Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
thm_steelmountain_CVE-2014-6287 preview

thm_steelmountain_CVE-2014-6287

GitHubmrintern/thm_steelmountain_cve-2014-6287

a python3 version of the exploit written for CVE-2014-6287. Useful for completing the "Steel Mountain" room on TryHackMe.com without the use of…

binary-exploitationctfeducation+3
1
4 years ago
thm-Moniker-Link-cve-2024-21413-writeup preview

thm-Moniker-Link-cve-2024-21413-writeup

GitHubshauryarathore357-hub/thm-moniker-link-cve-2024-21413-writeup

TryHackMe room walkthrough of CVE-2024-21413, covering the Outlook Moniker Link Protected View bypass, NTLM hash leaking, and credential capture with…

ctfeducationexploitation+6
19 days ago
probable_subdomains preview
Archived

probable_subdomains

GitHubzzzteph/probable_subdomains

Subdomains analysis and generation tool. Reveal the hidden!

curated-resourcesdns-subdomain-enumerationinformation-gathering+4
2431 year ago
THM-Vulnerability_Capstone-CVE-2018-16763 preview
Archived

THM-Vulnerability_Capstone-CVE-2018-16763

GitHubwizardy0ga/thm-vulnerability_capstone-cve-2018-16763

A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.

ctfeducationexploitation+5
4 years ago
BreakEscape preview

BreakEscape

GitHubcliffe/breakescape

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

ctfeducationlabs-practice+3
61 day ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
6 months ago
THM-Source-CVE-2019-15231 preview
Archived

THM-Source-CVE-2019-15231

GitHubwizardy0ga/thm-source-cve-2019-15231

A write up on the TryHackMe room Source & a python script to exploit the vulnerability

ctfeducationexploitation+3
4 years ago
CVE-2021-44228_PoC preview

CVE-2021-44228_PoC

GitHubab0x90/cve-2021-44228_poc

Python proof-of-concept for CVE-2021-44228 (Log4Shell) that automates exploitation via a crafted Java payload, with argparse options for customizable…

educationexploitationpayload-generation+3
164 years ago
Active-Directory-BadSuccessor preview

Active-Directory-BadSuccessor

GitHubmusa-xvi/active-directory-badsuccessor

A TryHackme room covering the CVE-2025-53779 exploitation using windows

authenticationctfeducation+6
4 months ago
THM---Solar-exploiting-Log-4j preview

THM---Solar-exploiting-Log-4j

GitHubsaru1718/thm---solar-exploiting-log-4j

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

educationexploitationids-ips-evasion+7
6 months ago
mysqli preview

mysqli

GitHubrgkue/mysqli

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

ctfeducationpassword-cracking+3
3 months ago
CVE-2022-22909 preview

CVE-2022-22909

GitHubkaal18/cve-2022-22909

Python-based exploit for Hotel Druid 3.0.3 Remote Code Execution (CVE-2022-22909). Injects PHP payloads via room names to achieve command execution…

exploitationpayload-generationpenetration-testing+3
24 years ago
Room-Walkthrough-Billing preview

Room-Walkthrough-Billing

GitHubadityabhatt3010/room-walkthrough-billing

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

ctfeducationexploitation+6
142 months ago
CVE-2026-66749-Unchecked-Room-Lookup-Leads-to-Server-Crash-Let-s-Chat- preview

CVE-2026-66749-Unchecked-Room-Lookup-Leads-to-Server-Crash-Let-s-Chat-

GitHubtheopaid/cve-2026-66749-unchecked-room-lookup-leads-to-server-crash-let-s-chat-

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

code-analysiseducationexploitation+4
2 months ago
CVE-2026-38361 preview

CVE-2026-38361

GitHuba1ohadance/cve-2026-38361

Advisory: CVE-2026-38361 multiple DoS vulnerabilities (CWE-400/CWE-670) in dash-uploader (Python/PyPI)

educationexploitationpenetration-testing+2
4 months ago
CVE-Research preview

CVE-Research

GitHubanugiarrawwala/cve-research

CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523

ctfeducationexploitation+2
2 years ago
CVE-2024-23742 preview

CVE-2024-23742

GitHubgiovannipajeu1/cve-2024-23742

Proof-of-concept exploit for CVE-2024-23742 in Loom for macOS. Validates vulnerability and injects arbitrary code via RunAsNode settings to gain a…

exploitationpayload-generationpenetration-testing+3
12 years ago
CVE-2025-65881 preview

CVE-2025-65881

GitHubmmakingdom/cve-2025-65881

Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php Due to invalid Content-Type

code-analysiseducationpenetration-testing+3
10 months ago
Previous12Next