Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1292 results
CVE-2023-27100 preview

CVE-2023-27100

GitHubfabdotnet/cve-2023-27100

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via crafted X-Forwarded-For headers and anti-CSRF tokens to evade sshguard…

authenticationexploitationids-ips-evasion+3
2 years ago
CVE-2023-46449 preview

CVE-2023-46449

GitHubsajaljat/cve-2023-46449

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…

authenticationeducationmisconfiguration+3
2 years ago
CVE-2021-3560-Polkit-Privilege-Esclation preview

CVE-2021-3560-Polkit-Privilege-Esclation

GitHubsecnigma/cve-2021-3560-polkit-privilege-esclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

authenticationexploitationpenetration-testing+2
1263 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHub0xf3d0rq/cve-2017-7921

CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems…

authenticationexploitationinformation-gathering+3
19 months ago
wolfGuard preview

wolfGuard

GitHubwolfssl/wolfguard

FIPS 140-3 compliant VPN kernel module and user tool, drop-in replacement for WireGuard with AES-256-GCM, SHA2-256, and SECP256R1 cryptography for…

authenticationcryptographyencryption-decryption-tools+1
12411 days ago
Openbsd-Privilege-Escalation preview

Openbsd-Privilege-Escalation

GitHubretrymp3/openbsd-privilege-escalation

Script that automates the process of escalating privileges on openbsd system (CVE-2019-19520) by exploiting the xlock binary and againing it's sgid…

authenticationexploitationpenetration-testing+2
21 year ago
watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260 preview

watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260

GitHubwatchtowrlabs/watchtowr-vs-bmc-footprints-rce-cve-2025-71257-cve-2025-71260

Detection artifact generator that verifies BMC FootPrints instances for pre-authenticated RCE chain (CVE-2025-71257, CVE-2025-71260) by bypassing…

authenticationexploitationpenetration-testing+3
26 months ago
CVE-2026-10243-AUTH preview

CVE-2026-10243-AUTH

GitHubxmyronn/cve-2026-10243-auth

Proof of concept demonstrating unauthenticated access to critical admin functions in Smart Parking System 1.0, allowing account creation, data…

authenticationexploitationpenetration-testing+2
4 months ago
SYNwall preview

SYNwall

GitHubsynwall/synwall

Linux kernel module implementing a zero-configuration, OTP-based firewall for IoT devices. Transparently authenticates network traffic using a…

authenticationembedded-systems-securityiot-security+1
2614 months ago
cacti-cve-2022-46169-exploit preview

cacti-cve-2022-46169-exploit

GitHubariyaadinatha/cacti-cve-2022-46169-exploit

This is poc of CVE-2022-46169 authentication bypass and remote code execution

authenticationeducationexploitation+3
153 years ago
lsarelayx preview

lsarelayx

GitHubccob/lsarelayx

System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

authenticationexploitationpassword-attacks+2
5864 years ago
hiya preview

hiya

GitHub10toothhtoot01/hiya

A fingerprint module, That also adds support of passkeys to linux

authenticationencryption-decryption-toolshardware-security+2
52 months ago
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
4 months ago
sklad preview

sklad

GitHubrench321/sklad

Industrial-grade secure snippet warehouse for your system tray. 📦 Built with Rust (Tauri v2) & React. Offline-first, AES-256 encrypted, and…

authenticationencryption-decryption-toolsgeneral-purpose-utilities+3
1741 month ago
CVE-2020-29667 preview

CVE-2020-29667

GitHubjet-pentest/cve-2020-29667

Proof-of-concept exploit for CVE-2020-29667 targeting insufficient session expiration and a hardcoded cookie value in Lan ATMService M3 ATM…

authenticationexploitationpenetration-testing+2
5 years ago
keepassxc preview

keepassxc

GitHubkeepassxreboot/keepassxc

Secure offline storage of credentials with encrypted vaults, password generator, TOTP, YubiKey/OnlyKey support, browser integration, and CLI.

authenticationcryptographyencryption-decryption-tools+1
28.7k6 days ago
DavRelayUp preview

DavRelayUp

GitHubdec0ne/davrelayup

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

authenticationexploitationlateral-movement+2
5783 years ago
OWASP-WSTG-Rag preview

OWASP-WSTG-Rag

GitHubzilbonn/owasp-wstg-rag

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

ai-securityapi-security-testingauthentication+8
229 months ago
Previous1…345…72Next