Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1621 results
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write preview

CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

GitHubbiitts/cve-2026-82286-gpt-crawler-arbitrary-file-write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

educationexploitationlabs-practice+3
11 days ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
1 month ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
1 month ago
joomla_exploits preview

joomla_exploits

GitHubaramosf/joomla_exploits

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

crawlereducationexploitation+5
11 month ago
live-server-evil-crawler preview

live-server-evil-crawler

GitHubnatsuki-engr/live-server-evil-crawler

Live Server VSCode Vulnerability (CVE-2025-65717) Demo

educationexploitationlabs-practice+3
6 months ago
Wordpress_CVE-2019-9787 preview

Wordpress_CVE-2019-9787

GitHubmatinciel/wordpress_cve-2019-9787

Try to reproduce this issue with Docker

crawlereducationexploitation+3
6 years ago
CVE-2026-53753-Crawl4AI-RCE preview

CVE-2026-53753-Crawl4AI-RCE

GitHubbiitts/cve-2026-53753-crawl4ai-rce

CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.

code-analysisdynamic-analysis-sandboxingeducation+7
2 months ago
ctf-skills preview

ctf-skills

GitHubljagiello/ctf-skills

Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more

binary-exploitationcryptographyctf+9
3.2k15 days ago
kubernetes-goat preview

kubernetes-goat

GitHubmadhuakula/kubernetes-goat

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

cloud-securitycontainer-escapecontainer-security+4
5.8k4 months ago
AutomatedLab preview

AutomatedLab

GitHubautomatedlab/automatedlab

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

cloud-infrastructure-securityeducationlabs-practice+1
2.2k2 months ago
VAmPI preview

VAmPI

GitHuberev0s/vampi

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

api-security-testingeducationlabs-practice+2
1.3k5 months ago
terragoat preview

terragoat

GitHubbridgecrewio/terragoat

Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.

cloud-securitydevsecopseducation+2
1.3k3 years ago
labs preview

labs

GitHubnixawk/labs

Vulnerability Labs for security analysis

curated-resourcesexploitationlabs-practice+3
1.2k5 years ago
crAPI preview

crAPI

GitHubowasp/crapi

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

api-securityapi-security-testingeducation+3
1.6k7h 19m ago
BestEdrOfTheMarket preview

BestEdrOfTheMarket

GitHubxacone/bestedrofthemarket

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…

defensive-toolseducationlabs-practice+1
1.6k3 months ago
Damn-Vulnerable-GraphQL-Application preview

Damn-Vulnerable-GraphQL-Application

GitHubdolevf/damn-vulnerable-graphql-application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

api-securityapi-security-testingctf+5
1.7k1 year ago
awesome-soc-analyst preview

awesome-soc-analyst

GitHubletsdefend/awesome-soc-analyst

Useful resources for SOC Analyst and SOC Analyst candidates.

curated-resourcesdigital-forensicseducation+6
1.0k3 years ago
DSP preview

DSP

GitHubdockersecurityplayground/dsp

A Microservices-based framework for the study of Network Security and Penetration Test techniques

container-securityeducationlabs-practice+3
6326 months ago
Previous12…91Next