Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
235 results
CVE-2018-15473-py3 preview

CVE-2018-15473-py3

GitHubdirty-racoon/cve-2018-15473-py3

Python3 exploit for CVE-2018-15473 that enumerates valid usernames on OpenSSH servers via timing-based authentication analysis.

authenticationexploitationpenetration-testing+1
5 years ago
CVE-2024-57610 preview

CVE-2024-57610

GitHubh4ckm3-png/cve-2024-57610

Proof-of-concept demonstrating lack of rate limiting on the Sylius v2.0.2 login endpoint, enabling unrestricted automated authentication attempts.

authenticationpapers-researchpenetration-testing+2
1 year ago
SmartAsset-UE-CVE-2020-26526 preview

SmartAsset-UE-CVE-2020-26526

GitHublukaszstu/smartasset-ue-cve-2020-26526

It is possible to enumerate valid usernames on the login page.

authenticationinformation-gatheringpenetration-testing+2
6 years ago
evil-winrm-py preview

evil-winrm-py

GitHubadityatelange/evil-winrm-py

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

authenticationcommand-and-controllateral-movement+7
40014 days ago
secretive preview

secretive

GitHubmaxgoedjen/secretive

Protect your SSH keys with your Mac's Secure Enclave

authenticationencryption-decryption-toolshardware-security+2
8.9k3 days ago
Rubeus preview

Rubeus

GitHubghostpack/rubeus

Trying to tame the three-headed dog.

authenticationexploitationlateral-movement+6
5.2k10 months ago
pypykatz preview

pypykatz

GitHubskelsec/pypykatz

Mimikatz implementation in pure Python

authenticationdigital-forensicsencryption-decryption-tools+4
3.4k5 months ago
fwknop preview

fwknop

GitHubmrash/fwknop

Single Packet Authorization > Port Knocking

authenticationauthentication-authorizationcryptography+3
1.5k4 months ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3048 years ago
SharpNamedPipePTH preview

SharpNamedPipePTH

GitHubs3cur3th1ssh1t/sharpnamedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+5
3084 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubhorizon3ai/cve-2022-1388

POC for CVE-2022-1388

authenticationeducationexploitation+3
2294 years ago
CVE-2024-4358 preview

CVE-2024-4358

GitHubsinsinology/cve-2024-4358

Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)

authenticationexploitationpayload-development+3
782 years ago
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
171 month ago
CVE-2019-12476 preview

CVE-2019-12476

GitHub0katz/cve-2019-12476

PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted…

authenticationexploitationpenetration-testing+2
436 years ago
CVE-2024-4358 preview

CVE-2024-4358

GitHubverylazytech/cve-2024-4358

Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024

authenticationeducationexploitation+3
131 year ago
CVE-2024-28987 preview

CVE-2024-28987

GitHubhorizon3ai/cve-2024-28987

Proof-of-concept exploit for CVE-2024-28987 targeting SolarWinds Web Help Desk hardcoded credential vulnerability. Automates exploitation via URL…

authenticationexploitationinformation-gathering+3
82 years ago
inetutils-telnetd-auth-bypass preview

inetutils-telnetd-auth-bypass

GitHubleonjza/inetutils-telnetd-auth-bypass

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

authenticationexploitationlabs-practice+2
128 months ago
secure-vault-for-commercial preview

secure-vault-for-commercial

GitHubkeerthivasan-sankar/secure-vault-for-commercial

secure vault for your files

authenticationcryptographydata-recovery+3
313 days ago
Previous1…101112…14Next