Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
75 results
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.3k
15h 52m ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerdynamic-code-analysisfuzzing+8
15.2k1 year ago
Demo_CVE-2025-3248 preview

Demo_CVE-2025-3248

GitHubkiraly07/demo_cve-2025-3248

Educational lab simulating CVE-2025-3248 with a vulnerable Docker service and PoC exploit for hands-on security training and mitigation practice.

container-securityeducationexploitation+3
211 months ago
CVE-2026-39987-Lab preview

CVE-2026-39987-Lab

GitHubrootdirective-sec/cve-2026-39987-lab

Local Docker lab reproducing CVE-2026-39987, a pre-auth RCE in marimo's terminal WebSocket. Compares vulnerable and patched versions with least-harm…

container-securityeducationexploitation+3
14 months ago
cve-images preview

cve-images

GitHubedgecases-purplehax/cve-images

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

container-securityctfcurated-resources+5
13 months ago
CVE-2026-23744-Lab preview

CVE-2026-23744-Lab

GitHubrootdirective-sec/cve-2026-23744-lab

Docker lab to compare vulnerable and patched builds of MCPJam Inspector for CVE-2026-23744, demonstrating network binding differences and API…

container-securityeducationlabs-practice+2
7 months ago
cve-2017-7529 preview

cve-2017-7529

GitHubcved-sources/cve-2017-7529

Docker-based reproduction of CVE-2017-7529 (Nginx integer overflow) for security testing and education. Part of the Cved vulnerable container…

container-securityeducationexploitation+2
5 years ago
Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212- preview

Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212-

GitHubjasalurah/creating-a-vulnerable-docker-environment-cve-2023-30212-

Docker-based vulnerable environment for practicing CVE-2023-30212 exploitation, featuring an OURPHP web app with a reflected XSS vulnerability for…

container-securityeducationexploitation+3
3 years ago
CVE-2021-42013 preview

CVE-2021-42013

GitHublayarkacasiber/cve-2021-42013

Docker-based lab environment for exploiting CVE-2021-42013 (Apache HTTP Server path traversal and RCE) with step-by-step setup instructions for…

container-securityeducationexploitation+3
4 years ago
-INE_Shivam_Gupta_23104003 preview

-INE_Shivam_Gupta_23104003

GitHubshivamg2004/-ine_shivam_gupta_23104003

CVE-2021-43798 Grafana Unauthenticated Path Traversal - Security Lab | Shivam Gupta | 23104003

container-securityeducationexploitation+5
3 days ago
Nightingale preview

Nightingale

GitHubrajanagori/nightingale

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

container-securityeducationforensics+7
3121 day ago
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

container-securitydevsecopsdns-subdomain-enumeration+8
111 days ago
owasp-ctf-in-a-box preview

owasp-ctf-in-a-box

GitHubowasp/owasp-ctf-in-a-box

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

container-securityctfdevsecops+6
112 days ago
owasp-ctf preview

owasp-ctf

GitHubowasp/owasp-ctf

Self-hosted CTF control plane for security-learning events: team registration, live leaderboard, and patch-to-score, quiz, jeopardy, and AI challenge…

container-securityctfdevsecops+7
112 days ago
neko preview

neko

GitHubm1k1o/neko

A self hosted virtual browser that runs in docker and uses WebRTC.

container-securityprivacyremote-access-tool+1
22.4k13 days ago
offensive-docker preview

offensive-docker

GitHubaaaguirrep/offensive-docker

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

container-securityexploit-frameworkspassword-cracking+5
7724 years ago
bento preview

bento

GitHubhimazawa/bento

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

container-securityctfexploitation+4
765 years ago
log4shell-poc-lab preview

log4shell-poc-lab

GitHubobscuritylabs/log4shell-poc-lab

A lab demonstration of the log4shell vulnerability: CVE-2021-44228

container-securityeducationexploitation+3
94 years ago
Previous12345Next