Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
azure-sentinel-detection-engineering preview

azure-sentinel-detection-engineering

GitHubibondarenko1/azure-sentinel-detection-engineering

9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated…

cloud-securityconfiguration-auditingdevsecops+4
5
27 days ago
log4j-CVE-2021-44228 preview

log4j-CVE-2021-44228

GitHubkubearmor/log4j-cve-2021-44228

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

cloud-securitycontainer-securityeducation+4
94 years ago
lxd-group-privesc-report preview

lxd-group-privesc-report

GitHubstar-sg/lxd-group-privesc-report

Proof-of-concept and educational report demonstrating local privilege escalation to root via default LXD group membership on Ubuntu Server, with…

container-securityeducationexploitation+3
73 months ago
CVE-2026-44578 preview

CVE-2026-44578

GitHubdinosn/cve-2026-44578

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

cloud-securityeducationexploitation+3
93 months ago
DEFCON-KQL-KUNG-FU-22 preview

DEFCON-KQL-KUNG-FU-22

GitHubdarwinsec/defcon-kql-kung-fu-22

DEF CON Cloud Village workshop slides teaching KQL for cloud security log analysis, with practical exercises in a shared Azure Log Analytics…

cloud-securitycurated-resourceseducation+3
188 months ago
CVE-2022-0492-Docker-Breakout-Checker-and-PoC preview

CVE-2022-0492-Docker-Breakout-Checker-and-PoC

GitHubt1erno/cve-2022-0492-docker-breakout-checker-and-poc

Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)

cloud-securitycontainer-escapecontainer-security+6
83 years ago
log4j-docker preview

log4j-docker

GitHubankur-katiyar/log4j-docker

Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)

cloud-securitycontainer-securityeducation+3
54 years ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

ai-securitycloud-securityeducation+5
21 month ago
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

cloud-securitycontainer-securityeducation+7
18 days ago
CVE-2021-38647-POC-and-Demo-environment preview

CVE-2021-38647-POC-and-Demo-environment

GitHubsimenbai/cve-2021-38647-poc-and-demo-environment

OMIGod / CVE-2021-38647 POC and Demo environment

cloud-securityeducationexploitation+3
34 years ago
nhi-zero-trust-bypass preview

nhi-zero-trust-bypass

GitHubalexsvobo/nhi-zero-trust-bypass

Demonstrates a real-world zero-trust bypass by exploiting BIND CVE-2025-40775 to disrupt DNS, break secret rotation, and expose static credentials in…

cloud-securitydns-analysiseducation+5
51 year ago
mongobleed-exploit-CVE-2025-14847 preview

mongobleed-exploit-CVE-2025-14847

GitHubfranksec42/mongobleed-exploit-cve-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

cloud-securitycontainer-securitydatabase-security+6
36 months ago
PENTEST-LAB preview

PENTEST-LAB

GitHubpannagkumaar/pentest-lab

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

ai-securityapi-securityauthentication+8
1 month ago
nessus-vulnerability-scanning-lab preview

nessus-vulnerability-scanning-lab

GitHubkingsrule50/nessus-vulnerability-scanning-lab

Enterprise vulnerability management on Azure — Terraform-deployed Nessus scanner, credentialed scanning, CVE-2013-3900 remediation with verified…

cloud-securityconfiguration-auditingdevsecops+4
1 month ago
text4shell-cve-2022-42889 preview

text4shell-cve-2022-42889

GitHubdevenes/text4shell-cve-2022-42889

Kubernetes Lab for CVE-2022-42889

cloud-securitycontainer-securityeducation+3
23 years ago
cve-2026-59891-control-lab preview

cve-2026-59891-control-lab

GitHubgyubin02/cve-2026-59891-control-lab

Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci

cloud-securitycontainer-securityeducation+4
1 month ago
how-to-check-patch-secure-log4j-CVE-2021-44228 preview

how-to-check-patch-secure-log4j-CVE-2021-44228

GitHubanuvindhs/how-to-check-patch-secure-log4j-cve-2021-44228

A one-stop repo/ information hub for all log4j vulnerability-related information.

curated-resourceseducationinformation-gathering+3
24 years ago
omigod-lab preview

omigod-lab

GitHubcraig-m-unsw/omigod-lab

A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").

cloud-securityeducationexploitation+3
14 years ago
Previous1234567Next