Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
174 results
CVE-2018-14667 preview

CVE-2018-14667

GitHubsyriusbughunt/cve-2018-14667

All about CVE-2018-14667; From what it is to how to successfully exploit it.

educationexploitationlabs-practice+3
50
7 years ago
cybersecurity-projects preview

cybersecurity-projects

GitHubosxninja/cybersecurity-projects

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

ai-securitycurated-resourcesdigital-forensics+7
2511 days ago
page_table_walk preview

page_table_walk

GitHubjazho76/page_table_walk

Walk x86-64 page tables by hand in qemu and gdb. Decompose a virtual address, follow cr3 through all levels of physical memory, and extract a flag…

binary-analysisctfdebuggers+4
285 months ago
CVE-2022-26923-Powershell-POC preview

CVE-2022-26923-Powershell-POC

GitHublsecqt/cve-2022-26923-powershell-poc

A powershell poc to load and automatically run Certify and Rubeus from memory.

educationexploitationlabs-practice+3
174 years ago
CVE-2026-0047-poc preview

CVE-2026-0047-poc

GitHubmobilehackinglab/cve-2026-0047-poc

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

android-securitybinary-exploitationeducation+6
153 months ago
cmdchamp preview

cmdchamp

GitHubmellen9999/cmdchamp

bash CLI trainer — 30 levels from ls to privilege escalation

ctfeducationforensics+8
1212h 54m ago
2026 preview

2026

GitHub100daysofyara/2026

Rules shared by the community from 100 Days of YARA 2026

curated-resourceseducationlabs-practice+3
124 months ago
CVE-2015-1328 preview

CVE-2015-1328

GitHubfernandocassiodev/cve-2015-1328

Step-by-step walkthrough for exploiting CVE-2015-1328 (OverlayFS) to escalate privileges from a low-privileged user to root on Ubuntu 14.04. Includes…

binary-exploitationctfeducation+3
28 days ago
Cyber-Defenders-lab- preview

Cyber-Defenders-lab-

GitHubabiral-timalsina/cyber-defenders-lab-

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

digital-forensicseducationincident-response+3
11 days ago
100DaysofYARA preview

100DaysofYARA

GitHubsquiblydoo/100daysofyara

Rules shared by the community from 100 Days of YARA 2026

curated-resourceseducationlabs-practice+3
55 months ago
CVE-2012-2982-Python-PoC preview

CVE-2012-2982-Python-PoC

GitHubcd6629/cve-2012-2982-python-poc

This was converted from a metasploit module as an exercise for OSCP studying

educationexploitationlabs-practice+3
55 years ago
From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps preview

From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps

GitHubmrk336/from-foothold-to-domain-admin-weaponizing-cve-2025-54918-in-real-world-devops

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

cloud-securityconfiguration-auditingdevsecops+7
411 months ago
AgentCyTE preview

AgentCyTE

GitHubanantaakotal/agentcyte

Generates reproducible CORE network topologies from XML scenario files for cybersecurity training and experimentation. Provides Web GUI and CLI for…

educationlabs-practicenetwork-security+3
38 months ago
TwoMillion-Machine-Writeup preview

TwoMillion-Machine-Writeup

GitHubanxs3c/twomillion-machine-writeup

From deobfuscating code.js to root, CVE-2023-0386

ctfeducationexploitation+7
2 months ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
Exploiting-Samba-on-Metasploitable-2 preview

Exploiting-Samba-on-Metasploitable-2

GitHubvig9610/exploiting-samba-on-metasploitable-2

Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a…

educationexploitationexploit-frameworks+8
5 months ago
pentest-metasploitable2 preview

pentest-metasploitable2

GitHubemilebarnard242/pentest-metasploitable2

A documented penetration testing lab built on Kali Linux and Metasploitable2, walking through a full attack chain from network traffic analysis and…

educationexploitationlabs-practice+6
4 months ago
CVE-2015-3306-Python-PoC preview

CVE-2015-3306-Python-PoC

GitHubcd6629/cve-2015-3306-python-poc

Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development

educationexploitationexploit-frameworks+3
15 years ago
Previous123…10Next