Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
evil-winrm-py preview

evil-winrm-py

GitHubadityatelange/evil-winrm-py

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

authenticationcommand-and-controllateral-movement+7
400
14 days ago
POC-CVE-2026-0073 preview

POC-CVE-2026-0073

GitHubnaheeju/poc-cve-2026-0073

Security research PoC for CVE-2026-0073: ADB authentication bypass verification

android-securityauthenticationexploitation+2
51 month ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
91 month ago
CVE-2026-0073-Android-adbd-authentication-bypass-POC preview

CVE-2026-0073-Android-adbd-authentication-bypass-POC

GitHubsectestannaquinn/cve-2026-0073-android-adbd-authentication-bypass-poc

Proof-of-concept exploit for CVE-2026-0073, an Android ADB authentication bypass allowing network attackers to connect to devices with ADB over TCP…

android-securityauthenticationexploitation+3
845 months ago
CVE-2026-7671 preview

CVE-2026-7671

GitHubcaginkyr/cve-2026-7671

Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.

android-securityauthenticationexploitation+2
25 months ago
CVE-2026-0073-Android-adbd-authentication-bypass preview

CVE-2026-0073-Android-adbd-authentication-bypass

GitHubaye468448-eng/cve-2026-0073-android-adbd-authentication-bypass

PoC for CVE-2026-0073, an Android ADB authentication bypass enabling network attackers to connect to previously paired devices over wireless…

android-securityauthenticationexploitation+3
1 month ago
abdal-lockbox preview

abdal-lockbox

GitLabprof.shafiei/abdal-lockbox

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

android-securityauthenticationcryptography+5
1 month ago
ResetNightmare-impacket preview

ResetNightmare-impacket

GitHubmihat2/resetnightmare-impacket

CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC

authenticationexploitationinformation-gathering+4
121 month ago
MemorizingTrustManager preview

MemorizingTrustManager

GitHubge0rg/memorizingtrustmanager

A "plugin" for Android Java to allow asking the user about SSL certificates

android-securityauthenticationcryptography+3
1813 years ago
CVE-2026-0073 preview

CVE-2026-0073

GitHub0xblackash/cve-2026-0073

CVE-2026-0073

android-securityauthenticationexploitation+3
55 months ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1031 year ago
Aegis preview

Aegis

GitHubbeemdevelopment/aegis

A free, secure and open source app for Android to manage your 2-step verification tokens.

android-securityauthenticationauthentication-authorization+5
13.2k28 days ago
poc-CVE-2026-0073 preview

poc-CVE-2026-0073

GitHubxqi1337/poc-cve-2026-0073

CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC

android-securityauthenticationexploitation+3
13 months ago
CVE-2025-14998 preview

CVE-2025-14998

GitHubktn1990/cve-2025-14998

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

authenticationexploitationpassword-attacks+3
29 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubjenderal92/cve-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

authenticationeducationexploitation+3
4 months ago
Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit preview

Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit

GitHubmostafasoliman/oracle-oam-padding-oracle-cve-2018-2879-exploit

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

authenticationcryptographyexploitation+5
115 years ago
phonepe-sensitive-data-exposure-cve-2025-5154 preview

phonepe-sensitive-data-exposure-cve-2025-5154

GitHubhonestcorrupt/phonepe-sensitive-data-exposure-cve-2025-5154

CVE-2025-5154: Proof-of-concept for unencrypted local storage of authentication tokens, PII, and KYC data in the PhonePe Android app, enabling…

android-securityauthenticationdata-exfiltration+6
11 year ago
CVE-2021-36808 preview

CVE-2021-36808

GitHubctuihu/cve-2021-36808

A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

android-securityauthenticationexploitation+2
4 years ago
Previous123Next