Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
227 results
redis-post-exploitation preview

redis-post-exploitation

GitHubknqyf263/redis-post-exploitation

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

database-securityeducationexploitation+3
3
5 years ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
12 months ago
samba-trans2open-exploit-report preview

samba-trans2open-exploit-report

GitHubbakr-ht/samba-trans2open-exploit-report

Exploitation report of the Samba Trans2Open vulnerability (CVE-2003-0201), including tools used, exploitation steps, and protection techniques to…

educationexploitationnetwork-mapping+6
211 months ago
CVE-2026-31431-Metasploit-exploit preview

CVE-2026-31431-Metasploit-exploit

GitHubadityasingh108/cve-2026-31431-metasploit-exploit

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…

binary-exploitationeducationexploitation+7
23 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
zerologon preview

zerologon

GitHubwrathfuldiety/zerologon

zerologon script to exploit CVE-2020-1472 CVSS 10/10

educationexploitationlateral-movement+5
25 years ago
Penetration-Test preview

Penetration-Test

GitHubjeevananand1202/penetration-test

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

educationexploitationpassword-cracking+6
4 months ago
osTicketFileReadIntoRCE preview

osTicketFileReadIntoRCE

GitHubclarissss/osticketfilereadintorce

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket…

educationexploitationpayload-development+6
5 months ago
offensive-security-adversary-emulation preview

offensive-security-adversary-emulation

GitHubkhalilu020/offensive-security-adversary-emulation

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

educationexploitationlabs-practice+5
29 days ago
BlueDoor preview

BlueDoor

GitHubsethwhy/bluedoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative…

ctfeducationexploitation+7
21 year ago
CVE-2025-50154-Aggressor-Script preview

CVE-2025-50154-Aggressor-Script

GitHubash1996x/cve-2025-50154-aggressor-script

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

command-and-controlctfeducation+9
111 months ago
EternalBlue-Exploit-Demonstration preview

EternalBlue-Exploit-Demonstration

GitHubdannic145/eternalblue-exploit-demonstration

Educational lab demonstrating EternalBlue (MS17-010) exploitation against Windows 7 using Metasploit, including post-exploitation, WannaCry…

ctfeducationexploitation+8
4 months ago
pentest-metasploitable2 preview

pentest-metasploitable2

GitHubemilebarnard242/pentest-metasploitable2

Structured penetration testing lab documenting a full attack chain from network reconnaissance to root exploitation of vsftpd 2.3.4 backdoor, with…

educationexploitationlabs-practice+6
4 months ago
HTB-Pterodactyl-Writeup preview

HTB-Pterodactyl-Writeup

GitHubv0idw1re/htb-pterodactyl-writeup

HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM…

ctfeducationexploitation+9
4 months ago
Optimum preview

Optimum

GitHubr3fr4kt/optimum

Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain…

educationexploitationinformation-gathering+7
5 months ago
Exploiting-Samba-on-Metasploitable-2 preview

Exploiting-Samba-on-Metasploitable-2

GitHubvig9610/exploiting-samba-on-metasploitable-2

Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a…

educationexploitationexploit-frameworks+8
5 months ago
EternalBlue-Exploit-Demonstration-MS17-010 preview

EternalBlue-Exploit-Demonstration-MS17-010

GitHubichhyak22/eternalblue-exploit-demonstration-ms17-010

Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving…

command-and-controleducationexploitation+8
4 months ago
PwnTillDawn-Portal-Walkthrough preview

PwnTillDawn-Portal-Walkthrough

GitHubtr00jan99/pwntilldawn-portal-walkthrough

A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to…

ctfeducationexploitation+5
5 months ago
Previous1…91011…13Next