Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
cve-2026-31431 preview

cve-2026-31431

GitHubvasyapokemon/cve-2026-31431

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

curated-resourcesdigital-forensicseducation+8
4 months ago
CVE-2026-31431-CopyFail-Lab preview

CVE-2026-31431-CopyFail-Lab

GitHubu1tr0nex/cve-2026-31431-copyfail-lab

Lab testing documentation for CVE-2026-31431 (Copy Fail) Linux kernel LPE

binary-exploitationeducationexploitation+3
4 months ago
CopyFail-Exploits-CVE-2026-31431 preview

CopyFail-Exploits-CVE-2026-31431

GitHubshotafry/copyfail-exploits-cve-2026-31431

Multi-language educational exploit implementations for CVE-2026-31431, a Linux kernel local privilege escalation via the algif_aead module, with a…

binary-exploitationctfeducation+4
74 months ago
CVE-2025-3052 preview

CVE-2025-3052

GitHubthemalwareguardian/cve-2025-3052

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

binary-analysiseducationembedded-systems-security+5
1 month ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
5 months ago
HiddenSteps preview

HiddenSteps

GitHubjgalego/hiddensteps

HiddenSteps — a local-first personal workflow intelligence platform

ctfcurated-resourcesdata-exfiltration+8
51 month ago
Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability preview

Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability

GitHubkasunpriyashan/y2s1-project-linux-exploitaion-using-cve-2016-5195-vulnerability

Educational Linux privilege escalation exploit targeting CVE-2016-5195 (Dirty COW) to demonstrate kernel vulnerability exploitation and root access…

binary-exploitationeducationexploitation+4
4 years ago
wazuh-nginx-cve-2026-42945-sca-lab preview

wazuh-nginx-cve-2026-42945-sca-lab

GitHubsoksofos/wazuh-nginx-cve-2026-42945-sca-lab

Centralized Wazuh SCA Assessment for CVE-2026-42945 on NGINX Servers

configuration-auditingdefensive-toolseducation+3
4 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubrheodev/cve-2026-42945

NGINX Rift 漏洞分析与复现

binary-exploitationeducationexploitation+4
234 months ago
polkit-CVE-2021-3560_writeup preview

polkit-CVE-2021-3560_writeup

GitHubrealatharva15/polkit-cve-2021-3560_writeup

beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560

binary-exploitationctfeducation+4
8 months ago
GitPython-Exploit-CVE-2022-24439 preview

GitPython-Exploit-CVE-2022-24439

GitHubmakkkiiii/gitpython-exploit-cve-2022-24439

Method I used for my Practical Pentest Module.

educationexploitationlabs-practice+2
11 year ago
drupalgeddon2-cli preview

drupalgeddon2-cli

GitHubnayem-m/drupalgeddon2-cli

CLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education

educationexploitationlabs-practice+3
3 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubquantumworld-dpdns-io/cve-2026-42945

Full CVE-2026-42945 research repository with heap buffer overflow analysis, RCE exploit (heap spray + Feng Shui), detection scripts, and patching…

binary-exploitationeducationexploitation+6
4 months ago
sudoinjection preview

sudoinjection

GitHubmikivirus0/sudoinjection

Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)

binary-exploitationctfeducation+5
21 year ago
CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh preview

CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh

GitHubrauljvc8/cve-2025-68616-detecting-and-patching-an-ssrf-in-weasyprint-with-wazuh

Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

educationincident-responseintrusion-detection+3
2 months ago
nginx-rift-private-lab preview

nginx-rift-private-lab

GitHubhamid-k/nginx-rift-private-lab

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

binary-exploitationctfeducation+8
774 months ago
CVE-2022-0543-Home-Lab preview

CVE-2022-0543-Home-Lab

GitHubnetw0rk7/cve-2022-0543-home-lab

CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER

container-securityeducationexploitation+5
10 months ago
CVE-2021-36394-Pre-Auth-RCE-in-Moodle preview

CVE-2021-36394-Pre-Auth-RCE-in-Moodle

GitHublavclash75/cve-2021-36394-pre-auth-rce-in-moodle

Pre-authentication remote code execution exploit targeting Moodle's Shibboleth authentication module. Includes Docker-based lab environment for…

educationexploitationlabs-practice+3
94 years ago
Previous12Next