Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
206 results
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
745
5 years ago
CVE-2020-10770-keycloak-exploit-poc preview

CVE-2020-10770-keycloak-exploit-poc

GitHub0xlyvio/cve-2020-10770-keycloak-exploit-poc

Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

educationexploitationpenetration-testing+3
7 days ago
CVE-2015-8562 preview

CVE-2015-8562

GitHubdmonst3r/cve-2015-8562

Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header

exploitationpenetration-testingremote-access-tool+2
49 years ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
720 days ago
CVE-2019-18634-writeup preview

CVE-2019-18634-writeup

GitHubdevteam6rabbit/cve-2019-18634-writeup

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

binary-exploitationctfeducation+4
8 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubdevtint/cve-2026-41940

Technical analysis and educational resource for CVE-2026-41940, covering root cause, scanner behavior, prevention, mitigation, IOC hunting, and VaPT…

curated-resourceseducationincident-response+3
4 months ago
cve_2026_31431_audit preview

cve_2026_31431_audit

GitHubmariohy/cve_2026_31431_audit

A security auditing toolkit for CVE-2026-31431 vulnerability research

exploitationpenetration-testingpost-exploitation+3
4 months ago
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
264 months ago
CVE-2021-34600 preview

CVE-2021-34600

GitHubx41sec/cve-2021-34600

Proof-of-concept exploit for CVE-2021-34600, demonstrating a key generation vulnerability in Telenot access control systems using Proxmark3 RFID…

exploitationhardware-hackinghardware-iot-security+3
34 years ago
cve-2021-3864 preview

cve-2021-3864

GitHubwalac/cve-2021-3864

Proof-of-concept exploit for CVE-2021-3864, a privilege escalation vulnerability in logrotate, demonstrating core file generation to achieve root…

exploitationpenetration-testingprivilege-escalation+2
4 years ago
HotelDruid-CVE-2021-42948 preview

HotelDruid-CVE-2021-42948

GitHubdhammon/hoteldruid-cve-2021-42948

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
CVE-2025-60375 preview

CVE-2025-60375

GitHubajansha/cve-2025-60375

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

authenticationexploitationpenetration-testing+2
11 months ago
CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE preview

CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE

GitHubyunfeige18/cve-2026-1281-cve-2026-1340-ivanti-epmm-rce

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

educationexploitationpenetration-testing+2
36 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubahmadf77/cve-2026-23744

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

command-and-controlexploitationpayload-development+3
5 months ago
reconkg preview

reconkg

GitHubxghst0/reconkg

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

network-securitypenetration-testingthreat-feeds-aggregators+2
18 days ago
SharpExchange preview

SharpExchange

GitHubceramicskate0/sharpexchange

C# Tool to interact with MS Exchange based on MS docs

data-exfiltrationeducationinformation-gathering+4
1023 years ago
exploit-writing-for-oswe preview

exploit-writing-for-oswe

GitHubrizemon/exploit-writing-for-oswe

Tips on how to write exploit scripts (faster!)

curated-resourceseducationpayload-development+4
6012 years ago
wmiexec-Pro preview

wmiexec-Pro

GitHubxiaolichan/wmiexec-pro

New generation of wmiexec.py

information-gatheringlateral-movementpenetration-testing+5
1.3k5 months ago
Previous12…12Next