Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
130 results
CVE-2021-40113 preview

CVE-2021-40113

GitHubkarammahmad/cve-2021-40113

CVE documentation repository detailing unauthenticated remote vulnerabilities in Cisco Catalyst PON Series Switches ONT, including default credential…

authenticationconfiguration-auditingexploitation+3
3 years ago
asterisk preview

asterisk

GitHubasterisk/asterisk

The official Asterisk Project repository.

authenticationconfiguration-auditingencryption-decryption-tools+1
3.5k1 month ago
WindowsProtocolTestSuites preview

WindowsProtocolTestSuites

GitHubmicrosoft/windowsprotocoltestsuites

⭐⭐ Join us at SNIA SDC for the SMB3 IO Lab (September 28 - October 1, 2026), see upcoming Interoperability Events

authenticationcloud-securityconfiguration-auditing+6
56611 days ago
ipmi preview

ipmi

GitHubzenfish/ipmi

IPMI stuff from DARPA work

authenticationconfiguration-auditinghardware-security+7
7620 days ago
Azure-AD-Password-Checker preview

Azure-AD-Password-Checker

GitHubquahac/azure-ad-password-checker

Azure AD Password Checker

authenticationcloud-securityconfiguration-auditing+3
861 year ago
EIPP preview

EIPP

GitHubsynacktiv/eipp

Entra ID Password Protection Banned Password Lists

authenticationcloud-securityconfiguration-auditing+4
202 years ago
cve-2026-20833-rc4-kerberos preview

cve-2026-20833-rc4-kerberos

GitHubv-jfanca/cve-2026-20833-rc4-kerberos

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

authenticationconfiguration-auditingcryptography+3
36 months ago
CVE-2026-12352 preview

CVE-2026-12352

GitHubnvicloud/cve-2026-12352

Proof-of-concept for CVE-2026-12352, an authentication bypass in Digi PortServer TS that discloses device configuration including plaintext RADIUS…

authenticationconfiguration-auditingexploitation+2
2 months ago
CVE-2022-43959 preview

CVE-2022-43959

GitHubsecware-ru/cve-2022-43959

Bitrix Vulnerability CVE-2022-43959

authenticationconfiguration-auditingmisconfiguration+3
43 years ago
CPanel-Audit-Remediation-Tool preview

CPanel-Audit-Remediation-Tool

GitHubunderh0st/cpanel-audit-remediation-tool

Audit and incident response tool for CVE-2026-41940 vulnerability

authenticationconfiguration-auditingeducation+3
4 months ago
asf__james-project_CVE-2022-22931_3-6-0 preview

asf__james-project_CVE-2022-22931_3-6-0

GitHubshoucheng3/asf__james-project_cve-2022-22931_3-6-0

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

authenticationcloud-securityconfiguration-auditing+5
1 year ago
proftpd-cve-2019-12815 preview

proftpd-cve-2019-12815

GitHublcartey/proftpd-cve-2019-12815

Exploit for CVE-2019-12815 in ProFTPD 1.3.x, a configurable FTP daemon with virtual users, multiple authentication methods, and modular architecture…

authenticationconfiguration-auditingexploitation+3
6 years ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
721 days ago
Session-Persistence-After-Enabling-2FA-CVE-2025-60425 preview

Session-Persistence-After-Enabling-2FA-CVE-2025-60425

GitHubaakashtyal/session-persistence-after-enabling-2fa-cve-2025-60425

Detailed vulnerability report on Nagios Fusion session persistence after enabling 2FA, including CVE-2025-60425, affected versions, mitigation…

authenticationexploitationpenetration-testing+3
10 months ago
wordpress-really-simple-security-authn-bypass-vulnerable-application preview

wordpress-really-simple-security-authn-bypass-vulnerable-application

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

authenticationexploitationlabs-practice+3
81 year ago
NextJS-CVE-2025-29927 preview

NextJS-CVE-2025-29927

GitHubenochgitgamefied/nextjs-cve-2025-29927

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…

authenticationeducationlabs-practice+3
1 year ago
CVE-2022-23342 preview

CVE-2022-23342

GitHubinitroot/cve-2022-23342

Proof-of-concept for Active Directory username enumeration vulnerability in Hyland OnBase via login endpoint response differences, enabling…

authenticationinformation-gatheringreconnaissance+2
34 years ago
Previous1…678Next