Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
oscp-notes-2026 preview

oscp-notes-2026

GitLabwattocyber/oscp-notes-2026

OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

curated-resourceseducationinformation-gathering+7
7 days ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

container-escapectfcurated-resources+9
7 days ago
CVE-2025-26264 preview

CVE-2025-26264

GitHubhxlxmj/cve-2025-26264

Proof-of-concept exploit targeting GeoVision GV-ASWeb Notification Settings to achieve authenticated remote code execution via command injection and…

exploitationlateral-movementpenetration-testing+3
1 year ago
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

binary-exploitationcurated-resourceseducation+9
3.9k7 months ago
peeko preview

peeko

GitHubb3rito/peeko

XSS-based C2 that turns a victim's browser into a proxy for internal scanning, URL fetch, cookie theft, JS execution, and data exfiltration via…

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
onetwoseven-writeup preview

onetwoseven-writeup

GitHubdopaminauta/onetwoseven-writeup

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

ctfeducationexploitation+7
118 days ago
TwoMillion-Machine-Writeup preview

TwoMillion-Machine-Writeup

GitHubanxs3c/twomillion-machine-writeup

Step-by-step penetration testing walkthrough for a HackTheBox Linux box: API enumeration, vertical privilege escalation, OS command injection,…

ctfeducationexploitation+7
2 months ago
CVE preview

CVE

GitHubtomerpeled92/cve

Curated repository of CVEs with PoCs, articles, and detailed descriptions for vulnerability research and exploitation.

curated-resourcesexploitationlateral-movement+3
1128 days ago
Pentest-Cheat-Sheet preview

Pentest-Cheat-Sheet

GitHubd0n601/pentest-cheat-sheet

There are many cheat sheets out there, but this is mine.

curated-resourceseducationexploitation+7
381 year ago
CVE-2026-34197 preview

CVE-2026-34197

GitHub0xblackash/cve-2026-34197

Technical analysis and proof-of-concept for CVE-2026-34197, a critical authenticated RCE in Apache ActiveMQ via Jolokia MBeans leading to remote…

exploitationlateral-movementpenetration-testing+4
14 months ago
CobaltStrike-Toolset preview

CobaltStrike-Toolset

GitHubqax-a-team/cobaltstrike-toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

command-and-controlexploit-frameworkslateral-movement+8
5927 years ago
CVE-2026-6875-PoC-Exploit preview

CVE-2026-6875-PoC-Exploit

GitHubtc4dy/cve-2026-6875-poc-exploit

Exploit framework for CVE-2026-6875, a pre-auth RCE in ServiceNow. Chains JS injection, sandbox escape, and root privesc. Includes interactive shell,…

exploitationlateral-movementpenetration-testing+7
31 month ago
PoC-CVE-2022-30190 preview

PoC-CVE-2022-30190

GitHubjmousqueton/poc-cve-2022-30190

Proof-of-concept exploit for CVE-2022-30190 (Follina) enabling remote code execution via malicious Office documents using the ms-msdt URI scheme…

command-and-controlexploitationlateral-movement+4
1574 years ago
FUXAPWN preview

FUXAPWN

GitHubhann1bl3l3ct3r/fuxapwn

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

exploitationinformation-gatheringlateral-movement+8
3 months ago
Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment preview

Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment

GitHubtadash10/exploiting-cve-2021-44228-log4shell-in-a-banking-environment

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

command-and-controldata-exfiltrationeducation+8
32 years ago
docker-lab-cve-2017-5638-cve-2021-41773 preview

docker-lab-cve-2017-5638-cve-2021-41773

GitHubkouf320/docker-lab-cve-2017-5638-cve-2021-41773

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

educationexploitationids-ips-evasion+6
23 months ago
CVE-2025-8110 preview

CVE-2025-8110

GitHubpopyue/cve-2025-8110

Python exploit for CVE-2025-8110, a Gogs symlink traversal vulnerability enabling authenticated arbitrary file write to RCE via SSH keys, crontab,…

educationexploitationlateral-movement+6
4 months ago
CVE-2025-33053-POC preview

CVE-2025-33053-POC

GitHubcyberw1ng/cve-2025-33053-poc

Proof-of-concept for CVE-2025-33053 WebDAV RCE with .url file hijacking, decoy execution, and simulated C2. Includes Docker-based setup, payload…

command-and-controleducationexploitation+7
8 months ago
Previous123Next