Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
706 results
CVE-2026-18963 preview

CVE-2026-18963

GitHubalt3kx/cve-2026-18963

Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user…

authenticationexploitationinformation-gathering+4
4
18 days ago
brutus preview

brutus

GitHubpraetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

authenticationexploitationinformation-gathering+7
3249h 19m ago
CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7 preview

CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7

GitHubhuyvo2910/cve-2025-25749-weak-password-policy-in-hoteldruid-3.0.7

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

authenticationeducationpassword-attacks+3
1 year ago
Bash-Script-CVE-2019-17662 preview

Bash-Script-CVE-2019-17662

GitHubkxisxr/bash-script-cve-2019-17662

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication…

authenticationexploitationinformation-gathering+3
14 years ago
CVE-2024-7593 preview

CVE-2024-7593

GitHubrxerium/cve-2024-7593

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

authenticationexploitationpenetration-testing+3
11 months ago
SharpNamedPipePTH preview

SharpNamedPipePTH

GitHubs3cur3th1ssh1t/sharpnamedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+5
3104 years ago
CVE-2019-17240 preview

CVE-2019-17240

GitHubpingport80/cve-2019-17240

This is the exploit of CVE-2019-17240.

authenticationexploitationids-ips-evasion+2
35 years ago
CVE-2025-13390 preview

CVE-2025-13390

GitHubnxploited/cve-2025-13390

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

authenticationexploitationpayload-development+5
18 months ago
CVE-2025-64513 preview

CVE-2025-64513

GitHubshinyseam/cve-2025-64513

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

authenticationdatabase-securityexploitation+3
110 months ago
CVE-2018-13382 preview

CVE-2018-13382

GitHubmilo2012/cve-2018-13382

CVE-2018-13382

authenticationexploitationpenetration-testing+3
1467 years ago
trident preview
Archived

trident

GitHubpraetorian-inc/trident

automated password spraying tool

authenticationcloud-securitypassword-attacks+3
1485 years ago
frevvomapexec preview
Archived

frevvomapexec

GitHubhateshape/frevvomapexec

PoC Exploit for CVE-2018-8820

authenticationexploitationpenetration-testing+2
48 years ago
cve-2026-20833-rc4-kerberos preview

cve-2026-20833-rc4-kerberos

GitHubv-jfanca/cve-2026-20833-rc4-kerberos

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

authenticationconfiguration-auditingcryptography+3
36 months ago
ADCSPwn preview

ADCSPwn

GitHubbats3c/adcspwn

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

authenticationexploitationpenetration-testing+2
8785 years ago
KnockKnock preview
Archived

KnockKnock

GitHuboptiv/knockknock

Enumerate valid users within Microsoft Teams and OneDrive with clean output.

authenticationcloud-securityinformation-gathering+3
621 year ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

authenticationcloud-securitydevsecops+3
5036 months ago
go-secdump preview

go-secdump

GitHubjfjallid/go-secdump

Tool to remotely dump secrets from the Windows registry

authenticationencryption-decryption-toolslateral-movement+4
5372 months ago
PowerPriv preview

PowerPriv

GitHubg0ldengunsec/powerpriv

A Powershell implementation of PrivExchange designed to run under the current user's context

authenticationexploitationlateral-movement+2
1257 years ago
Previous1234…40Next