Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
attestos preview

attestos

GitHubplunder707/attestos

Bazzite plus a TPM boot attestation layer. Work in progress: builds unverified, UKI mechanism unresolved. Spec: github.com/plunder707/attested-gaming

authenticationcryptographydefensive-tools+2
1
13 days ago
OpenSC preview

OpenSC

GitHubx41sec/opensc

OpenSC bugfixing

authenticationcryptographyencryption-decryption-tools+2
18 years ago
Berserko preview

Berserko

GitHubnccgroup/berserko

Burp Suite extension to perform Kerberos authentication

authenticationpenetration-testingweb-proxies-interception+1
1052 years ago
hostap preview

hostap

GitHubjmalinen/hostap

Clone of w1.fi hostap.git - NOTE: This is not the main development location and pull requests for this repository are ignored. See the upstream…

authenticationwi-fi-auditingwireless-security
166 years ago
research preview

research

GitHubalessandrobertoldi/research
authenticationcurated-resourcesdns-subdomain-enumeration+5
3 months ago
ZackAttack preview

ZackAttack

GitHuburbanesec/zackattack

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

authenticationexploitationinformation-gathering+6
26210 years ago
wordpress-really-simple-security-authn-bypass-vulnerable-application preview

wordpress-really-simple-security-authn-bypass-vulnerable-application

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

authenticationexploitationlabs-practice+3
81 year ago
fortios-auth-bypass-check-CVE-2024-55591 preview

fortios-auth-bypass-check-CVE-2024-55591

GitHubwatchtowrlabs/fortios-auth-bypass-check-cve-2024-55591
authenticationexploitationpenetration-testing+3
661 year ago
Pyrescom-Termod-PoC preview

Pyrescom-Termod-PoC

GitHuboutpost24/pyrescom-termod-poc

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

authenticationcommand-and-controlexploitation+5
5 years ago
CVE-2024-32113-POC preview

CVE-2024-32113-POC

GitHubracerz-fighting/cve-2024-32113-poc

Apache OfBiz vulns

authenticationexploitationpayload-generation+3
72 years ago
asf__james-project_CVE-2022-22931_3-6-0 preview

asf__james-project_CVE-2022-22931_3-6-0

GitHubshoucheng3/asf__james-project_cve-2022-22931_3-6-0
authenticationcloud-securityconfiguration-auditing+5
1 year ago
CVE-2024-20674 preview

CVE-2024-20674

GitHubgpotter2/cve-2024-20674
authenticationexploitationnetwork-security+2
11 year ago
CVE-2023-47504-POC preview

CVE-2023-47504-POC

GitHubdavidxbors/cve-2023-47504-poc
authenticationexploitationpenetration-testing+2
12 years ago
CVE-2024-3596-Detector preview

CVE-2024-3596-Detector

GitHubalperenugurlu/cve-2024-3596-detector
authenticationcryptographynetwork-security+3
72 years ago
CVE-2023-46747-RCE preview

CVE-2023-46747-RCE

GitHubw01fh4cker/cve-2023-46747-rce

exploit for f5-big-ip RCE cve-2023-46747

authenticationexploitationpenetration-testing+3
2061 year ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubyucaerin/cve-2026-8181

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

authenticationctfeducation+4
3 months ago
AddUser-SAMR preview

AddUser-SAMR

GitHubricardojoserf/adduser-samr

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

authenticationidentity-access-managementlateral-movement+5
963 days ago
jboss-autopwn-1 preview

jboss-autopwn-1

GitHub1872892142/jboss-autopwn-1

JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation…

authenticationcommand-and-controlexploitation+5
11 years ago
Previous12Next