Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k1 day ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
16 days ago
athena preview

athena

GitHubathena-os/athena

Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

educationlabs-practicelearning-paths-courses+3
1.3k7 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubcrowsec-edtech/cve-2026-87902

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

exploitationlabs-practicepayload-development+5
311 days ago
EXPLOIT-CVE-2026-87902 preview

EXPLOIT-CVE-2026-87902

GitHubjoaovicdev/exploit-cve-2026-87902

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

container-securityeducationexploitation+6
12 days ago
wraith preview

wraith

GitHubarcanum-sec/wraith

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

command-and-controleducationexploitation+6
1542 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
14 months ago
POC_CVE-2026-35037 preview

POC_CVE-2026-35037

GitHubfineman999/poc_cve-2026-35037

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

educationexploitationlabs-practice+3
4 months ago
polkit-CVE-2021-3560_writeup preview

polkit-CVE-2021-3560_writeup

GitHubrealatharva15/polkit-cve-2021-3560_writeup

beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560

binary-exploitationctfeducation+4
8 months ago
Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device preview

Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device

GitHubkamalideenak/microsoft-defender-for-endpoint-deployment-on-windows-10-11-device

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…

configuration-auditingdefensive-toolseducation+4
1 year ago
PentesterLab preview

PentesterLab

GitHubelw0od/pentesterlab

OrangeBadge - Exercise CVE-2018-6574: go get RCE

binary-exploitationeducationexploitation+3
1 year ago
POC-CVE-2016-10033 preview

POC-CVE-2016-10033

GitHubastrowmist/poc-cve-2016-10033

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

educationexploitationlabs-practice+4
2 years ago
ThreatPursuit-VM preview
Archived

ThreatPursuit-VM

GitHubmandiant/threatpursuit-vm

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

curated-resourcesdigital-forensicseducation+8
1.3k3 years ago
commons-text-goat preview

commons-text-goat

GitHubtulhan/commons-text-goat

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

educationexploitationlabs-practice+3
13 years ago
Cybersecurity-Books preview

Cybersecurity-Books

GitHubzealraj/cybersecurity-books

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

curated-resourcesdigital-forensicseducation+6
6944 years ago
log4shellwithlog4j2_13_3 preview

log4shellwithlog4j2_13_3

GitHubpaulvkitor/log4shellwithlog4j2_13_3

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

educationexploitationlabs-practice+2
4 years ago
android-kernel-exploitation preview

android-kernel-exploitation

GitHubcloudfuzz/android-kernel-exploitation

Hands-on workshop for learning Android kernel vulnerability analysis and exploitation, with Docker-based build environment and practical exercises.

android-securitybinary-exploitationeducation+4
6514 years ago
Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability preview

Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability

GitHubkasunpriyashan/y2s1-project-linux-exploitaion-using-cve-2016-5195-vulnerability

Educational Linux privilege escalation exploit targeting CVE-2016-5195 (Dirty COW) to demonstrate kernel vulnerability exploitation and root access…

binary-exploitationeducationexploitation+4
4 years ago
Previous12Next