Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
EasyTokens preview

EasyTokens

GitHubsecdev02/easytokens

Kali365 - EvilTokens Replica

adversarial-attackauthenticationcloud-security+7
722 months ago
PENTEST-LAB preview

PENTEST-LAB

GitHubpannagkumaar/pentest-lab

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

ai-securityapi-securityauthentication+8
2 months ago
pocKeycloakCVE-2023-0264 preview

pocKeycloakCVE-2023-0264

GitHubeliangonzi00/pockeycloakcve-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

authenticationdefensive-toolsexploitation+7
1 month ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
2 months ago
CVE-2025-58434-AND-59528-POC preview

CVE-2025-58434-AND-59528-POC

GitHubkartik2005221/cve-2025-58434-and-59528-poc

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

authenticationeducationexploitation+5
185 months ago
CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001 preview

CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001

GitHubninjazan420/cve-2025-52691-poc-smartermail-authentication-bypass-exploit-wt-2026-0001

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

authenticationexploitationpenetration-testing+4
8 months ago
ADCollector preview

ADCollector

GitHubdev-2null/adcollector

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

authenticationconfiguration-auditinginformation-gathering+4
63511 months ago
BARK preview

BARK

GitHubbloodhoundad/bark

BloodHound Attack Research Kit

authenticationcloud-securityexploitation+6
6091 year ago
Go365 preview

Go365

GitHuboptiv/go365

An Office365 User Attack Tool

authenticationinformation-gatheringpassword-attacks+1
6504 years ago
ridenum preview

ridenum

GitHubtrustedsec/ridenum

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

authenticationinformation-gatheringnetwork-security+3
3186 years ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubakash7350/cve-2020-1472

Python exploit that tests domain controllers for Zerologon (CVE-2020-1472) and resets the vulnerable machine account password through Netlogon…

authenticationexploitationnetwork-security+2
23 years ago
EntraGoat preview

EntraGoat

GitHubsemperis/entragoat

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

authenticationcloud-securityctf+7
9844 months ago
RiskySPN preview

RiskySPN

GitHubcyberark/riskyspn

Detect and abuse risky SPNs

authenticationpassword-crackingpenetration-testing+2
2669 years ago
ketshash preview

ketshash

GitHubcyberark/ketshash

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

authenticationdefensive-toolsincident-response+3
1681 year ago
ADCSync preview

ADCSync

GitHubjpg0mez/adcsync

Use ESC1 to perform a makeshift DCSync and dump hashes

authenticationexploitationpassword-cracking+1
2132 years ago
CVE-2026-25050 preview

CVE-2026-25050

GitHubchristbowel/cve-2026-25050

Proof-of-concept exploit for CVE-2026-25050, a timing attack enabling user enumeration via GraphQL authentication. Measures response times to…

authenticationexploitationinformation-gathering+2
27 months ago
bitlocker-hardening preview

bitlocker-hardening

GitHubandrei-majer/bitlocker-hardening

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

authenticationconfiguration-auditingdefensive-tools+5
54 months ago
MicroTrick preview

MicroTrick

GitHubdigiprosec/microtrick

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

authenticationembedded-systems-securityexploitation+7
1 day ago
Previous12345Next