Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
raptor preview

raptor

GitHubgadievron/raptor

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

ai-assisted-reversingbinary-analysisdynamic-analysis-sandboxing+7
3.7k
1 day ago
T3MP3ST preview

T3MP3ST

GitHubelder-plinius/t3mp3st

autonomous red teaming platform; multi-agent offensive-security meta-harness

ai-securitybinary-analysiscloud-security+9
5.6k11 days ago
Zetsu preview

Zetsu

GitHubchaelsoo/zetsu

A personal RAG system for offensive security knowledge

educationexploitationinformation-gathering+8
17612 days ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubnullroot-red/cve-2026-23744

Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).

educationexploitationpayload-generation+3
15 days ago
ProjectSecurity-Homelab preview

ProjectSecurity-Homelab

GitHubahndrewalters/projectsecurity-homelab

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…

container-securitydefensive-toolseducation+4
16 days ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k23 days ago
Certipy preview

Certipy

GitHubly4k/certipy

Tool for Active Directory Certificate Services enumeration and abuse

authenticationexploitationpenetration-testing+3
3.6k24 days ago
GPOHound preview

GPOHound

GitHubcogiceo/gpohound

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

configuration-auditinginformation-gatheringmisconfiguration+4
4171 month ago
CloudSec preview

CloudSec

GitHubeshlomo1/cloudsec

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

anti-botcloud-securitycontainer-escape+8
291 month ago
CVE-2026-53435 preview

CVE-2026-53435

GitHubamesianx/cve-2026-53435

An offensive security researcher + an AI vs. a fresh n-day: building the first public PoC for CVE-2026-53435 in one Friday night. Raw 8h20m log…

binary-exploitationeducationexploitation+3
112 months ago
redteam-research preview

redteam-research

GitHubblackarrowsec/redteam-research

Collection of PoC and offensive techniques used by the BlackArrow Red Team

exploitationpenetration-testingred-teaming+1
1.2k4 months ago
CVE-2021-41773---Apache-Path-Traversal---RCE preview

CVE-2021-41773---Apache-Path-Traversal---RCE

GitHubareeba-zehra-jafri/cve-2021-41773---apache-path-traversal---rce

Proof-of-concept (PoC) for CVE-2021-41773, demonstrating Apache HTTP Server 2.4.49 path traversal and remote code execution (RCE) in a controlled lab…

educationexploitationlabs-practice+3
5 months ago
context-aware-offensive-intelligence preview

context-aware-offensive-intelligence

GitHubindoushka/context-aware-offensive-intelligence

Research framework redefining post-exploitation through decision intelligence.

configuration-auditinginformation-gatheringmisconfiguration+4
7 months ago
DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint- preview

DDoS-Purple-Teaming-Offensive-Multi-Vector-7-Tier-Defensive-Holistic-Blueprint-

GitHubsastraadiwiguna-purpleeliteteaming/ddos-purple-teaming-offensive-multi-vector-7-tier-defensive-holistic-blueprint-

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

cloud-securitycommand-and-controldefensive-tools+9
7 months ago
cve-2025-59532-poc preview

cve-2025-59532-poc

GitHubbaktistr/cve-2025-59532-poc

A Docker-based research environment for analyzing CVE-2025-59532, a path traversal vulnerability in OpenAI Codex CLI that allows arbitrary file write…

container-securityctfeducation+5
8 months ago
cve-2025-62726-poc preview

cve-2025-62726-poc

GitHubbaktistr/cve-2025-62726-poc

This is a proof-of-concept demonstration for CVE-2025-62726, created for educational purposes as part of a class project. Part of CMU Course : 18-739…

educationexploitationpayload-development+3
8 months ago
rejjeto_hfs-rce-exploit-cve-2014-6287 preview

rejjeto_hfs-rce-exploit-cve-2014-6287

GitHubjoaz94/rejjeto_hfs-rce-exploit-cve-2014-6287

Remote Command Execution exploit for Rejetto HTTP File Server 2.3.x (CVE-2014-6287) rewritten in Python 3 for modern offensive security testing.

command-and-controleducationexploitation+5
8 months ago
CVE2_Jenkins_RCE preview

CVE2_Jenkins_RCE

GitHubdavidmgaviria/cve2_jenkins_rce

A proof of concept cross-site WebSocket hijacking exploit for CVE-2024-23898 — a vulnerability affecting Jenkins versions 2.217-2.441. For…

educationexploitationpenetration-testing+3
21 year ago
Previous12Next