Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
CVE-2020-10560 preview

CVE-2020-10560

GitHubkevthehermit/cve-2020-10560

Docker-based lab environment and proof-of-concept scripts for exploiting CVE-2020-10560, an arbitrary file read vulnerability in OSSN. Includes PHP…

educationexploitationlabs-practice+3
8
6 years ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubpopclom/cve-2025-5548

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

binary-exploitationdebuggerseducation+8
6 months ago
ghostcat-verification preview

ghostcat-verification

GitHubshaunmclernon/ghostcat-verification

Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)

educationexploitationlabs-practice+2
16 years ago
Trickster-HTB preview

Trickster-HTB

GitHubpallangyo98/trickster-htb

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

ctfeducationexploitation+5
1 year ago
CVE-2021-3129-Lab preview

CVE-2021-3129-Lab

GitHubthenareshofficial/cve-2021-3129-lab

CVE-2021-3129: Laravel Debug Mode RCE - Complete exploitation lab with Python exploit, Docker container, and security analysis guide.

educationexploitationlabs-practice+3
12 months ago
cve-2025-65099 preview

cve-2025-65099

GitHubb-faller/cve-2025-65099

Proof-of-concept exploit for CVE-2025-65099 in Claude Code, demonstrating yarnPath and plugin techniques to achieve code execution in a controlled…

educationexploitationlabs-practice+2
9 months ago
CVE-2026-74469 preview

CVE-2026-74469

GitHub0xblackash/cve-2026-74469

Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC,…

binary-exploitationeducationexploitation+5
2 days ago
pentest-writeups preview

pentest-writeups

GitHubamericooo/pentest-writeups

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

ctfeducationexploitation+6
2 months ago
Triage-CVE-2021-26855-ProxyLogon---Microsoft-Exchange- preview

Triage-CVE-2021-26855-ProxyLogon---Microsoft-Exchange-

GitHubprobablysecure/triage-cve-2021-26855-proxylogon---microsoft-exchange-

Hands-on CVE triage lab: analyze NVD entries, decode CVSS vectors, map CWE weaknesses, and contextualize risk for high-profile exploits like…

educationincident-responselabs-practice+2
2 months ago
CVE-2025-8088 preview

CVE-2025-8088

GitHubwalidpyh/cve-2025-8088

Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab…

binary-exploitationeducationexploitation+2
41 year ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubkondordevsecuritycorp/cve-2026-34197

Exploit for Apache ActiveMQ RCE via Jolokia API (CVE-2026-34197) with command output capture, mass scanning, and auto-exploitation.

exploitationlabs-practicepayload-generation+4
25 months ago
attackgen preview

attackgen

GitHubmrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

ai-securityctfeducation+5
1.2k14h 42m ago
cve-2024-3094 preview

cve-2024-3094

GitHubvaleriot30/cve-2024-3094

A XZ backdoor vulnerability explained in details

binary-analysiseducationexploitation+3
11 year ago
CVE-2020-0796 preview

CVE-2020-0796

GitHubmaqeel-git/cve-2020-0796

Analysis and ethical exploitation guide for CVE-2020-0796 (SMBGhost) SMBv3 vulnerability with technical details and practical attack plan.

binary-exploitationeducationexploitation+2
1 year ago
cloudfoxable preview

cloudfoxable

GitHubbishopfox/cloudfoxable

Create your own vulnerable by design AWS penetration testing playground

cloud-infrastructure-securitycloud-securityctf+3
4754 months ago
pwnedit preview

pwnedit

GitHubliveoverflow/pwnedit

CVE-2021-3156 - Sudo Baron Samedit

binary-exploitationctfdebuggers+5
2254 years ago
POC_CVE-2026-46716 preview

POC_CVE-2026-46716

GitHubhaerin-l/poc_cve-2026-46716

Reproducible lab environment for CVE-2026-46716, a critical cross-tenant RCE in Nezha Monitoring via cron API authorization bypass. Includes Nuclei…

ctfeducationexploitation+4
3 months ago
LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320 preview

LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320

GitHubvictormbogu1/letsdefend-soc342-cve-2025-53770-sharepoint-toolshell-auth-bypass-andrce-eventid-320

Step-by-step walkthrough of a LetsDefend SOC342 lab analyzing CVE-2025-53770 SharePoint ToolShell auth bypass and RCE, including attack chain,…

ctfeducationexploitation+6
11 months ago
Previous12Next