Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
85 results
cve-2014-0160 preview

cve-2014-0160

GitHubcved-sources/cve-2014-0160

cve-2014-0160

container-securityeducationexploitation+2
5 years ago
cve-2018-15877 preview

cve-2018-15877

GitHubcved-sources/cve-2018-15877

cve-2018-15877

container-securityeducationexploitation+2
5 years ago
cve-2019-6340 preview

cve-2019-6340

GitHubcved-sources/cve-2019-6340

cve-2019-6340

container-securityeducationexploitation+3
5 years ago
cve-2019-5420 preview

cve-2019-5420

GitHubcved-sources/cve-2019-5420

cve-2019-5420

container-securityeducationexploitation+2
3 years ago
SUDO_KILLER preview

SUDO_KILLER

GitHubth3xace/sudo_killer

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

ctfeducationexploitation+5
2.5k5 months ago
FTC-Skystone-Dark-Angels-Romania-2020 preview

FTC-Skystone-Dark-Angels-Romania-2020

GitHubchrisneagu/ftc-skystone-dark-angels-romania-2020

NOTICE This repository contains the public FTC SDK for the SKYSTONE (2019-2020) competition season. If you are looking for the current season's FTC…

educationembedded-systems-securityhardware-security+3
3035 years ago
Persistnux preview

Persistnux

GitHubgo-lanz/persistnux

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

container-escapedigital-forensicseducation+7
31 month ago
TerraformGoat preview

TerraformGoat

GitHubhxsecurity/terraformgoat

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

cloud-infrastructure-securitycloud-securityeducation+2
6383 years ago
cnappgoat preview

cnappgoat

GitHubtenable/cnappgoat

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

cloud-infrastructure-securitycloud-securityctf+5
2962 years ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground
educationexploitationlabs-practice+3
225 days ago
CVE-2025-32463-EXPLOIT preview

CVE-2025-32463-EXPLOIT

GitHubsecvulnhub/cve-2025-32463-exploit
binary-exploitationeducationexploitation+4
14 months ago
attack_range preview

attack_range

GitHubsplunk/attack_range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

cloud-securityeducationlabs-practice+1
2.5k2 months ago
IG-Detective preview

IG-Detective

GitHubshredzwho/ig-detective

OSINT tool researched and designed to hunt down IG handles

educationfingerprint-spoofingforensics+7
1523 days ago
fortigate-cve-2022-40684-tool preview

fortigate-cve-2022-40684-tool

GitHubpintukumar-sutradhar/fortigate-cve-2022-40684-tool

FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.

educationexploitationlabs-practice+3
4 months ago
BadBlood preview

BadBlood

GitHubdavidprowe/badblood

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is…

educationidentity-access-managementlabs-practice+1
2.3k3 years ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

ai-securitycloud-securityeducation+5
225 days ago
arya preview

arya

GitHubclaroty/arya

Generates pseudo-malicious files from YARA rules to trigger AV/EDR detection, enabling malware research, rule QA, and network sensor pressure testing…

educationlabs-practicemalware-analysis+2
2603 years ago
defcon33_silence_kill_edr preview

defcon33_silence_kill_edr

GitHubarosenmund/defcon33_silence_kill_edr
adversarial-attackeducationlabs-practice+6
3461 year ago
Previous12345Next