Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
BlueCloud preview

BlueCloud

GitHubiknowjason/bluecloud

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

cloud-infrastructure-securitycloud-securitydefensive-tools+7
149
3 years ago
CVE-2024-47176 preview

CVE-2024-47176

GitHubdeancooreman/cve-2024-47176

Automated VirtualBox lab for exploiting CVE-2024-47176 (CUPS RCE) with a custom Python exploit, target Ubuntu VM, and Kali attacker VM for hands-on…

educationexploitationlabs-practice+2
3 months ago
CVE-2023-27326 preview

CVE-2023-27326

GitHubmalwareman007/cve-2023-27326

VM Escape for Parallels Desktop <18.1.1

binary-exploitationexploitationexploit-frameworks+4
373 years ago
CVE-2026-66804 preview

CVE-2026-66804

GitHubcypherhippie/cve-2026-66804

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

exploitationpenetration-testingpost-exploitation+1
118 days ago
VMPacker preview

VMPacker

GitHubleochen-coremind/vmpacker

ARM64 ELF Virtual Machine Protection System

anti-botbinary-analysisembedded-systems-security+8
4945 months ago
CVE-2026-66804-CrossDevice-Service-EoP preview

CVE-2026-66804-CrossDevice-Service-EoP

GitHubrat5ak/cve-2026-66804-crossdevice-service-eop

CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM

educationexploitationpenetration-testing+3
2423 days ago
RootQuest-CTF-Box-Multi-Stage-Exploitation-VM preview

RootQuest-CTF-Box-Multi-Stage-Exploitation-VM

GitHubthieveshkar/rootquest-ctf-box-multi-stage-exploitation-vm

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

binary-exploitationcryptographyctf+7
10 months ago
CVE-2024-21111 preview

CVE-2024-21111

GitHubx0rsys/cve-2024-21111

Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16

binary-exploitationexploitationpenetration-testing+2
22 years ago
Analyse-faille-de-s-curit-CVE-2025-6018-CVE-2025-6019 preview

Analyse-faille-de-s-curit-CVE-2025-6018-CVE-2025-6019

GitHubeuxem/analyse-faille-de-s-curit-cve-2025-6018-cve-2025-6019

Hands-on lab demonstrating exploitation of CVE-2025-6018 and CVE-2025-6019 using a pre-configured openSUSE Leap VM with Vagrant and VirtualBox for…

educationexploitationlabs-practice+2
9 months ago
cve-2026-23398-poc preview

cve-2026-23398-poc

GitHubzpol/cve-2026-23398-poc

Reproducible lab for CVE-2026-23398, a Linux kernel NULL dereference in icmp_tag_validation() triggered by ICMP Fragmentation Needed packets, causing…

educationexploitationfuzzing+3
15 months ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubjorrit-vm/cve-2026-33017

Educational lab demonstrating unauthenticated RCE in Langflow via CVE-2026-33017, with automated VM setup and a PoC exploit for reverse shell.

educationexploitationlabs-practice+6
14 months ago
CVE-2018-1002105 preview

CVE-2018-1002105

GitHubsh-ubh/cve-2018-1002105

Proof-of-concept exploit for CVE-2018-1002105, a Kubernetes privilege escalation vulnerability allowing unauthorized command execution in pods via…

cloud-securitycontainer-securityexploitation+3
14 years ago
TraditionalJay preview

TraditionalJay

GitHubastraljays/traditionaljay

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

cloud-securitycommand-and-controleducation+5
1 month ago
CVE-2023-46604 preview

CVE-2023-46604

GitHubklaasstessens/cve-2023-46604

Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)

educationexploitationlabs-practice+3
3 months ago
CVE-2023-33668 preview

CVE-2023-33668

GitHublodi-g/cve-2023-33668

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

binary-analysiseducationexploitation+3
23 years ago
vphone-cli preview

vphone-cli

GitHublakr233/vphone-cli

Boot and manage virtual iPhones on Apple Silicon with firmware patching, jailbreak variants, and security research features for iOS testing and…

exploitationfirmware-analysisios-security+3
10.5k5 days ago
CyberSec2026 preview

CyberSec2026

GitHubsanderschepers1993/cybersec2026

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

educationexploitationlabs-practice+3
3 months ago
commando-vm preview

commando-vm

GitHubmandiant/commando-vm

Customizable Windows-based virtual machine distribution pre-packaged with offensive security tools for penetration testing and red teaming operations.

dynamic-analysis-sandboxingpenetration-testingred-teaming+1
7.8k10 months ago
Previous12Next