Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
44 results
PaperCut-CVE-2026-81578-82078 preview

PaperCut-CVE-2026-81578-82078

GitHubyora1928/papercut-cve-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

educationexploitationlabs-practice+4
5 days ago
sadcloud preview

sadcloud

GitHubnccgroup/sadcloud

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

cloud-infrastructure-securitycloud-securityeducation+3
7882 years ago
cve-2021-41773-source-code-analysis preview

cve-2021-41773-source-code-analysis

GitHubkunalkhandelwal-dev/cve-2021-41773-source-code-analysis

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

code-analysiseducationlabs-practice+2
1 month ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

ai-securitycloud-securityeducation+5
21 month ago
clickfix-simulator-2025 preview

clickfix-simulator-2025

GitHubboredchilada/clickfix-simulator-2025

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

educationlabs-practicepenetration-testing+4
49 months ago
DeepTrap preview

DeepTrap

GitHubzjuicsr/deeptrap

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

adversarial-attackai-securitycommand-and-control+8
103 months ago
MongoBleed preview

MongoBleed

GitHubsho-luv/mongobleed

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…

ctfdatabase-securityeducation+6
26 months ago
fortigate-cve-2022-40684-tool preview

fortigate-cve-2022-40684-tool

GitHubpintukumar-sutradhar/fortigate-cve-2022-40684-tool

FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.

educationexploitationlabs-practice+3
5 months ago
cve-2026-54316-lab preview

cve-2026-54316-lab

GitHubinertfluid/cve-2026-54316-lab

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

ctfdata-exfiltrationeducation+5
2 months ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubj4ck3lsyn-gen2/cve-2025-53770

Lab & PoC

container-securityeducationexploitation+5
15 months ago
CVE-2024-27198_LAB preview

CVE-2024-27198_LAB

GitHubne0zer01/cve-2024-27198_lab

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

authentication-authorizationeducationexploitation+8
3 months ago
CVE-2024-21413-Vulnerabilidad-Outlook-LAB preview

CVE-2024-21413-Vulnerabilidad-Outlook-LAB

GitHubd1se0/cve-2024-21413-vulnerabilidad-outlook-lab

Educational lab demonstrating CVE-2024-21413 Outlook vulnerability exploitation with Python email exploit tool and Responder for NTLM credential…

educationemail-securityexploitation+4
41 year ago
Blind-Trust-CVE-2024-21413-Research preview

Blind-Trust-CVE-2024-21413-Research

GitHubh1ssbl1tz/blind-trust-cve-2024-21413-research

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

educationemail-securityexploitation+7
2 months ago
ReactNext2Shell preview

ReactNext2Shell

GitHubfurkankayapinar/reactnext2shell

CVE-2025-55182 and CVE-2025-66478

educationexploitationlabs-practice+5
18 months ago
athena preview

athena

GitHubathena-os/athena

Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

educationlabs-practicelearning-paths-courses+3
1.3k9 days ago
cve-2025-32433_rce_exploit preview
Archived

cve-2025-32433_rce_exploit

GitHubgiriaryan694-a11y/cve-2025-32433_rce_exploit

This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHackMe lab environment.

binary-exploitationeducationexploitation+5
8 months ago
NextJS-CVE-2025-29927-Docker-Lab preview

NextJS-CVE-2025-29927-Docker-Lab

GitHubenochgitgamefied/nextjs-cve-2025-29927-docker-lab

Docker-based lab for exploring and reproducing the Next.js CVE-2025-29927 middleware authorization bypass vulnerability. Includes vulnerable app,…

authentication-authorizationeducationlabs-practice+3
7 months ago
cve-2019-9184 preview

cve-2019-9184

GitHubcved-sources/cve-2019-9184

Docker container with a pre-configured vulnerable environment for CVE-2019-9184, designed for security testing and educational exploitation practice.

container-securityeducationexploitation+3
5 years ago
Previous123Next