Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
11 results
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

OSWE, OSEP, OSED, OSEE

binary-exploitationcurated-resourceseducation+9
3.9k
7 months ago
OSWE-Labs-Poc preview

OSWE-Labs-Poc

GitHubsvdwi/oswe-labs-poc

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

ctfeducationexploitation+4
1355 years ago
CVE-2023-38831_ReverseShell_Winrar-RCE preview

CVE-2023-38831_ReverseShell_Winrar-RCE

GitHubmaalfer/cve-2023-38831_reverseshell_winrar-rce

Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.

educationexploitationlabs-practice+3
222 years ago
CVE-2025-6218_WinRAR preview

CVE-2025-6218_WinRAR

GitHubspeinador/cve-2025-6218_winrar

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite…

binary-exploitationeducationexploitation+3
161 year ago
CVE-2026-22874-PoC preview

CVE-2026-22874-PoC

GitHubeliot-code/cve-2026-22874-poc

Proof-of-concept exploit for CVE-2026-22874, a Server-Side Request Forgery (SSRF) vulnerability in Gitea versions prior to 1.26.3. Intended for…

educationexploitationlabs-practice+2
1 month ago
CVE-2025-8110 preview

CVE-2025-8110

GitHubxdezen/cve-2025-8110

Python proof-of-concept for CVE-2025-8110, demonstrating arbitrary file write to RCE in Gogs via symlink and API, with educational lab usage.

educationexploitationlabs-practice+3
1 month ago
EXPLOIT-CVE-2021-44228 preview

EXPLOIT-CVE-2021-44228

GitHubjoaovicdev/exploit-cve-2021-44228

Docker-based educational lab demonstrating Log4Shell (CVE-2021-44228) RCE exploitation with a vulnerable Java application, LDAP redirector, and…

educationexploitationlabs-practice+3
4 months ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubdanilo1992-sys/cve-2021-29447

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

educationexploitationlabs-practice+3
5 months ago
CVE-2023-38831_ReverseShell_Winrar preview

CVE-2023-38831_ReverseShell_Winrar

GitHubben1b3astt/cve-2023-38831_reverseshell_winrar

Generates a malicious RAR archive exploiting CVE-2023-38831 to deliver a reverse shell via a crafted PDF, for ethical testing in controlled…

educationexploitationlabs-practice+3
13 years ago
React2Shell-CVE-2025-55182-An-lise-T-cnica preview

React2Shell-CVE-2025-55182-An-lise-T-cnica

GitHubbig02-bot/react2shell-cve-2025-55182-an-lise-t-cnica

Educational technical analysis of CVE-2025-55182, a critical unauthenticated RCE in React Server Components and Next.js via React Flight…

educationexploitationlabs-practice+3
6 months ago
EP4-redes preview

EP4-redes

GitHubcaiocgh/ep4-redes

CVE-2018-15473-Exploit

educationexploitationlabs-practice+2
6 years ago