Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
CVE-2026-58138 preview

CVE-2026-58138

GitHub0xblackash/cve-2026-58138

Defensive security research repository detailing CVE-2026-58138, an unauthenticated RCE in Conductor via GraalVM. Provides technical analysis,…

curated-resourcesdefensive-toolseducation+3
1
1 day ago
EpSiLoNPoInTlnk preview

EpSiLoNPoInTlnk

GitHubepsilonpointori/epsilonpointlnk

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

anti-botexploitationmalware-analysis+4
24 months ago
CVE-2026-72898 preview

CVE-2026-72898

GitHub0xblackash/cve-2026-72898

CVE-2026-72898

database-securityexploitationincident-response+3
524 days ago
xss2shell preview

xss2shell

GitHub0xlipon/xss2shell

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

defensive-toolspayload-generationpenetration-testing+6
328 days ago
adversary_emulation_library preview

adversary_emulation_library

GitHubcenter-for-threat-informed-defense/adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

curated-resourcesdata-exfiltrationdefensive-tools+5
2.2k1 year ago
pocKeycloakCVE-2023-0264 preview

pocKeycloakCVE-2023-0264

GitHubeliangonzi00/pockeycloakcve-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

authenticationdefensive-toolsexploitation+7
1 month ago
cve-2025-55182-react2shell_reproduction preview

cve-2025-55182-react2shell_reproduction

GitHubrazureink/cve-2025-55182-react2shell_reproduction

CVE Reproduction: cve-2025-55182-react2shell_reproduction

exploitationpayload-developmentpenetration-testing+3
1 month ago
Predator preview

Predator

GitHubs0md3v/predator

Anti-Automation System

anti-botcrawlerids-ips-evasion+3
1275 years ago
awswaf preview

awswaf

GitHubxkiian/awswaf

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

anti-botcaptcha-bypassids-ips-evasion+3
3591 year ago
OSWE-Labs-Poc preview

OSWE-Labs-Poc

GitHubsvdwi/oswe-labs-poc

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

ctfeducationexploitation+4
1345 years ago
CVE-2020-3452 preview

CVE-2020-3452

GitHubmurataydemir/cve-2020-3452

[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal

exploitationinformation-gatheringpenetration-testing+3
85 years ago
CVE-2021-3441-check preview

CVE-2021-3441-check

GitHubtcbutler320/cve-2021-3441-check

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

exploitationinformation-gatheringioc-management+3
25 years ago
CVE-2023-22515-Scan preview

CVE-2023-22515-Scan

GitHuberikwynter/cve-2023-22515-scan

Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence

exploitationinformation-gatheringpenetration-testing+3
802 years ago
wp2shell-scan preview

wp2shell-scan

GitHubinstawp/wp2shell-scan

Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

defensive-toolsforensicsincident-response+5
51 month ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

command-and-controldefensive-toolseducation+8
13 years ago
follina preview

follina

GitHubnoxtal/follina

All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as…

command-and-controlexploitationpayload-generation+3
214 years ago
fire-wall-server preview

fire-wall-server

GitHubnosie12/fire-wall-server

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

defensive-toolseducationintrusion-detection+3
1 year ago
Arbitrary-File-Read-CVE-2024-24919 preview

Arbitrary-File-Read-CVE-2024-24919

GitHubluismateo1/arbitrary-file-read-cve-2024-24919

Walkthrough of detecting, investigating, and responding to a CVE-2024-24919 path traversal attack, including log analysis, threat intel checks, and…

educationexploitationincident-response+3
1 year ago
Previous1234Next