHubraniaemran/cve-2024-36401-security-simulator

Educational Python simulator modeling a fictional security incident inspired by CVE-2024-36401 to demonstrate vulnerability management, segmentation,…

defensive-toolseducationincident-response+5
8 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
8 days ago
CVE-2026-20131 preview

CVE-2026-20131

GitHubsak110/cve-2026-20131

Detection and proof-of-concept exploit for CVE-2026-20131, a critical unauthenticated Java deserialization RCE in Cisco Secure FMC. Includes a safe…

educationexploitationlabs-practice+4
36 months ago
vuln4japi preview

vuln4japi

GitHubnix-xin/vuln4japi

A vulnerable Java based REST API for demonstrating CVE-2021-44228 (log4shell).

educationexploitationlabs-practice+3
14 years ago
cve-2021-4034-playground preview

cve-2021-4034-playground

GitHubsilocityit/cve-2021-4034-playground

A hands-on binary exploitation challenge based on CVE-2021-4034, designed for practicing privilege escalation techniques in a controlled environment.

binary-exploitationctfeducation+2
4 years ago
Mass-Scanner-CVE-2026-3891 preview

Mass-Scanner-CVE-2026-3891

GitHubanggatechi/mass-scanner-cve-2026-3891

Python-based mass scanner for validating a specific WordPress AJAX behavior in authorized environments, supporting URL normalization, endpoint…

educationlabs-practicepenetration-testing+2
25 months ago
mtechweek_04 preview

mtechweek_04

GitHubaish19siddiqua-commits/mtechweek_04

Documented penetration test on an isolated Metasploitable2 VM using Metasploit and Nmap, covering remote exploitation, privilege escalation, and…

educationexploitationlabs-practice+5
1 month ago
CVE-2007-2447-Exploitation-SIEM-Detection-Lab preview

CVE-2007-2447-Exploitation-SIEM-Detection-Lab

GitHubharshiys/cve-2007-2447-exploitation-siem-detection-lab

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

educationexploitationexploit-frameworks+7
1 month ago
EvilFontTool preview

EvilFontTool

GitHubdoctoreww/evilfonttool

A font-based deception tool for red teaming, security research, and whatever else.

adversarial-attackai-securityeducation+3
3491 month ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubgodoy-sec/cve-2017-14980

Study of a classic stack-based buffer overflow vulnerability in a controlled lab environment for educational purposes.

binary-exploitationdebuggerseducation+5
11 month ago
LOAD preview

LOAD

GitHub0xballpoint/load

Lord Of Active Directory - automatic vulnerable active directory on AWS

cloud-infrastructure-securityeducationlabs-practice+3
1562 years ago
CVE-2021-3156-Project preview

CVE-2021-3156-Project

GitHubshams-ul-mehmood/cve-2021-3156-project

Educational lab environment for CVE-2021-3156 (Baron Samedit) with a Dockerized vulnerable sudo target, exploit scaffold, canary test, root-cause…

binary-exploitationeducationexploitation+3
1 month ago
redxor preview

redxor

GitHubcorelight/redxor

Detection of Linux Malware C2 RedXOR - demonstration

defensive-toolseducationintrusion-detection+3
35 years ago
cve-2021-41773-source-code-analysis preview

cve-2021-41773-source-code-analysis

GitHubkunalkhandelwal-dev/cve-2021-41773-source-code-analysis

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

code-analysiseducationlabs-practice+2
1 month ago
cve-2024-49113-ldap_nightmare_reproduction preview

cve-2024-49113-ldap_nightmare_reproduction

GitHubrazureink/cve-2024-49113-ldap_nightmare_reproduction

Reproduction of cve-2024-49113-ldap_nightmare_reproduction

binary-exploitationeducationexploitation+4
2 months ago
bitpixie preview

bitpixie

GitHublr2006-robot/bitpixie

Cracking BitLocker encryption based on CVE-2023-21563 vulnerability

educationencryption-decryption-toolsexploitation+5
33 months ago
CVE-2023-25157-GeoServer-SQLi-Lab preview

CVE-2023-25157-GeoServer-SQLi-Lab

GitHubgiangdurian/cve-2023-25157-geoserver-sqli-lab

Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

database-securityeducationlabs-practice+3
2 months ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
93811 months ago
Previous123456Next