Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
BadZure preview

BadZure

GitHubmvelazc0/badzure

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

cloud-securityctfeducation+6
524
11 days ago
CVE-2021-3156-Project preview

CVE-2021-3156-Project

GitHubshams-ul-mehmood/cve-2021-3156-project

Educational lab environment for CVE-2021-3156 (Baron Samedit) with a Dockerized vulnerable sudo target, exploit scaffold, canary test, root-cause…

binary-exploitationeducationexploitation+3
20 days ago
distributed-system-testing preview

distributed-system-testing

GitHubshenli/distributed-system-testing

AI-agent skills for distributed-systems testing

ai-securitychaos-engineeringcurated-resources+4
2301 month ago
CVE2PoC preview

CVE2PoC

GitHub0liverflow/cve2poc

CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID

educationexploitationinformation-gathering+5
1511 month ago
CVE-2021-3156 preview

CVE-2021-3156

GitHubijbaig/cve-2021-3156

CVE-2021-3156 (Baron Samedit) Report and Research

binary-exploitationeducationexploitation+3
1 month ago
CVE-2023-4911 preview

CVE-2023-4911

GitHubbaeseungwon1010/cve-2023-4911

CVE-2023-4911 (Looney Tunables) analysis report and Docker reproduction lab

binary-exploitationeducationexploitation+3
1 month ago
CVE-2026-44963 preview

CVE-2026-44963

GitHubsentinelxofficial/cve-2026-44963

Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)

educationexploitationincident-response+4
42 months ago
CVE-2026-24136-Lab preview

CVE-2026-24136-Lab

GitHubblankbire/cve-2026-24136-lab

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

api-security-testingeducationlabs-practice+3
12 months ago
POC_CVE-2026-46716 preview

POC_CVE-2026-46716

GitHubhaerin-l/poc_cve-2026-46716

Reproducible lab environment for CVE-2026-46716, a critical cross-tenant RCE in Nezha Monitoring via cron API authorization bypass. Includes Nuclei…

ctfeducationexploitation+4
3 months ago
EntraGoat preview

EntraGoat

GitHubsemperis/entragoat

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

authenticationcloud-securityctf+7
9814 months ago
CVE-2026-41651 preview

CVE-2026-41651

GitHubbaph00met/cve-2026-41651

Proof-of-concept exploit for CVE-2026-41651, a PackageKit TOCTOU local privilege escalation, with technical analysis, detection logic, and…

exploitationlabs-practicepenetration-testing+3
164 months ago
CVE-2026-30498 preview

CVE-2026-30498

GitHubmehdi-ben-hamou/cve-2026-30498

Educational CSRF vulnerability demonstration with a controlled lab environment, including a proof-of-concept exploit and a fixed version with proper…

educationexploitationlabs-practice+3
15 months ago
CVE-2026-1581-Analysis-Lab preview

CVE-2026-1581-Analysis-Lab

GitHubrootdirective-sec/cve-2026-1581-analysis-lab

Reproduces CVE-2026-1581, an unauthenticated time-based SQL injection in wpForo Forum <=2.4.14, with a Docker lab and PoC to demonstrate the…

educationexploitationlabs-practice+3
16 months ago
CVE-2025-62878 preview

CVE-2025-62878

GitHubkinokopio/cve-2025-62878

CVE-2025-62878

cloud-securitycontainer-securityeducation+4
16 months ago
CVE-2024-44902-env preview

CVE-2024-44902-env

GitHubkre80r/cve-2024-44902-env

Vulnerable ThinkPHP 8.0.4 test environment for CVE-2024-44902 nuclei template validation

educationexploitationlabs-practice+3
9 months ago
PurpleCloud preview

PurpleCloud

GitHubiknowjason/purplecloud

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

cloud-infrastructure-securitycloud-securityeducation+4
6571 year ago
Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467- preview

Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-

GitHubahmedmansour93/event-id-217-rule-name-soc254-apache-ofbiz-auth-bypass-and-code-injection-0day-cve-2023-51467-

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

educationexploitationincident-response+3
1 year ago
Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577- preview

Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-

GitHubahmedmansour93/event-id-268-rule-name-soc292-possible-php-injection-detected-cve-2024-4577-

🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This…

ctfeducationincident-response+3
1 year ago
Previous12Next