Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
1day-archive preview

1day-archive

GitHub1dayexploit/1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

binary-analysiscurated-resourceseducation+5
29
8 days ago
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

binary-exploitationcurated-resourceseducation+9
3.9k7 months ago
analyze-Exploit-CVE-2023-22518-Confluence preview

analyze-Exploit-CVE-2023-22518-Confluence

GitHubd3ckkno0b/analyze-exploit-cve-2023-22518-confluence

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

code-analysisdebuggerseducation+4
11 year ago
sagemcom-fast-3890-exploit preview

sagemcom-fast-3890-exploit

GitHublyrebirds/sagemcom-fast-3890-exploit

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

binary-exploitationembedded-systems-securityexploitation+4
2246 years ago
TwoMillion-Machine-Writeup preview

TwoMillion-Machine-Writeup

GitHubanxs3c/twomillion-machine-writeup

Step-by-step penetration testing walkthrough for a HackTheBox Linux box: API enumeration, vertical privilege escalation, OS command injection,…

ctfeducationexploitation+7
2 months ago
readable-thrift preview

readable-thrift

GitHubnccgroup/readable-thrift

Converts binary Thrift protocol messages to/from human-readable JSON for manual analysis and tampering, with support for integration into Burp and…

penetration-testingreverse-engineeringutilities-frameworks+2
244 years ago
pwn2own2018 preview

pwn2own2018

GitHubsaelo/pwn2own2018

Exploit chain for Safari + macOS exploiting JIT type confusion, launchd sandbox escape, and XNU IPC MitM for kernel code execution.

binary-exploitationeducationexploitation+5
7597 years ago
pwn-hisilicon-dvr preview

pwn-hisilicon-dvr

GitHubtothi/pwn-hisilicon-dvr

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

binary-analysisembedded-systems-securityexploitation+8
3833 years ago
PHPStudy-Backdoor preview

PHPStudy-Backdoor

GitHubjas502n/phpstudy-backdoor

Proof-of-concept exploit for PHPStudy backdoor with DLL detection, remote command execution via HTTP Accept-Charset header, and embedded C2 payloads…

command-and-controlmalware-analysispayload-development+4
196 years ago
CVE-2026-33439 preview

CVE-2026-33439

GitHubthemalwareguardian/cve-2026-33439

Exploit implementation for CVE-2026-33439, a pre-authentication Java deserialization RCE in OpenAM. Includes detailed vulnerability analysis, gadget…

binary-exploitationcode-analysiseducation+8
23 months ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

android-securityauthenticationcryptography+8
1011 year ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab demonstrating Log4Shell (CVE-2021-44228) exploitation using Docker, Kali Linux, Burp Suite, and log4j-shell-poc. Designed for controlled…

command-and-controleducationexploitation+7
8 months ago
Solar-exploiting-log-4j preview

Solar-exploiting-log-4j

GitHublathika-3006/solar-exploiting-log-4j

Step-by-step TryHackMe walkthrough for exploiting the Log4Shell vulnerability (CVE-2021-44228) to achieve remote code execution and capture flags.

educationexploitationlabs-practice+6
25 months ago
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

binary-analysiscommand-and-controlembedded-systems-security+7
21 year ago
DarkSword_analysis preview

DarkSword_analysis

GitHubstationedk-06/darksword_analysis

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

binary-analysiseducationexploit-frameworks+5
15 months ago
CVE-2026-6307-Longinus preview

CVE-2026-6307-Longinus

GitHubj4ck3lsyn-gen2/cve-2026-6307-longinus

Proof-of-concept exploit for CVE-2026-6307, a V8 TurboFan type confusion enabling addrof/fakeobj primitives for sandbox escape and remote code…

binary-exploitationeducationexploitation+6
101 month ago
CVE-2025-60854 preview

CVE-2025-60854

GitHubk0n9-log/cve-2025-60854

Technical analysis and proof-of-concept exploit for a command injection vulnerability (CVE-2025-60854) in D-Link AX1500 routers, enabling…

binary-analysiscommand-and-controlembedded-systems-security+7
8 months ago
CVE-2025-26244 preview

CVE-2025-26244

GitHubjarm222/cve-2025-26244

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

command-and-controlexploitationpayload-development+4
1 year ago
Previous123Next