Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
219 results
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

cloud-securitycontainer-securityeducation+7
1
4 days ago
drupalgeddon2-cve-lab preview

drupalgeddon2-cve-lab

GitHubvaibhav91one/drupalgeddon2-cve-lab

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

container-securityeducationlabs-practice+3
4 days ago
CVE-2026-12243-NLTK-PoC preview

CVE-2026-12243-NLTK-PoC

GitHubmorzelowski/cve-2026-12243-nltk-poc

Docker lab demonstrating CVE-2026-12243 path traversal in NLTK before 3.10.0, contrasting vulnerable and patched behavior with a synthetic secret in…

container-securityeducationlabs-practice+2
5 days ago
specterops-k8s-red-teamers-libvirt-patch preview

specterops-k8s-red-teamers-libvirt-patch

GitHubgregdurys/specterops-k8s-red-teamers-libvirt-patch

Unofficial libvirt patch for the free SpecterOps Kubernetes for Red Teamers lab

cloud-securityeducationlabs-practice+1
135 days ago
CVE-2026-39987-Lab preview

CVE-2026-39987-Lab

GitHubrootdirective-sec/cve-2026-39987-lab

Local Docker lab reproducing CVE-2026-39987, a pre-auth RCE in marimo's terminal WebSocket. Compares vulnerable and patched versions with least-harm…

container-securityeducationexploitation+3
14 months ago
CVE-2026-23744-Lab preview

CVE-2026-23744-Lab

GitHubrootdirective-sec/cve-2026-23744-lab

Docker lab to compare vulnerable and patched builds of MCPJam Inspector for CVE-2026-23744, demonstrating network binding differences and API…

container-securityeducationlabs-practice+2
6 months ago
CVE-2026-1357-Lab preview

CVE-2026-1357-Lab

GitHubrootdirective-sec/cve-2026-1357-lab

Local Docker lab for comparing vulnerable and patched versions of WPvivid Backup & Migration (CVE-2026-1357) for educational verification and…

container-securityeducationlabs-practice+2
6 months ago
CVE-2025-32463 preview

CVE-2025-32463

GitHubricardomaia/cve-2025-32463

Provides a containerized environment and signed Nuclei template to safely test CVE-2025-32463, a sudo privilege escalation vulnerability, with…

container-securityeducationexploitation+3
10 months ago
pack2theroot-lab preview

pack2theroot-lab

GitHubdinosn/pack2theroot-lab

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

container-securityctfdefensive-tools+7
84 months ago
CVE-2026-3288-lab preview

CVE-2026-3288-lab

GitHubbvabhishek/cve-2026-3288-lab

Docker-based vulnerable lab for CVE-2026-3288 NGINX Ingress configuration injection, with exploit scripts, detection monitoring, and remediation…

cloud-infrastructure-securityconfiguration-auditingcontainer-security+6
14 months ago
telnet-inetutils-auth-bypass-CVE-2026-24061 preview

telnet-inetutils-auth-bypass-CVE-2026-24061

GitHubjakeswiz/telnet-inetutils-auth-bypass-cve-2026-24061

This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why…

container-securityeducationexploitation+3
17 months ago
Demo_CVE-2025-3248 preview

Demo_CVE-2025-3248

GitHubkiraly07/demo_cve-2025-3248

Educational lab simulating CVE-2025-3248 with a vulnerable Docker service and PoC exploit for hands-on security training and mitigation practice.

container-securityeducationexploitation+3
211 months ago
ARTAXERXES preview

ARTAXERXES

GitLabtoxy4ny/artaxerxes

Advanced Multi-Technology Stress Testing Framework Educational Cybersecurity Tool for High-Performance Network Testing

educationlabs-practicenetwork-security+2
1 month ago
CVE-2026-58455-PoC preview

CVE-2026-58455-PoC

GitHubboreas37/cve-2026-58455-poc

PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.

container-securityexploitationlabs-practice+3
113 days ago
CVE-2026-78122-POC preview

CVE-2026-78122-POC

GitHublegendile7/cve-2026-78122-poc

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…

configuration-auditingcontainer-securitydata-exfiltration+3
112 days ago
POC-CopyEscape-CVE-2026-17106 preview

POC-CopyEscape-CVE-2026-17106

GitHub686f6c61/poc-copyescape-cve-2026-17106

PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker +…

adversarial-attackcontainer-escapecontainer-security+5
122 days ago
ActBench preview

ActBench

GitHubzjuicsr/actbench

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

ai-securityapi-security-testinglabs-practice+1
420 days ago
deploy-goad preview

deploy-goad

GitHublkarlslund/deploy-goad

Script to install prerequisites for deploying GOAD on Ubuntu Linux 22.04

educationlabs-practicepenetration-testing+1
1162 years ago
Previous12…13Next