Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
CVE-2026-54121-Certighost preview

CVE-2026-54121-Certighost

GitHubzerodayevil/cve-2026-54121-certighost

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

authenticationexploitationimpersonation-tools+6
83
16 days ago
puppet-os-hardening preview

puppet-os-hardening

GitHubdev-sec/puppet-os-hardening

This puppet module provides numerous security-related configurations, providing all-round base protection.

authenticationcloud-infrastructure-securityconfiguration-auditing+3
29111 days ago
puppet-ssh-hardening preview

puppet-ssh-hardening

GitHubdev-sec/puppet-ssh-hardening

This puppet module provides secure ssh-client and ssh-server configurations.

authenticationcloud-infrastructure-securityconfiguration-auditing+2
602 years ago
parsedmarc preview

parsedmarc

GitHubdomainaware/parsedmarc

A Python package and CLI for parsing aggregate and forensic DMARC reports

authenticationdefensive-toolsdns-analysis+2
1.3k3 days ago
OpenSC.tokend preview

OpenSC.tokend

GitHubopensc/opensc.tokend

Tokend module for OS X with support for all cards supported by OpenSC

authenticationcryptographyhardware-security+1
362 years ago
mobileiron-exploit preview

mobileiron-exploit

GitHubsynacktiv/mobileiron-exploit

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

authenticationauthentication-authorizationexploitation+3
92 years ago
EvilSunCheck preview

EvilSunCheck

GitHubfrompartsunknown/evilsuncheck

This is a little Python script to detect the "EvilSun" vulnerability (CVE-2020-14871) on Solaris systems. The vulnerability is a buffer overflow in…

authenticationexploitationnetwork-security+2
1 year ago
CVE-2026-46376 preview

CVE-2026-46376

GitHubportbuster1337/cve-2026-46376

CVE-2026-46376 - FreePBX Unauthenticated UCP Access via Hard-Coded Credentials

authenticationeducationexploitation+4
4 months ago
CVE-2024-55591 preview

CVE-2024-55591

GitHubvirus-or-not/cve-2024-55591

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to…

authenticationeducationexploitation+3
81 year ago
hiya preview

hiya

GitHub10toothhtoot01/hiya

A fingerprint module, That also adds support of passkeys to linux

authenticationencryption-decryption-toolshardware-security+2
53 months ago
CVE-2022-43959 preview

CVE-2022-43959

GitHubsecware-ru/cve-2022-43959

Bitrix Vulnerability CVE-2022-43959

authenticationconfiguration-auditingmisconfiguration+3
43 years ago
apache__jspwiki_CVE-2019-10078_2-11-0-M3 preview

apache__jspwiki_CVE-2019-10078_2-11-0-M3

GitHubshoucheng3/apache__jspwiki_cve-2019-10078_2-11-0-m3

Exploit module for Apache JSPWiki CVE-2019-10078, enabling security testing of Java-based wiki platforms through targeted vulnerability exploitation…

authenticationcode-analysisexploitation+3
11 months ago
apache__jspwiki_CVE-2019-0225_2-11-0-M2 preview

apache__jspwiki_CVE-2019-0225_2-11-0-M2

GitHubshoucheng3/apache__jspwiki_cve-2019-0225_2-11-0-m2

Exploit module for Apache JSPWiki CVE-2019-0225, enabling remote code execution via crafted requests. Designed for penetration testing and…

authenticationcode-analysisexploitation+3
1 year ago
CVE-2018-13257 preview

CVE-2018-13257

GitHubgluxon/cve-2018-13257

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

authenticationpenetration-testingphishing+3
17 years ago
CVE-2025-3616 preview

CVE-2025-3616

GitHubb4d-53ct0r/cve-2025-3616

Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

authenticationexploit-frameworkspayload-development+3
8 months ago
PaperCut-Authentication_Bypass_and_RCE preview

PaperCut-Authentication_Bypass_and_RCE

GitHubjoaoaugustom/papercut-authentication_bypass_and_rce

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

authenticationeducationexploitation+5
4 months ago
wolfGuard preview

wolfGuard

GitHubwolfssl/wolfguard

FIPS 140-3 compliant VPN kernel module and user tool, drop-in replacement for WireGuard with AES-256-GCM, SHA2-256, and SECP256R1 cryptography for…

authenticationcryptographyencryption-decryption-tools+1
1253 days ago
ssh-tpm-agent preview

ssh-tpm-agent

GitHubfoxboron/ssh-tpm-agent

SSH agent that creates and manages TPM-sealed keys for hardware-bound authentication, supporting key generation, import, wrapping, PIN protection,…

authenticationcloud-securitydevsecops+3
75721 days ago
Previous12Next