Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
27 results
nextjs-middleware-auth-bypass-lab preview

nextjs-middleware-auth-bypass-lab

GitHubberraesen/nextjs-middleware-auth-bypass-lab

Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

authentication-authorizationeducationlabs-practice+3
1
20 days ago
svja preview

svja

GitHubtheronielanddaronpodcastshow/svja

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

api-security-testingauthentication-authorizationeducation+5
137 months ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5452 years ago
simple-maven preview

simple-maven

GitHubmindpatch/simple-maven
api-security-testingeducationlabs-practice+3
1 year ago
dvcsharp-api preview

dvcsharp-api

GitHubappsecco/dvcsharp-api

Damn Vulnerable C# Application (API)

api-security-testingeducationlabs-practice+3
852 years ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

command-and-controleducationexploitation+7
8 months ago
CVE-2026-47101-PoC preview

CVE-2026-47101-PoC

GitHublearner202649/cve-2026-47101-poc

The code for personally reproducing the corresponding vulnerability

api-security-testingauthentication-authorizationeducation+7
3 months ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
9 days ago
CVE-2026-55255-Lab preview

CVE-2026-55255-Lab

GitHubrootdirective-sec/cve-2026-55255-lab
api-security-testingeducationlabs-practice+3
1 month ago
CVE-2026-46645-Analysis-Lab preview

CVE-2026-46645-Analysis-Lab

GitHubrootdirective-sec/cve-2026-46645-analysis-lab
api-security-testingeducationlabs-practice+3
2 months ago
cve-2026-40072-ssrf-lab preview

cve-2026-40072-ssrf-lab

GitHubu1tr0nex/cve-2026-40072-ssrf-lab

Hands-on lab for CVE-2026-40072 — SSRF vulnerability in web3.py via CCIP Read (EIP-3668)

educationlabs-practicepenetration-testing+3
2 months ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
CVE-2014-6271-Shellshock- preview

CVE-2014-6271-Shellshock-

GitHubdrhaitham/cve-2014-6271-shellshock-

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

command-and-controlctfeducation+8
8 months ago
web-threat-mitigation preview

web-threat-mitigation

GitHubbrunoh6/web-threat-mitigation

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

configuration-auditingdevsecopseducation+8
1 year ago
CVE-2026-24055-OAuth-Langfuse preview

CVE-2026-24055-OAuth-Langfuse

GitHubimzanggg/cve-2026-24055-oauth-langfuse
api-security-testingeducationexploitation+3
15 days ago
CVE-2026-24136-Lab preview

CVE-2026-24136-Lab

GitHubblankbire/cve-2026-24136-lab

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

api-security-testingeducationlabs-practice+3
12 months ago
BadHost-CVE-2026-48710-Exploit preview

BadHost-CVE-2026-48710-Exploit

GitHubbhanunamikaze/badhost-cve-2026-48710-exploit

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

api-security-testingauthentication-authorizationexploitation+4
12 months ago
Previous12Next