Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
11 results
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
117
6 years ago
sdk preview

sdk

GitLabcosignet/sdk

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

api-securityauthenticationauthentication-authorization+3
1 month ago
Hybrid Submit preview

Hybrid Submit

GitLabkaysec/hybrid-submit

A script that automatically submits files to Hybrid Analysis (API)

api-securitymalware-analysisscripting-automation
2 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
26 months ago
graphw00f preview

graphw00f

GitHubdolevf/graphw00f

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

api-securityapi-security-testingdynamic-code-analysis+5
8953 months ago
f5-waf-quick-patch-cve-2021-44228 preview

f5-waf-quick-patch-cve-2021-44228

GitHubirgoncalves/f5-waf-quick-patch-cve-2021-44228

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

api-securitycloud-securitydevsecops+3
34 years ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

api-securityauthentication-authorizationcryptography+4
1 month ago
CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover- preview

CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover-

GitHubgeorge0papasotiriou/cve-2026-3456-oauth2-pkce-race-condition-account-takeover-

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

api-securityauthentication-authorizationexploitation+3
1 month ago
CVE-2026-11102-OAuth2-Implicit-Grant-Fragment-Hijacking preview

CVE-2026-11102-OAuth2-Implicit-Grant-Fragment-Hijacking

GitHubgeorge0papasotiriou/cve-2026-11102-oauth2-implicit-grant-fragment-hijacking

Proof-of-concept exploit for CVE-2026-11102 demonstrating OAuth2 implicit grant fragment hijacking via unvalidated redirect_uri, leading to access…

api-securityauthentication-authorizationexploitation+3
1 month ago
CVE-2026-21003-JWT-none-Algorithm-Bypass-via-kid-Header-Omission preview

CVE-2026-21003-JWT-none-Algorithm-Bypass-via-kid-Header-Omission

GitHubgeorge0papasotiriou/cve-2026-21003-jwt-none-algorithm-bypass-via-kid-header-omission

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

adversarial-attackapi-securityauthentication-authorization+4
1 month ago
CVE-2026-18953 preview

CVE-2026-18953

GitHubronamosa/cve-2026-18953

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

api-securityexploitationpenetration-testing+1
26 days ago