Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
481 results
commons-text-goat preview

commons-text-goat

GitHubtulhan/commons-text-goat

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

educationexploitationlabs-practice+3
1
3 years ago
LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197 preview

LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197

GitHubarkha-corvus/letsdefend-soc235-atlassian-confluence-broken-access-control-0-day-cve-2023-22515-eventid-197

I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian…

educationincident-responselog-analysis+3
111 months ago
iovy_root_research preview

iovy_root_research

GitHubmobilelinux/iovy_root_research

A root tool based on the [CVE-2015-1805 vulnerability](https://access.redhat.com/security/cve/cve-2015-1805) It supports 32 and 64bit, get sys call…

android-securitybinary-exploitationexploitation+2
7 years ago
log4shellwithlog4j2_13_3 preview

log4shellwithlog4j2_13_3

GitHubpaulvkitor/log4shellwithlog4j2_13_3

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

educationexploitationlabs-practice+2
4 years ago
PentesterLab preview

PentesterLab

GitHubelw0od/pentesterlab

OrangeBadge - Exercise CVE-2018-6574: go get RCE

binary-exploitationeducationexploitation+3
1 year ago
katoolin3 preview
Archived

katoolin3

GitHubs-h-3-l-l/katoolin3

Get your favourite Kali Linux tools on Debian/Ubuntu/Linux Mint

educationgeneral-purpose-utilitiespenetration-testing+2
3856 years ago
LOIC preview
Archived

LOIC

GitHubneweracracker/loic

Deprecated - Low Orbit Ion Cannon - An open source network stress tool, written in C#. Based on Praetox's LOIC project. USE ON YOUR OWN RISK. WITHOUT…

command-and-controleducationnetwork-mapping+2
3.0k2 years ago
seeker preview

seeker

GitHubthewhiteh4t/seeker

Accurately Locate Smartphones using Social Engineering

educationinformation-gatheringosint+3
10.0k3 months ago
moukthar preview

moukthar

GitHubtomiwa-ot/moukthar

Android remote administration tool

android-securitycommand-and-controldata-exfiltration+6
68010 months ago
PartyLoud preview

PartyLoud

GitHubdavideolgiati/partyloud

A simple tool to generate fake web browsing and mitigate tracking

anti-botdns-analysisprivacy
2844 years ago
hot-jar-swapping-urlclassloader preview

hot-jar-swapping-urlclassloader

GitHubfransr/hot-jar-swapping-urlclassloader

Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes

educationexploitationpayload-development+1
323 years ago
mtk-su-reverse-cve-2020-0069 preview

mtk-su-reverse-cve-2020-0069

GitHubtherealjunior/mtk-su-reverse-cve-2020-0069

reversing mtk-su

android-securitybinary-exploitationeducation+3
176 years ago
K2-CLI preview

K2-CLI

GitHubodinglyn0/k2-cli

Putting the analysis in steganalysis.

anomaly-detectionctfdigital-forensics+7
128 months ago
CVE-2021-4034 preview

CVE-2021-4034

GitHubal1ex/cve-2021-4034

Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)

binary-exploitationeducationexploitation+2
44 years ago
CVE-2022-35841 preview

CVE-2022-35841

GitHubwack0/cve-2022-35841

small writeup on EnterpriseModernAppManager::ProvisionApplication bug

binary-exploitationeducationexploitation+2
34 years ago
CVE-2026-15282 preview

CVE-2026-15282

GitHubshinthink/cve-2026-15282

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

educationexploitationpayload-generation+5
2 months ago
CVE-2020-8835-verification preview

CVE-2020-8835-verification

GitHubdigamma-ai/cve-2020-8835-verification

Coq-based formal verification of a Linux kernel eBPF verifier vulnerability (CVE-2020-8835) with reproducible build environment and proof artifacts.

educationpapers-researchvulnerability-analysis
25 years ago
log4j2-vulnerable-spring-app preview

log4j2-vulnerable-spring-app

GitHubzzzz0317/log4j2-vulnerable-spring-app

CVE-2021-44228

educationexploitationlabs-practice+3
44 years ago
Previous1…252627Next