Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Identity & Access Management (IAM)

Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

NewestRelevanceMost popularRecently updated
877 results
CVE-2026-71206-PoC preview

CVE-2026-71206-PoC

GitHubnel-droid/cve-2026-71206-poc

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

authentication-authorizationvulnerability-analysisexploitation+3
4 days ago
slater preview

slater

GitHubhikari-systems/slater

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

authentication-authorizationencryption-decryption-toolsnetwork-security+3
1004 days ago
cloudsplaining preview

cloudsplaining

GitHubsalesforce/cloudsplaining

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

cloud-infrastructure-securityvulnerability-analysisconfiguration-auditing+3
2.2k4 days ago
policy_sentry preview

policy_sentry

GitHubsalesforce/policy_sentry

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

cloud-infrastructure-securityconfiguration-auditingcloud-security+2
2.2k4 days ago
symfony preview

symfony

GitHubsymfony/symfony

The Symfony PHP framework

authentication-authorizationgeneral-purpose-utilitiesscripting-automation+3
31.1k5 days ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationosintpenetration-testing-frameworks+8
735 days ago
Claude-Skills-Governance-Risk-and-Compliance preview

Claude-Skills-Governance-Risk-and-Compliance

GitHubsushegaad/claude-skills-governance-risk-and-compliance

Installable Claude Skills providing expert-level compliance guidance for 30+ frameworks including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF,…

vulnerability-analysiscloud-securityprivacy+5
8145 days ago
cve-2026-71362-magento-lab preview

cve-2026-71362-magento-lab

GitHubdinosn/cve-2026-71362-magento-lab

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

authentication-authorizationvulnerability-analysisexploitation+4
15 days ago
jit preview

jit

GitHubjitpass/jit

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

authentication-authorizationencryption-decryption-toolsconfiguration-auditing+3
146 days ago
cottage preview

cottage

GitHubsayanarijit/cottage

A modern git based age-encrypted secrets manager for teams.

authentication-authorizationencryption-decryption-toolsscripting-automation+6
436 days ago
CVE-2026-13610 preview

CVE-2026-13610

GitHubghostpels/cve-2026-13610

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

authentication-authorizationprivilege-escalationvulnerability-analysis+4
6 days ago
CVE-2026-31816 preview

CVE-2026-31816

GitHubk3ystr0k3r/cve-2026-31816

PoC exploit for critical Budibase auth bypass: unanchored webhook regex lets attackers append ?/webhooks/trigger, reach protected APIs, and chain…

authentication-authorizationexploitationweb-application-exploitation+3
6 days ago
CVE-2025-32433-PoC-Analysis preview

CVE-2025-32433-PoC-Analysis

GitHubliam-worsley/cve-2025-32433-poc-analysis

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

authentication-authorizationvulnerability-analysisexploitation+4
6 days ago
libsignal preview

libsignal

GitHubsignalapp/libsignal

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

encryption-decryption-toolsidentity-managementcryptography+2
5.9k6 days ago
Kerberos-CVE-2026-27912 preview

Kerberos-CVE-2026-27912

GitHuboxstussz-eng/kerberos-cve-2026-27912

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

authentication-authorizationprivilege-escalationpassword-attacks+2
6 days ago
heartwood preview

heartwood

GitHubradicle-dev/heartwood

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

authentication-authorizationcode-analysisnetwork-security+2
2576 days ago
squid preview

squid

GitHubsquid-cache/squid

Squid Web Proxy Cache - Source Code

authentication-authorizationgeneral-purpose-utilitiesweb-proxies-interception+3
3.1k6 days ago
cloudflared preview

cloudflared

GitHubcloudflare/cloudflared

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

cloud-infrastructure-securitynetwork-securitycloud-security+3
15.2k6 days ago
Previous1…345…49Next