Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
16 results
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k14h 50m ago
CVE-2025-30065-PoC preview

CVE-2025-30065-PoC

GitHubron-imperva/cve-2025-30065-poc

CVE-2025-30065 PoC

binary-exploitationcontainer-securityexploitation+2
1 year ago
poc-cve-2024-38396 preview

poc-cve-2024-38396

GitHubvin01/poc-cve-2024-38396

PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution

container-securityeducationexploitation+2
192 years ago
k0otkit preview

k0otkit

GitHubmetarget/k0otkit

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

command-and-controlcontainer-escapecontainer-security+5
2995 years ago
abaddon preview
Archived

abaddon

GitHubwavestone-cdt/abaddon

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

cloud-infrastructure-securitycommand-and-controlexploit-frameworks+5
3313 years ago
KLAIOS preview

KLAIOS

GitHublglznl/klaios

KLAIOS is a hybrid security environment that merges Kali Linux’s offensive toolkit with hardened, VPN-bunker-style isolation—enhanced by modern AI…

ai-securitycontainer-securityexploit-frameworks+7
17 months ago
CVE-2026-5817-PoC preview

CVE-2026-5817-PoC

GitHubgouldnicholas/cve-2026-5817-poc

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

ai-securitycontainer-escapecontainer-security+4
3 months ago
boopkit preview

boopkit

GitHubkrisnova/boopkit

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

command-and-controlexploitationids-ips-evasion+6
1.7k3 years ago
PackMyPayload preview

PackMyPayload

GitHubmgeeky/packmypayload

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

container-securityexploit-frameworkspayload-development+3
1.2k2 years ago
cve-2022-42889-text4shell-docker preview

cve-2022-42889-text4shell-docker

GitHubkarthikuj/cve-2022-42889-text4shell-docker

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

container-securityeducationexploitation+3
753 years ago
POC-CVE-2019-5736 preview

POC-CVE-2019-5736

GitHubbbrathnayaka/poc-cve-2019-5736

Proof-of-concept exploits for CVE-2019-5736, a runC container escape vulnerability, demonstrating container breakout via malicious images and exec…

container-escapecontainer-securityexploitation+3
6 years ago
CVE-2022-42889-PoC preview

CVE-2022-42889-PoC

GitHubsunnyvale-it/cve-2022-42889-poc

CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept

container-securityeducationexploitation+3
23 years ago
log4j-vulnerable-app-cve-2021-44228-terraform preview

log4j-vulnerable-app-cve-2021-44228-terraform

GitHubmkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform

A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228

cloud-infrastructure-securityexploitationpayload-generation+3
24 years ago
IngressNightmare-PoC preview

IngressNightmare-PoC

GitHublufeirider/ingressnightmare-poc

One-click proof-of-concept exploit script for IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974)…

exploitationpayload-generationpenetration-testing+3
91 year ago
Log4j-Exploit-CVE-2021-44228 preview

Log4j-Exploit-CVE-2021-44228

GitHubwillian-2-0-0-1/log4j-exploit-cve-2021-44228

Exploit tool for CVE-2021-44228 (Log4Shell) that sets up a malicious LDAP server and delivers a Java payload to achieve remote code execution on…

command-and-controlexploitationpayload-generation+3
4 years ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubdevengpk/cve-2022-22965

Dockerized Spring4Shell (CVE-2022-22965) proof-of-concept with Python exploit script and webshell deployment for educational vulnerability testing.

container-securityeducationexploitation+3
3 years ago