Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
707 results
NfSpy preview

NfSpy

GitHubbonsaiviking/nfspy

ID-spoofing NFS client

authenticationexploitationinformation-gathering+4
3006 years ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubkh4sh3i/cve-2022-23131

Python exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Includes Shodan and FOFA dorks for vulnerable instance discovery.

authenticationexploitationinformation-gathering+3
154 years ago
CVE-2023-2732 preview

CVE-2023-2732

GitHubap0dexme0/cve-2023-2732

Perform With Massive Authentication Bypass (Wordpress Mstore-API)

authenticationeducationpenetration-testing+2
23 years ago
CVE-2026-75431_PowerJob_jwt_key_predictable preview

CVE-2026-75431_PowerJob_jwt_key_predictable

GitHubunpredictable21/cve-2026-75431_powerjob_jwt_key_predictable

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

authenticationexploitationpenetration-testing+2
1 month ago
apache__mina-sshd_CVE-2023-35887_2-9-2 preview

apache__mina-sshd_CVE-2023-35887_2-9-2

GitHubshoucheng3/apache__mina-sshd_cve-2023-35887_2-9-2

Pure Java SSH client/server library implementing SSH-2 protocol with support for multiple ciphers, key exchanges, authentication methods, SFTP, SCP,…

authenticationcryptographyencryption-decryption-tools+5
1 year ago
Pyrescom-Termod-PoC preview

Pyrescom-Termod-PoC

GitHuboutpost24/pyrescom-termod-poc

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

authenticationcommand-and-controlexploitation+5
5 years ago
ator preview

ator

GitHubportswigger/ator

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

api-security-testingauthenticationpenetration-testing+1
382 years ago
CVE-2022-29593 preview

CVE-2022-29593

GitHub9lyph/cve-2022-29593

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

authenticationexploitationfuzzing+8
81 year ago
CVE-2026-15469 preview

CVE-2026-15469

GitHubtony102741/cve-2026-15469

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

authenticationcryptographyexploitation+5
221 days ago
CVE-2025-12720 preview

CVE-2025-12720

GitHubd0n601/cve-2025-12720

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

api-security-testingauthenticationexploitation+3
10 months ago
raider preview
Archived

raider

GitHubdigeex/raider

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

api-security-testingauthenticationpenetration-testing+1
1395 years ago
HuntCyberArk preview

HuntCyberArk

GitHublogisek/huntcyberark

CyberArk Security Audit

api-security-testingauthenticationcloud-security+7
257 months ago
OWASP-WSTG-Rag preview

OWASP-WSTG-Rag

GitHubzilbonn/owasp-wstg-rag

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

ai-securityapi-security-testingauthentication+8
229 months ago
CVE-2026-35616-check preview

CVE-2026-35616-check

GitHubbishopfox/cve-2026-35616-check

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

api-security-testingauthenticationexploitation+3
25 months ago
CVE-2025-67159 preview

CVE-2025-67159

GitHubremenis/cve-2025-67159

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

authenticationexploitationhardware-iot-security+3
8 months ago
shimit preview

shimit

GitHubcyberark/shimit

A tool that implements the Golden SAML attack

authenticationcloud-securityexploitation+2
3468 years ago
AzureRedOps preview

AzureRedOps

GitHubmr-un1k0d3r/azureredops

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

authenticationcloud-securityexploitation+8
1842 months ago
CrackMapExecWin preview

CrackMapExecWin

GitHubmaaaaz/crackmapexecwin

The great CrackMapExec tool compiled for Windows

authenticationinformation-gatheringlateral-movement+4
26710 years ago
Previous1…91011…40Next