Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
179 results
CVE-2024-4323-Exploit-POC preview

CVE-2024-4323-Exploit-POC

GitHubskilfoy/cve-2024-4323-exploit-poc

This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code…

exploitationpayload-generationpenetration-testing+3
152 years ago
CVE-2020-11978 preview

CVE-2020-11978

GitHubpberba/cve-2020-11978

PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11

command-and-controlexploitationpenetration-testing+2
85 years ago
Unrestricted-File-Upload-on-SiteMagic-CMS-4.4.2 preview

Unrestricted-File-Upload-on-SiteMagic-CMS-4.4.2

GitHubv1n1v131r4/unrestricted-file-upload-on-sitemagic-cms-4.4.2

This repo describe how to exploit unrestricted file upload vulnerability on SiteMagic CMS 4.4.2

penetration-testingvulnerability-analysisweb-application-exploitation
26 years ago
CVE-2025-6018-and-CVE-2025-6019-Privilege-Escalation preview

CVE-2025-6018-and-CVE-2025-6019-Privilege-Escalation

GitHubazureadtrent/cve-2025-6018-and-cve-2025-6019-privilege-escalation

This is just a quick note on how to exploit these vulnerabilities to get root.

exploitationpenetration-testingpost-exploitation+2
16 months ago
CVE-2023-27997 preview

CVE-2023-27997

GitHubcyb3renthusiast/cve-2023-27997

How to get access via CVE-2022-27997

exploitationinformation-gatheringpenetration-testing+2
2 years ago
VBA-RunPE preview
Archived

VBA-RunPE

GitHubitm4n/vba-runpe

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

exploitationids-ips-evasionpayload-development+3
8156 years ago
NodeGoat preview

NodeGoat

GitHubowasp/nodegoat

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

educationlabs-practicelearning-paths-courses+3
2.1k3 years ago
Leaked-Credentials preview

Leaked-Credentials

GitHubh4x0r-dz/leaked-credentials

how to look for Leaked Credentials !

educationinformation-gatheringpenetration-testing+2
1.1k2 years ago
netlas-cookbook preview

netlas-cookbook

GitHubnetlas-io/netlas-cookbook

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

curated-resourcesdigital-forensicseducation+9
8891 year ago
exploit-writing-for-oswe preview

exploit-writing-for-oswe

GitHubrizemon/exploit-writing-for-oswe

Tips on how to write exploit scripts (faster!)

curated-resourceseducationpayload-development+4
6002 years ago
Flutter-Reverse-Engineering-Labs preview

Flutter-Reverse-Engineering-Labs

GitHubbrnpl/flutter-reverse-engineering-labs

Hands-on challenges for learning how to reverse engineer Flutter applications.

android-securitybinary-analysisctf+6
5815 days ago
CmdLineSpoofer preview

CmdLineSpoofer

GitHubplackyhacker/cmdlinespoofer

How to spoof the command line when spawning a new process from C#.

command-and-controleducationexploitation+5
1124 years ago
CVE-2022-42889-POC preview

CVE-2022-42889-POC

GitHubkorteke/cve-2022-42889-poc

A simple application that shows how to exploit the CVE-2022-42889 vulnerability

educationexploitationpayload-development+3
103 years ago
CVE-2016-6516-exploit preview

CVE-2016-6516-exploit

GitHubwpengfei/cve-2016-6516-exploit

An demonstration of how to exploit double-fetch vulnerability CVE-2016-6516

binary-exploitationeducationexploitation+2
98 years ago
hinge-command-control-c2 preview

hinge-command-control-c2

GitHubmatthewwiese/hinge-command-control-c2

A proof of concept demonstrating how to use the Hinge dating app as a C2.

command-and-controlosintpenetration-testing+3
118 months ago
SAPGateBreaker-Exploit preview

SAPGateBreaker-Exploit

GitHubbecodoexploit-mrcat/sapgatebreaker-exploit

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

educationexploitationpenetration-testing+3
31 year ago
nextjs-middleware-bypass-demo preview

nextjs-middleware-bypass-demo

GitHubfourcube/nextjs-middleware-bypass-demo

Demonstrates a middleware bypass vulnerability (CVE-2025-29927) in Next.js, showing how to exploit the x-middleware-subrequest header to access…

educationpenetration-testingvulnerability-analysis+2
51 year ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubthebl4ckph4nt0m/cve-2024-0044

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13. This repo demonstrates how to exploit…

android-securityeducationexploitation+3
21 year ago
Previous12…10Next