Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
110 results
CVE-2025-1974 preview

CVE-2025-1974

GitHubiteride/cve-2025-1974

In-depth technical analysis of CVE-2025-1974 (IngressNightmare), a critical RCE in ingress-nginx validating admission controller for Kubernetes,…

cloud-securitycontainer-securityeducation+4
11 months ago
CVE-2025-70849-Podinfo preview

CVE-2025-70849-Podinfo

GitHubkazisabu/cve-2025-70849-podinfo

PoC and Advisory for CVE-2025-70849: Unauthenticated Stored XSS in Podinfo /store endpoint.

educationexploitationpenetration-testing+3
4 months ago
CVE-2025-70849 preview

CVE-2025-70849

GitHubdeaprojects/cve-2025-70849

CVE-2025-70849: Stored XSS in Podinfo

educationexploitationpenetration-testing+2
13 months ago
poc_CVE-2018-1002105 preview

poc_CVE-2018-1002105

GitHubevict/poc_cve-2018-1002105

Proof-of-concept exploit for CVE-2018-1002105 targeting Kubernetes API server. Supports authenticated and unauthenticated privilege escalation to…

cloud-securitycontainer-securityexploitation+4
2237 years ago
CVE-2021-25735 preview

CVE-2021-25735

GitHubdarryk10/cve-2021-25735

Exploit for CVE-2021-25735 demonstrating Kubernetes Validating Admission Webhook bypass via node label manipulation, with deployable Docker container…

cloud-securitycontainer-securityexploitation+3
175 years ago
secureCodeBox preview

secureCodeBox

GitHubsecurecodebox/securecodebox

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

cloud-securitycontainer-securitydevsecops+3
9881 day ago
CVE-2025-1974 preview

CVE-2025-1974

GitHubyoshino-s/cve-2025-1974

Exploit for CVE-2025-1974 targeting ingress-nginx controllers in Kubernetes, enabling container escape via crafted shared object injection and shell…

cloud-securitycontainer-escapeexploitation+3
531 year ago
janusec preview

janusec

GitHubjanusec/janusec

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

api-securityauthenticationcloud-security+8
1.2k1 month ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k4 days ago
iron-proxy preview

iron-proxy

GitHubparadigmxyz/iron-proxy

An egress firewall for untrusted workloads.

cloud-securitycontainer-securitydatabase-security+5
6458 days ago
Nightingale preview

Nightingale

GitHubrajanagori/nightingale

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

container-securityeducationforensics+7
3132 days ago
bromure preview

bromure

GitHubrderaison/bromure

Proper sandboxing for agentic coding and web browsing

ai-securitycontainer-securitydynamic-analysis-sandboxing+6
2781 day ago
bento preview

bento

GitHubhimazawa/bento

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

container-securityctfexploitation+4
765 years ago
docker-cve-2022-39253-poc preview

docker-cve-2022-39253-poc

GitHubssst0n3/docker-cve-2022-39253-poc

Proof-of-concept exploit for CVE-2022-39253 demonstrating Docker container escape via malicious Git repository build, enabling host file system read…

container-escapecontainer-securityexploitation+2
101 year ago
trivy-module-wordpress preview

trivy-module-wordpress

GitHubaquasecurity/trivy-module-wordpress

Trivy example module for WordPress

container-securitydevsecopsstatic-analysis+3
53 years ago
heartbleed preview

heartbleed

GitHubcheese-hub/heartbleed

Educational Docker-based lab demonstrating the Heartbleed bug (CVE-2014-0160) with hacker, victim, and server containers for hands-on exploitation…

container-securityctfeducation+4
27 years ago
helm-plugin-path-traversal-security-assessment preview

helm-plugin-path-traversal-security-assessment

GitHubamnsecurity/helm-plugin-path-traversal-security-assessment

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

cloud-securitycontainer-securitycurated-resources+6
11 month ago
Demo_CVE-2025-3248 preview

Demo_CVE-2025-3248

GitHubkiraly07/demo_cve-2025-3248

Educational lab simulating CVE-2025-3248 with a vulnerable Docker service and PoC exploit for hands-on security training and mitigation practice.

container-securityeducationexploitation+3
211 months ago
Previous1234567Next