Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
516 results
CVE-2026-12793 preview

CVE-2026-12793

GitHubabraxas/cve-2026-12793

Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates…

educationexploitationlabs-practice+5
18h 48m ago
HTB-NanoCorp-CVE-2024-0670 preview

HTB-NanoCorp-CVE-2024-0670

GitHubtaktak0x/htb-nanocorp-cve-2024-0670

PowerShell exploit for CVE-2024-0670 that abuses CheckMK Agent MSI repair to escalate privileges to SYSTEM on the NanoCorp Hack The Box machine.

ctfeducationexploitation+4
2 months ago
Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526- preview

Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-

GitHubshirouuu/gitea-template-sync-path-traversal-privilege-escalation-cve-2026-38526-

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

ctfeducationexploitation+7
3 days ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
4 days ago
cctv preview

cctv

GitHubledksv/cctv

HackTheBox CCTV walkthrough chaining CVE-2024-51482 ZoneMinder SQL injection, bcrypt hash cracking, and CVE-2025-60787 motionEye RCE to obtain root.

ctfeducationexploitation+6
4 days ago
devarea preview

devarea

GitHubledksv/devarea

HackTheBox DevArea walkthrough chaining CVE-2022-46364 Apache CXF SSRF, CVE-2025-54123 Hoverfly RCE, and SUID bash hijacking for root escalation.

ctfeducationexploitation+6
2 months ago
wingdata preview

wingdata

GitHubledksv/wingdata

HackTheBox Wingdata walkthrough covering WingFTP CVE-2025-47812 command injection for initial access and tar path traversal sudo privilege escalation…

ctfeducationexploitation+7
4 days ago
metasploit-pentest-report preview

metasploit-pentest-report

GitHubronankongala/metasploit-pentest-report

Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings…

ctfcurated-resourceseducation+7
18 days ago
JFrog_CVE-2026-65615-ByGLM preview

JFrog_CVE-2026-65615-ByGLM

GitHubbl0odz/jfrog_cve-2026-65615-byglm

JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)

educationexploitationlabs-practice+7
4 days ago
sunset-noontide-pentesting preview

sunset-noontide-pentesting

GitHubzales2004/sunset-noontide-pentesting

Description Professional penetration testing assessment of the Sunset: Noontide VulnHub machine, covering reconnaissance, service enumeration,…

ctfeducationexploitation+9
5 days ago
DEVVORTEX preview

DEVVORTEX

GitHubr3fr4kt/devvortex

HackTheBox Devvortex walkthrough covering subdomain fuzzing, Joomla API enumeration, template-based web shell, bcrypt hash cracking, and Apport-CLI…

ctfeducationinformation-gathering+7
5 days ago
CyberSecurity-Pentest-Lab preview

CyberSecurity-Pentest-Lab

GitHubgermarr93/cybersecurity-pentest-lab

CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab

ctfeducationexploitation+6
6 days ago
Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation preview

Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation

GitHubrhimavanth32-max/metasploitable2-reconnaissance-and-unrealircd-backdoor-exploitation

End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

ctfeducationexploitation+7
6 days ago
TryHackMe-Blue-MS17-010 preview

TryHackMe-Blue-MS17-010

GitHubporcumarcooo/tryhackme-blue-ms17-010

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

ctfdefensive-toolseducation+4
7 days ago
CVE-2026-60137-and-CVE-2026-63030 preview

CVE-2026-60137-and-CVE-2026-63030

GitHubivanesk315/cve-2026-60137-and-cve-2026-63030

Docker-based WordPress lab reproducing CVE-2026-60137 and CVE-2026-63030 pre-auth RCE, with a Python PoC exploit for SQLi, privilege escalation, and…

educationexploitationlabs-practice+6
7 days ago
BLUE-WRITEUP-CVE-2017-0144 preview

BLUE-WRITEUP-CVE-2017-0144

GitHubquincyomoruyi6-lang/blue-writeup-cve-2017-0144

Conducted a complete security assessment of an unpatched Windows 7 target ("Blue") to demonstrate the impact of legacy service vulnerabilities in an…

ctfeducationexploitation+7
17 days ago
ctf-tracker preview

ctf-tracker

GitHubxxdndxx/ctf-tracker

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

ctfeducationexploitation+6
66 days ago
cve-2010-4221-lab preview

cve-2010-4221-lab

GitHubdiegslva/cve-2010-4221-lab

From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented

binary-exploitationeducationexploitation+5
9 days ago
Previous12…29Next