Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
PIL-CVE-2017-8291 preview

PIL-CVE-2017-8291

GitHubhkcfs/pil-cve-2017-8291

CVE-2017-8291 CTF with docker and examples

ctfeducationexploitation+3
1 year ago
CVE-2014-3704 preview

CVE-2014-3704

GitHubjoaomorenorf/cve-2014-3704

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

educationexploitationlabs-practice+2
11 year ago
CVE-2019-10945 preview

CVE-2019-10945

GitHubdpgg101/cve-2019-10945

Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion in Python3

educationexploitationlabs-practice+2
343 years ago
CopyFail-Exploits-CVE-2026-31431 preview

CopyFail-Exploits-CVE-2026-31431

GitHubshotafry/copyfail-exploits-cve-2026-31431

Multi-language educational exploit implementations for CVE-2026-31431, a Linux kernel local privilege escalation via the algif_aead module, with a…

binary-exploitationctfeducation+4
74 months ago
CVE-2012-2982-Python-PoC preview

CVE-2012-2982-Python-PoC

GitHubcd6629/cve-2012-2982-python-poc

This was converted from a metasploit module as an exercise for OSCP studying

educationexploitationlabs-practice+3
55 years ago
CVE-2015-3306-Python-PoC preview

CVE-2015-3306-Python-PoC

GitHubcd6629/cve-2015-3306-python-poc

Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development

educationexploitationexploit-frameworks+3
15 years ago
CVE-2025-32463_Sudo_PoC preview

CVE-2025-32463_Sudo_PoC

GitHubabrewer251/cve-2025-32463_sudo_poc

PoC for CVE-2025-32463: Local privilege escalation in sudo via --chroot. Exploits NSS module injection through crafted chroot environments. Designed…

binary-exploitationeducationexploitation+4
11 year ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
5 months ago
cve-2026-31431 preview

cve-2026-31431

GitHubvasyapokemon/cve-2026-31431

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

curated-resourcesdigital-forensicseducation+8
4 months ago
ADLab preview

ADLab

GitHubxbufu/adlab

Custom PowerShell module to setup an Active Directory lab environment to practice penetration testing.

educationlabs-practicepenetration-testing
1831 year ago
CVE-2021-36394-Pre-Auth-RCE-in-Moodle preview

CVE-2021-36394-Pre-Auth-RCE-in-Moodle

GitHublavclash75/cve-2021-36394-pre-auth-rce-in-moodle

Pre-authentication remote code execution exploit targeting Moodle's Shibboleth authentication module. Includes Docker-based lab environment for…

educationexploitationlabs-practice+3
94 years ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubquantumworld-dpdns-io/cve-2026-42945

Full CVE-2026-42945 research repository with heap buffer overflow analysis, RCE exploit (heap spray + Feng Shui), detection scripts, and patching…

binary-exploitationeducationexploitation+6
4 months ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
5 months ago
GitPython-Exploit-CVE-2022-24439 preview

GitPython-Exploit-CVE-2022-24439

GitHubmakkkiiii/gitpython-exploit-cve-2022-24439

Method I used for my Practical Pentest Module.

educationexploitationlabs-practice+2
11 year ago
TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation preview

TRAI-001-Critical-RCE-Vulnerability-in-Apache-Parquet-CVE-2025-30065-Simulation

GitHubthreatradarai/trai-001-critical-rce-vulnerability-in-apache-parquet-cve-2025-30065-simulation

A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked…

ctfeducationexploitation+3
11 year ago
polkit-CVE-2021-3560_writeup preview

polkit-CVE-2021-3560_writeup

GitHubrealatharva15/polkit-cve-2021-3560_writeup

beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560

binary-exploitationctfeducation+4
8 months ago
Metasploit-Module-TFM preview

Metasploit-Module-TFM

GitHubcgv-dev/metasploit-module-tfm

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

cloud-securitycontainer-securityeducation+7
2 years ago
AutomatedLab preview

AutomatedLab

GitHubautomatedlab/automatedlab

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

cloud-infrastructure-securityeducationlabs-practice+1
2.2k2 months ago
Previous12Next