Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1685 results
mutillidae preview

mutillidae

GitHubwebpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

ctfeducationlabs-practice+3
1.5k
9 days ago
Lab4PurpleSec preview

Lab4PurpleSec

GitHub0xmr007/lab4purplesec

Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense +…

educationids-ips-evasionintrusion-detection+5
3339 months ago
kubernetes-goat preview

kubernetes-goat

GitHubmadhuakula/kubernetes-goat

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

cloud-securitycontainer-escapecontainer-security+4
5.9k5 months ago
cve-2018-1273 preview

cve-2018-1273

GitHubcved-sources/cve-2018-1273

Docker container for CVE-2018-1273 exploitation lab, part of the Cved vulnerable environment management framework for security training and testing.

container-securityeducationexploitation+3
5 years ago
cve-2019-10678 preview

cve-2019-10678

GitHubcved-sources/cve-2019-10678

Docker container providing a vulnerable environment for CVE-2019-10678, designed for security training and exploitation practice within the Cved…

container-securityeducationexploitation+2
15 years ago
cve-2018-15877 preview

cve-2018-15877

GitHubcved-sources/cve-2018-15877

Docker container providing a pre-configured vulnerable environment for CVE-2018-15877, designed for security training and exploit practice within the…

container-securityeducationexploitation+2
5 years ago
CVE-2025-31486-Simulation preview

CVE-2025-31486-Simulation

GitHubhackmelocal/cve-2025-31486-simulation

Containerized lab environment to simulate and exploit CVE-2025-31486, a path traversal vulnerability in Vite's development server, with step-by-step…

ctfeducationlabs-practice+3
1 year ago
CVE-2026-2964-Lab preview

CVE-2026-2964-Lab

GitHubthegenetic/cve-2026-2964-lab

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

code-analysiseducationexploitation+4
6 months ago
cve-2016-8869 preview

cve-2016-8869

GitHubcved-sources/cve-2016-8869

Dockerized vulnerable environment for CVE-2016-8869 (Joomla privilege escalation) used for security training and exploitation practice.

container-securityeducationexploitation+3
5 years ago
OWASP-GoatDroid-Project preview
Archived

OWASP-GoatDroid-Project

GitHubnvisium-jack-mannino/owasp-goatdroid-project

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

android-securityeducationlabs-practice+3
25612 years ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
2 months ago
DVWA preview

DVWA

GitHubdigininja/dvwa

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

educationlabs-practicepenetration-testing+2
13.8k3 days ago
CVE-2025-55182-React2Shell-Lab preview

CVE-2025-55182-React2Shell-Lab

GitHubgoultarde/cve-2025-55182-react2shell-lab

CTF lab environment exploiting CVE-2025-55182 (RCE in React Server Components) with vulnerable Next.js blog, detection scripts, and manual exploit…

ctfeducationexploitation+3
9 months ago
cve-2019-9978 preview

cve-2019-9978

GitHubcved-sources/cve-2019-9978

Docker container providing a vulnerable environment for CVE-2019-9978 (WordPress Social Networks Auto Poster RCE) for security training and…

container-securityeducationexploitation+3
5 years ago
LayarKacaSiber-CVE-2021-41773 preview

LayarKacaSiber-CVE-2021-41773

GitHubdileepdkumar/layarkacasiber-cve-2021-41773

Docker-based lab environment for practicing CVE-2021-41773 (Apache HTTP Server 2.4.49 path traversal and RCE) with step-by-step setup instructions…

educationexploitationlabs-practice+3
10 months ago
CVE-2021-42013 preview

CVE-2021-42013

GitHublayarkacasiber/cve-2021-42013

Docker-based lab environment for exploiting CVE-2021-42013 (Apache HTTP Server path traversal and RCE) with step-by-step setup instructions for…

container-securityeducationexploitation+3
4 years ago
POC-CVE-2026-58048 preview

POC-CVE-2026-58048

GitHubimbas007/poc-cve-2026-58048

Security research project

database-securityexploitationlabs-practice+4
22 months ago
ICS-TestBed-Framework preview

ICS-TestBed-Framework

GitHubpmaynard/ics-testbed-framework

Deploys realistic virtual SCADA/ICS testbeds with IEC 60870-5-104 and OPC-UA nodes, enabling attack simulations, legitimate packet generation, and…

labs-practicenetwork-securitypacket-sniffing-analysis+3
707 years ago
Previous12…94Next