Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
CVE-2025-54424 preview

CVE-2025-54424

GitHubhophtien/cve-2025-54424

CVE-2025-54424: 1Panel TLS client cert bypass enables RCE via forged CN 'panel_client' using a bundled scanning and exploitation tool. Affected: <=…

educationexploitationlabs-practice+3
3
22h 30m ago
renode preview

renode

GitHubrenode/renode

Open-source simulation framework for developing, testing, and debugging unmodified software for multi-node embedded and IoT systems, supporting ARM,…

educationembedded-systems-securityfirmware-analysis+3
2.8k1 day ago
PaperCut-CVE-2026-81578-82078 preview

PaperCut-CVE-2026-81578-82078

GitHubyora1928/papercut-cve-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

educationexploitationlabs-practice+4
4 days ago
awesome-osint-arsenal preview

awesome-osint-arsenal

GitHubrawfilejson/awesome-osint-arsenal

OSINT & recon toolkit // 100+ tools, one-command installer, SOCMINT, GEOINT, network recon, dark web, forensics & more.

ctfcurated-resourcesdigital-forensics+8
2.7k5 days ago
attack_range preview

attack_range

GitHubsplunk/attack_range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

cloud-securityeducationlabs-practice+1
2.5k6 days ago
CVE-2026-56705 preview

CVE-2026-56705

GitHubboreas37/cve-2026-56705

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

educationexploitationlabs-practice+4
28 days ago
athena preview

athena

GitHubathena-os/athena

Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

educationlabs-practicelearning-paths-courses+3
1.3k9 days ago
attackgen preview

attackgen

GitHubmrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

ai-securityctfeducation+5
1.2k11 days ago
IG-Detective preview

IG-Detective

GitHubshredzwho/ig-detective

OSINT tool researched and designed to hunt down IG handles

educationfingerprint-spoofingforensics+7
15416 days ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

educationexploitationlabs-practice+3
217 days ago
cve-2026-71362-magento-lab preview

cve-2026-71362-magento-lab

GitHubdinosn/cve-2026-71362-magento-lab

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

authentication-authorizationeducationexploitation+4
318 days ago
CVE-2025-32433-PoC-Analysis preview

CVE-2025-32433-PoC-Analysis

GitHubliam-worsley/cve-2025-32433-poc-analysis

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

authentication-authorizationeducationexploitation+4
19 days ago
EvilFontTool preview

EvilFontTool

GitHubdoctoreww/evilfonttool

A font-based deception tool for red teaming, security research, and whatever else.

adversarial-attackai-securityeducation+3
33324 days ago
nextjs-middleware-auth-bypass-lab preview

nextjs-middleware-auth-bypass-lab

GitHubberraesen/nextjs-middleware-auth-bypass-lab

Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

authentication-authorizationeducationlabs-practice+3
11 month ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

api-securityauthentication-authorizationcryptography+4
1 month ago
cve-2021-41773-source-code-analysis preview

cve-2021-41773-source-code-analysis

GitHubkunalkhandelwal-dev/cve-2021-41773-source-code-analysis

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

code-analysiseducationlabs-practice+2
1 month ago
ARTAXERXES preview

ARTAXERXES

GitLabtoxy4ny/artaxerxes

Advanced Multi-Technology Stress Testing Framework Educational Cybersecurity Tool for High-Performance Network Testing

educationlabs-practicenetwork-security+2
1 month ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

ai-securitycloud-securityeducation+5
21 month ago
Previous12…8Next