Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
706 results
cpanel-cve-2026-41940-ioc preview

cpanel-cve-2026-41940-ioc

GitHubandrei-dr/cpanel-cve-2026-41940-ioc

CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

authenticationdefensive-toolsincident-response+3
4
4 months ago
cve-2025-24054-lab preview

cve-2025-24054-lab

GitHubt0tooro/cve-2025-24054-lab

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

authenticationconfiguration-auditingeducation+7
2 months ago
attestos preview

attestos

GitHubplunder707/attestos

Bazzite plus a TPM boot attestation layer. Work in progress: builds unverified, UKI mechanism unresolved. Spec: github.com/plunder707/attested-gaming

authenticationcryptographydefensive-tools+2
11 month ago
OpenSSL-1_0_1g_CVE-2015-3194 preview

OpenSSL-1_0_1g_CVE-2015-3194

GitHubtrinadh465/openssl-1_0_1g_cve-2015-3194

OpenSSL 1.0.1g source code snapshot, providing SSL/TLS and general-purpose cryptographic library with ciphers, digests, and X.509 certificate…

authenticationcode-analysiscryptography+3
12 years ago
CVE-2022-2466---Request-Context-not-terminated-with-GraphQL preview

CVE-2022-2466---Request-Context-not-terminated-with-GraphQL

GitHubyuxblank/cve-2022-2466---request-context-not-terminated-with-graphql

Proof-of-concept for CVE-2022-2466 demonstrating unauthenticated GraphQL request context termination in Quarkus/SmallRye, bypassing authorization…

api-securityauthenticationpenetration-testing+2
14 years ago
OpenSSL_1_0_1g_CVE-2015-0205 preview

OpenSSL_1_0_1g_CVE-2015-0205

GitHubsaurabh2088/openssl_1_0_1g_cve-2015-0205

Full-featured open-source toolkit implementing SSL/TLS protocols and a general-purpose cryptography library, including ciphers, digests, public key…

authenticationcode-analysiscryptography+3
2 years ago
OpenSSL-1_0_1g_CVE-2015-1790 preview

OpenSSL-1_0_1g_CVE-2015-1790

GitHubtrinadh465/openssl-1_0_1g_cve-2015-1790

OpenSSL toolkit implementing SSL/TLS protocols and a general-purpose cryptography library with ciphers, digests, public key algorithms, and X.509…

authenticationcode-analysiscryptography+3
2 years ago
Openssl_G2.5_CVE-2014-8275 preview

Openssl_G2.5_CVE-2014-8275

GitHubuthrasri/openssl_g2.5_cve-2014-8275

General-purpose cryptography library and SSL/TLS toolkit implementing ciphers, digests, public key algorithms, and X.509 certificates for secure…

authenticationcryptographydigital-forensics+3
2 years ago
openssl-1.1.1g_CVE-2021-23840 preview

openssl-1.1.1g_CVE-2021-23840

GitHubtrinadh465/openssl-1.1.1g_cve-2021-23840

OpenSSL toolkit providing TLS/SSL protocols and general-purpose cryptographic library with command-line tools for key generation, certificate…

authenticationcode-analysiscryptography+3
3 years ago
openssl-1.1.1g_CVE-2022-0778 preview

openssl-1.1.1g_CVE-2022-0778

GitHubtrinadh465/openssl-1.1.1g_cve-2022-0778

OpenSSL 1.1.1g source snapshot, a robust TLS/SSL and general-purpose cryptographic library with command-line tools for key generation, certificate…

authenticationcode-analysiscryptography+3
3 years ago
external_boringssl_openssl_1.1.0g_CVE-2021-23841 preview

external_boringssl_openssl_1.1.0g_CVE-2021-23841

GitHubtrinadh465/external_boringssl_openssl_1.1.0g_cve-2021-23841

OpenSSL 1.1.0g cryptographic library and TLS toolkit, providing encryption, decryption, certificate management, and SSL/TLS protocol support for…

authenticationcode-analysiscryptography+3
4 years ago
CVE-2024-10449-patch preview

CVE-2024-10449-patch

GitHubg-u-i-d/cve-2024-10449-patch

Patch for CVE-2024-10449: replaces vulnerable loginAction.php with a hardened version that requires database configuration for secure authentication.

authenticationcode-analysismisconfiguration+2
1 year ago
TATS preview

TATS

GitHubicemoonhsv/tats

Analyze and track OAuth 2.0, OIDC, and Microsoft Entra ID tokens from Burp, mitmproxy, or Chrome DevTools captures. Visualize token lifecycles,…

authenticationidentity-access-managementlog-analysis+2
720 days ago
c-jwt-cracker preview

c-jwt-cracker

GitHubbrendan-rius/c-jwt-cracker

JWT brute force cracker written in C

authenticationpassword-crackingpenetration-testing+1
2.6k5 years ago
EntraGoat preview

EntraGoat

GitHubsemperis/entragoat

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

authenticationcloud-securityctf+7
9824 months ago
jwt-cracker preview

jwt-cracker

GitHublmammino/jwt-cracker

Simple HS256, HS384 & HS512 JWT token brute force cracker.

authenticationpassword-crackingweb-security
1.2k2 years ago
JWT_Brute preview

JWT_Brute

GitHubjas502n/jwt_brute

JWT_Brute

authenticationpassword-crackingpenetration-testing+1
316 years ago
CVE-2026-48558 preview

CVE-2026-48558

GitHubj4ck3lsyn-gen2/cve-2026-48558

SimpleHelp OIDC Authentication Bypass PoC

authenticationeducationexploitation+3
72 months ago
Previous1…363738…40Next