Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
lil-pwny preview

lil-pwny

GitHubpapermtn/lil-pwny

Fast offline auditing of Active Directory passwords using Python.

authenticationpassword-crackingvulnerability-analysis
1672 years ago
Seth preview

Seth

GitHubsyss-research/seth

Perform a MitM attack and extract clear text credentials from RDP connections

authenticationeducationexploitation+4
1.5k10 months ago
securitybot preview
Archived

securitybot

GitHubdropbox/securitybot

Distributed alerting for the masses!

authenticationincident-responselog-analysis+2
9897 years ago
CVE-2025-50433 preview

CVE-2025-50433

GitHub0xmandor/cve-2025-50433

Proof of concept for a critical Monnit Cloud account takeover (CVE-2025-50433), exploiting missing token-email validation in password reset and…

authenticationexploitationinformation-gathering+3
10 months ago
CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID preview

CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID

GitHubgeorge0papasotiriou/cve-2026-11116-snmpv3-authentication-bypass-via-default-engineid

Demonstrates CVE-2026-11116 SNMPv3 authentication bypass caused by guessable default EngineIDs, with a Python pysnmp simulation and guidance for…

authenticationeducationexploitation+3
1 month ago
CVE-2025-58434-poc preview

CVE-2025-58434-poc

GitHubkartik2005221/cve-2025-58434-poc

Proof-of-concept exploit for CVE-2025-58434, demonstrating unauthenticated account takeover in Flowise via leaked password reset tokens. Includes…

authenticationeducationexploitation+4
15 months ago
AutoPtT preview

AutoPtT

GitHubricardojoserf/autoptt

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust, Golang, Nim…

authenticationlateral-movementpost-exploitation+1
15524 days ago
Moniker-Link-Lab-Setup preview

Moniker-Link-Lab-Setup

GitHube-m-e-k-a/moniker-link-lab-setup

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

authenticationeducationexploitation+6
6 months ago
magicNetdefs preview

magicNetdefs

GitHubcrisprss/magicnetdefs

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

adversarial-attackauthenticationexploitation+3
514 years ago
iDict preview

iDict

GitHubpr0x13/idict

PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials.

authenticationexploitationpassword-attacks+3
9023 years ago
CVE-2021-3560-Polkit-Privilege-Esclation preview

CVE-2021-3560-Polkit-Privilege-Esclation

GitHubsecnigma/cve-2021-3560-polkit-privilege-esclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

authenticationexploitationpenetration-testing+2
1263 years ago
Invoke-BadSuccessor.ps1 preview

Invoke-BadSuccessor.ps1

GitHubb5null/invoke-badsuccessor.ps1

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

authenticationexploitationpenetration-testing+4
473 months ago
2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424 preview

2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424

GitHubaakashtyal/2fa-bypass-using-a-brute-force-attack-cve-2025-60424

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

authenticationexploitationpassword-attacks+3
111 months ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
28 days ago
CVE-2026-26717 preview

CVE-2026-26717

GitHubrickidevs/cve-2026-26717

Technical write-up of CVE-2026-26717, an HMAC timing attack in OpenFUN Richie LMS webhook authentication, including vulnerable code, impact, and fix…

authenticationcode-analysisexploitation+2
7 months ago
cve-2021-21994_POC preview

cve-2021-21994_POC

GitHubmreza-en/cve-2021-21994_poc

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

authenticationexploitationfuzzing+3
1 month ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubkh4sh3i/cve-2022-23131

Python exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Includes Shodan and FOFA dorks for vulnerable instance discovery.

authenticationexploitationinformation-gathering+3
154 years ago
mfoc preview

mfoc

GitHubnfc-tools/mfoc

Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

authenticationcryptographyhardware-hacking+3
1.4k2 years ago
Previous12345Next