Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1292 results
chef-ssh-hardening preview

chef-ssh-hardening

GitHubdev-sec/chef-ssh-hardening

This chef cookbook provides secure ssh-client and ssh-server configurations.

authenticationcloud-infrastructure-securityconfiguration-auditing+2
168
12 days ago
cve-2018-10933 preview

cve-2018-10933

GitHubhackerhouse-opensource/cve-2018-10933

Docker-based CVE-2018-10933 libssh authentication bypass exploit with patched client for testing SSH server vulnerabilities and unauthorized access…

authenticationcontainer-securityexploitation+3
1107 months ago
TokenFlare preview

TokenFlare

GitHubjumpseclabs/tokenflare

Serverless AITM Simulation Framework for Entra ID and M365

authenticationcloud-securitycommand-and-control+6
2438 months ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

authenticationcloud-securitydevsecops+3
5026 months ago
signal-without-smartphone preview

signal-without-smartphone

GitHubalmet/signal-without-smartphone

Desktop application to register a Signal account and link Signal Desktop without requiring a smartphone, using Signal's cryptographic protocols for…

authenticationencryption-decryption-toolsmobile-security+2
761 month ago
PyADRecon preview

PyADRecon

GitHubl4rm4nd/pyadrecon

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

authenticationinformation-gatheringpenetration-testing+4
671 month ago
OpenClawMachines preview

OpenClawMachines

GitHubmathaix/openclawmachines

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

ai-securityauthenticationcloud-security+6
571 month ago
linux-fingerprint-r503 preview

linux-fingerprint-r503

GitHubmatpb/linux-fingerprint-r503

Linux desktop fingerprint login using a Grow R503 sensor + Arduino + a Rust fprintd-replacement daemon

authenticationcryptographyembedded-systems-security+3
452 months ago
Klip preview

Klip

GitHubvid4l-07/klip

Minimal terminal-based password manager

authenticationcryptographyencryption-decryption-tools+3
301 month ago
agent-vault-proxy preview

agent-vault-proxy

GitHubinflightsec/agent-vault-proxy

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

ai-securityapi-securityauthentication+3
281 day ago
ft9201-libfprint preview

ft9201-libfprint

GitHubomgrant/ft9201-libfprint

Linux libfprint driver for the Focal-systems FT9201 (2808:93a9) USB fingerprint reader — runs FocalTech's own Windows matching engine natively on…

authenticationbinary-analysisembedded-systems-security+4
241 month ago
agensic preview

agensic

GitHubalex188dot/agensic

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

ai-securityauthenticationdigital-forensics+5
2929 days ago
INSTA_CYBER preview

INSTA_CYBER

GitHubsabir555s/insta_cyber

INSTA_CYBER is a Python-powered ethical hacking tool designed for educational and research purposes. Built by Muhammad Sabir Ali (INNO_CYBER), this…

authenticationpassword-attackspassword-cracking+3
151 year ago
op4 preview

op4

GitHubopfour/op4

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

authenticationauthentication-authorizationcryptography+3
62 months ago
vcsa-hardening-tool preview

vcsa-hardening-tool

GitHubmandiant/vcsa-hardening-tool

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

authenticationcloud-infrastructure-securityconfiguration-auditing+9
135 months ago
webauthn_tpm_portable preview

webauthn_tpm_portable

GitHubmimi89999/webauthn_tpm_portable

Portable, hardware-backed WebAuthn credentials using TPM 2.0. Deterministic parent key derived from a master seed enables cross-device credential…

authenticationcryptographyencryption-decryption-tools+2
45 months ago
CVE-2025-5777-TrendMicro-ApexCentral-RCE preview

CVE-2025-5777-TrendMicro-ApexCentral-RCE

GitHubshivshantp/cve-2025-5777-trendmicro-apexcentral-rce

PoC for CVE-2025-5777 – Auth Bypass and RCE in Trend Micro Apex Central

authenticationcommand-and-controlexploitation+5
51 year ago
CVE-2024-10924-Bypass-MFA-Wordpress-LAB preview

CVE-2024-10924-Bypass-MFA-Wordpress-LAB

GitHubd1se0/cve-2024-10924-bypass-mfa-wordpress-lab

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

authenticationctfeducation+5
41 year ago
Previous1…567…72Next