Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1229 results
DEVVORTEX preview

DEVVORTEX

GitHubr3fr4kt/devvortex

HackTheBox Devvortex walkthrough covering subdomain fuzzing, Joomla API enumeration, template-based web shell, bcrypt hash cracking, and Apport-CLI…

ctfeducationinformation-gathering+7
6h 36m ago
CyberSecurity-Pentest-Lab preview

CyberSecurity-Pentest-Lab

GitHubgermarr93/cybersecurity-pentest-lab

CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab

ctfeducationexploitation+6
21h 58m ago
Spring4Shell-POC preview

Spring4Shell-POC

GitHublunasec-io/spring4shell-poc

This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).

exploitationlabs-practicepayload-development+4
1064 years ago
AfterLife preview

AfterLife

GitHubhet-p301204/afterlife

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706…

authenticationdefensive-toolseducation+5
1 day ago
CVE-2026-85706_docker_exp preview

CVE-2026-85706_docker_exp

GitHubflowerwitch/cve-2026-85706_docker_exp

Docker-based reproduction environment and PoC for CVE-2026-85706, demonstrating GitLab LFI bypass via .json suffix and trailing slash path tricks.

container-securityexploitationlabs-practice+4
1 day ago
secdim-assurance-drift-challenge preview

secdim-assurance-drift-challenge

GitHubfranklincg/secdim-assurance-drift-challenge

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

api-securityauthentication-authorizationctf+5
1 day ago
Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation preview

Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation

GitHubrhimavanth32-max/metasploitable2-reconnaissance-and-unrealircd-backdoor-exploitation

End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

ctfeducationexploitation+7
1 day ago
TryHackMe-Blue-MS17-010 preview

TryHackMe-Blue-MS17-010

GitHubporcumarcooo/tryhackme-blue-ms17-010

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

ctfdefensive-toolseducation+4
1 day ago
how_to_become_a_malware_analyst preview

how_to_become_a_malware_analyst

GitHubpinksawtooth/how_to_become_a_malware_analyst

Curated guide to becoming a malware analyst, covering essential knowledge, reverse engineering, analysis tools, and LLM-assisted learning with…

binary-analysisctfcurated-resources+7
2794 days ago
CVE-2026-76578 preview

CVE-2026-76578

GitHubbrainbob/cve-2026-76578

Proof-of-concept exploit for CVE-2026-76578 and CVE-2026-76560, chaining anonymous LDAP ADD with a 389-ds SELFDN bypass to gain FreeIPA domain admin…

authenticationexploitationidentity-management+5
2 days ago
CVE-2023-25157 preview

CVE-2023-25157

GitHubivanesk315/cve-2023-25157

Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.

database-securityeducationexploitation+6
2 days ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubivanesk315/cve-2026-18963

Docker-based lab and Python exploit for CVE-2026-18963, a Keycloak reset-credentials flow bypass enabling account takeover via email verification…

authenticationeducationexploitation+6
2 days ago
CVE-2026-53519 preview

CVE-2026-53519

GitHubivanesk315/cve-2026-53519

Docker lab reproducing CVE-2026-53519, a pre-auth path traversal in Nezha Dashboard that leaks jwt_secret_key and enables JWT forgery and admin…

authenticationeducationexploitation+5
2 days ago
BLUE-WRITEUP-CVE-2017-0144 preview

BLUE-WRITEUP-CVE-2017-0144

GitHubquincyomoruyi6-lang/blue-writeup-cve-2017-0144

Conducted a complete security assessment of an unpatched Windows 7 target ("Blue") to demonstrate the impact of legacy service vulnerabilities in an…

ctfeducationexploitation+7
12 days ago
CVE-2026-0303 preview

CVE-2026-0303

GitHubyonliud/cve-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

code-analysisdevsecopseducation+5
1 day ago
ctf-tracker preview

ctf-tracker

GitHubxxdndxx/ctf-tracker

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

ctfeducationexploitation+6
25 days ago
wraith preview

wraith

GitHubarcanum-sec/wraith

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

command-and-controleducationexploitation+6
1401 month ago
log4shell-exploitation-detection preview

log4shell-exploitation-detection

GitHubkalidoulabghaly/log4shell-exploitation-detection

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

container-securityeducationexploitation+5
4 days ago
Previous12…69Next