Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
64 results
Joomla-CMS-Full-Lifecycle-Pentest preview

Joomla-CMS-Full-Lifecycle-Pentest

GitHubmarwan651/joomla-cms-full-lifecycle-pentest

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

educationexploitationinformation-gathering+7
4 months ago
CVE-2026-55579 preview

CVE-2026-55579

GitHubch4120n/cve-2026-55579

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

educationexploitationlabs-practice+6
12 months ago
CVE-2022-30190-Follina-Lab preview

CVE-2022-30190-Follina-Lab

GitHubu1tr0nex/cve-2022-30190-follina-lab

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

command-and-controleducationexploitation+7
5 months ago
redthread preview

redthread

GitHubmatheusht/redthread

An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision…

adversarial-attackai-securitydefensive-tools+7
5019 days ago
kali-rpi-luks-crypt preview

kali-rpi-luks-crypt

GitHubtothi/kali-rpi-luks-crypt

Full disk encryption for Kali on Raspberry using LUKS

educationembedded-systems-securityencryption-decryption-tools+2
157 years ago
linux-root-kit preview

linux-root-kit

GitHubic3-512/linux-root-kit

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

command-and-controldigital-forensicseducation+8
101 year ago
libextractor-ole2-rce preview

libextractor-ole2-rce

GitHubhaitam-lazaar/libextractor-ole2-rce

PoC for a Critical stack-based buffer overflow in GNU libextractor ≤ 1.14. A malicious .doc file triggers an unbounded VLA allocation causing…

binary-exploitationexploitationlabs-practice+4
23 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
23 days ago
cve-2010-4221-lab preview

cve-2010-4221-lab

GitHubdiegslva/cve-2010-4221-lab

From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented

binary-exploitationeducationexploitation+5
1 month ago
Kestra-cve-2026-53576 preview

Kestra-cve-2026-53576

GitHubatlasvector/kestra-cve-2026-53576

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

container-securityexploitationincident-response+8
13 days ago
sunset-noontide-pentesting preview

sunset-noontide-pentesting

GitHubzales2004/sunset-noontide-pentesting

Description Professional penetration testing assessment of the Sunset: Noontide VulnHub machine, covering reconnaissance, service enumeration,…

ctfeducationexploitation+9
26 days ago
TarantuBench preview

TarantuBench

GitHubtrivulzianus/tarantubench

The full repo of all the labs available as part of the benchmark

authentication-authorizationctfeducation+6
34 months ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubgiangdurian/cve-2026-63030-cve-2026-60137

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

ctfeducationexploitation+4
2 months ago
flowise-arbitrary-file-read-getFileFromStorage preview

flowise-arbitrary-file-read-getFileFromStorage

GitHubmajpuv/flowise-arbitrary-file-read-getfilefromstorage

Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path…

data-exfiltrationexploitationinformation-gathering+4
2 months ago
CVE-2024-27198-SOC-Lab preview

CVE-2024-27198-SOC-Lab

GitHubptd200110/cve-2024-27198-soc-lab

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

educationexploitationids-ips-evasion+7
23 months ago
Zero-Day-Legacy preview

Zero-Day-Legacy

GitHubayham-megdadi/zero-day-legacy

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

ctfeducationlabs-practice+6
23 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubquantumworld-dpdns-io/cve-2026-42945

Full CVE-2026-42945 research repository with heap buffer overflow analysis, RCE exploit (heap spray + Feng Shui), detection scripts, and patching…

binary-exploitationeducationexploitation+6
4 months ago
crushftp_cve-2025-31161 preview

crushftp_cve-2025-31161

GitHubrufflabs/crushftp_cve-2025-31161

Pre-built vulnerable CrushFTP 10.8.0 binary for authorized penetration testing of CVE-2025-31161, an unauthenticated authentication bypass…

authenticationexploitationlabs-practice+3
3 months ago
Previous1234Next