Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

NewestRelevanceMost popularRecently updated
41 results
DFIR-LABS preview

DFIR-LABS

GitHubazr43lkn1ght/dfir-labs

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

ctfdigital-forensicsdisk-forensics+6
5859 months ago
CVE-2026-2964-Lab preview

CVE-2026-2964-Lab

GitHubthegenetic/cve-2026-2964-lab

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

code-analysiseducationexploitation+4
6 months ago
security-writeups preview

security-writeups

GitHubalzeaty1/security-writeups

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

ctfeducationlabs-practice+5
1 month ago
awesome-ios-security preview

awesome-ios-security

GitHubcy-clon3/awesome-ios-security

A curated list of awesome iOS application security resources.

ctfcurated-resourcesdynamic-analysis-sandboxing+9
6712 years ago
CVE-2019-11043-Vulnerability preview

CVE-2019-11043-Vulnerability

GitHubmagentabear/cve-2019-11043-vulnerability

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

educationexploitationlabs-practice+8
9 months ago
Cyber-Defenders-lab- preview

Cyber-Defenders-lab-

GitHubabiral-timalsina/cyber-defenders-lab-

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

digital-forensicseducationincident-response+3
1 month ago
workshop_firmware_reverse_engineering preview

workshop_firmware_reverse_engineering

GitHubemproof-com/workshop_firmware_reverse_engineering

Workshop on firmware reverse engineering

binary-analysiseducationembedded-systems-security+6
45111 months ago
CVE-2026-52813-Gogs-RCE preview

CVE-2026-52813-Gogs-RCE

GitHubiqx6889/cve-2026-52813-gogs-rce

CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive…

educationincident-responseioc-management+6
11 month ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
92310 days ago
wrongsecrets-binaries preview

wrongsecrets-binaries

GitHubowasp/wrongsecrets-binaries

Source code for the Binaries of OWASP WrongSecrets

binary-analysiscode-analysisctf+6
123 days ago
CVE-2026-25632 preview

CVE-2026-25632

GitHublazarus0x1337/cve-2026-25632

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

code-analysiseducationexploitation+4
11 month ago
hackaday-u preview

hackaday-u

GitHubwrongbaud/hackaday-u

Course materials for hackaday.io Ghidra training

binary-analysiseducationlabs-practice+3
4472 years ago
qub-network-security-cve-2023-20198 preview

qub-network-security-cve-2023-20198

GitHubdominic471/qub-network-security-cve-2023-20198

Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment

educationexploitationids-ips-evasion+6
1 year ago
CVE-2020-7598 preview

CVE-2020-7598

GitHubrenewablehacking/cve-2020-7598

Educational lab demonstrating CVE-2020-7598 prototype pollution in minimist with a vulnerable Node.js/Express app, exploit payload, and…

code-analysiseducationlabs-practice+3
3 months ago
wp2shell-lab preview

wp2shell-lab

GitHub47cid/wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

code-analysisctfeducation+7
152 months ago
SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400- preview

SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-

GitHubcyberbibs/soc274---palo-alto-networks-pan-os-command-injection-vulnerability-exploitation-cve-2024-3400-

Step-by-step SOC analyst walkthrough for investigating and remediating CVE-2024-3400 (PAN-OS command injection). Covers detection, log analysis,…

digital-forensicseducationincident-response+6
1 year ago
LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell preview

LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell

GitHubmichaael01/letsdefend--soc-342-cve-2025-53770-sharepoint-exploit-toolshell

Detailed walkthrough of CVE-2025-53770 (ToolShell) SharePoint zero-day exploitation, including RCE analysis, MachineKey exfiltration, payload…

digital-forensicseducationexploitation+8
11 months ago
lab_xz_backdoor preview

lab_xz_backdoor

GitHubstevehenderson/lab_xz_backdoor

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

educationexploitationforensics+6
3 months ago
Previous123Next