Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
316 results
CVE-2017-8759 preview

CVE-2017-8759

GitHubnccgroup/cve-2017-8759

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

exploitationmalware-analysispayload-development+2
94
8 years ago
xz-cve-2024-3094 preview

xz-cve-2024-3094

GitHubhackura/xz-cve-2024-3094

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

digital-forensicseducationforensics+6
7 months ago
CVE-2018-0802 preview

CVE-2018-0802

GitHubroninapt/cve-2018-0802

Proof-of-concept exploit for CVE-2018-0802 Office Equation Editor RCE, using Packager OLE object to drop and execute embedded payloads with bypass…

exploitationmalware-analysispayload-generation+3
5 years ago
neurax preview

neurax

GitHubredcode-labs/neurax

A framework for constructing self-spreading binaries

command-and-controlexploitationlateral-movement+7
1.0k2 years ago
LockingGirl-----CVE-2022-0847-Dirty_Pipe_virus preview

LockingGirl-----CVE-2022-0847-Dirty_Pipe_virus

GitHubsolomon12354/lockinggirl-----cve-2022-0847-dirty_pipe_virus

Educational demonstration of CVE-2022-0847 (Dirty Pipe) Linux kernel exploit with automated compilation script for privilege escalation and file…

binary-exploitationeducationexploitation+2
2 years ago
TryHack3M-Bricks-Heist preview

TryHack3M-Bricks-Heist

GitHubanjai7/tryhack3m-bricks-heist

TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification

ctfdigital-forensicseducation+5
11 months ago
CVE-2025-61228 preview

CVE-2025-61228

GitHubgraypixel2121/cve-2025-61228

Technical analysis and proof-of-concept exploit for CVE-2025-61228, a privilege escalation vulnerability in SuperDuper!'s auto-update mechanism, with…

educationexploitationmalware-analysis+3
9 months ago
CVE-2021-40444 preview

CVE-2021-40444

GitHublockedbyte/cve-2021-40444

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

exploitationmalware-analysispayload-generation+1
1.8k4 years ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubhqdat809/cve-2021-40444

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

exploitationmalware-analysispayload-generation+3
3 years ago
Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx preview

Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx

GitHubw1kyri3/exploit-poc-cve-2021-40444-inject-ma-doc-vao-docx

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted Office documents, with an integrated hosting…

command-and-controlexploitationmalware-analysis+3
4 years ago
CVE-2021-40444-exp preview

CVE-2021-40444-exp

GitHublisinan988/cve-2021-40444-exp

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…

command-and-controlexploitationmalware-analysis+2
4 years ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubalexcot25051999/cve-2021-40444

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

command-and-controlexploitationmalware-analysis+3
4 years ago
POC-of-CVE-2022-36271 preview

POC-of-CVE-2022-36271

GitHubsaumyajeetdas/poc-of-cve-2022-36271

This is working POC of CVE-2022-36271

binary-exploitationexploitationmalware-analysis+3
94 years ago
CVE-2017-5638_struts preview

CVE-2017-5638_struts

GitHubinitconf/cve-2017-5638_struts

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.

exploitationintrusion-detectionmalware-analysis+3
88 years ago
Rig-Exploit-for-CVE-2018-8174 preview

Rig-Exploit-for-CVE-2018-8174

GitHuborf53975/rig-exploit-for-cve-2018-8174

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

command-and-controlexploitationmalware-analysis+3
8 years ago
Reports preview

Reports

GitHubj4ck3lsyn-gen2/reports

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

binary-exploitationcurated-resourcesexploitation+8
21 month ago
CVE-2026-21509-PoC preview

CVE-2026-21509-PoC

GitHubgavz/cve-2026-21509-poc

Educational PoC generating a harmless DOCX with dummy OLE artifacts to test EDR/AV visibility, ASR rules, and sandbox analysis for CVE-2026-21509.…

defensive-toolseducationlabs-practice+2
207 months ago
security-labs-pocs preview

security-labs-pocs

GitHubdatadog/security-labs-pocs

Proof of concept code for Datadog Security Labs referenced exploits.

container-escapecurated-resourcesexploitation+4
4498 days ago
Previous12…18Next