Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
133 results
openclaw-dashboard preview

openclaw-dashboard

GitHubtugcantopaloglu/openclaw-dashboard

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

api-securityauthenticationcloud-security+7
699
5 months ago
ipmi preview

ipmi

GitHubzenfish/ipmi

IPMI stuff from DARPA work

authenticationconfiguration-auditinghardware-security+7
753 years ago
Azure-AD-Password-Checker preview

Azure-AD-Password-Checker

GitHubquahac/azure-ad-password-checker

Azure AD Password Checker

authenticationcloud-securityconfiguration-auditing+3
861 year ago
EIPP preview

EIPP

GitHubsynacktiv/eipp

Entra ID Password Protection Banned Password Lists

authenticationcloud-securityconfiguration-auditing+4
202 years ago
CVE-2022-43959 preview

CVE-2022-43959

GitHubsecware-ru/cve-2022-43959

Bitrix Vulnerability CVE-2022-43959

authenticationconfiguration-auditingmisconfiguration+3
43 years ago
asf__james-project_CVE-2022-22931_3-6-0 preview

asf__james-project_CVE-2022-22931_3-6-0

GitHubshoucheng3/asf__james-project_cve-2022-22931_3-6-0

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

authenticationcloud-securityconfiguration-auditing+5
1 year ago
proftpd-cve-2019-12815 preview

proftpd-cve-2019-12815

GitHublcartey/proftpd-cve-2019-12815

Exploit for CVE-2019-12815 in ProFTPD 1.3.x, a configurable FTP daemon with virtual users, multiple authentication methods, and modular architecture…

authenticationconfiguration-auditingexploitation+3
6 years ago
cve-2026-20833-rc4-kerberos preview

cve-2026-20833-rc4-kerberos

GitHubv-jfanca/cve-2026-20833-rc4-kerberos

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

authenticationconfiguration-auditingcryptography+3
35 months ago
CPanel-Audit-Remediation-Tool preview

CPanel-Audit-Remediation-Tool

GitHubunderh0st/cpanel-audit-remediation-tool

Audit and incident response tool for CVE-2026-41940 vulnerability

authenticationconfiguration-auditingeducation+3
3 months ago
CVE-2026-12352 preview

CVE-2026-12352

GitHubnvicloud/cve-2026-12352

Proof-of-concept for CVE-2026-12352, an authentication bypass in Digi PortServer TS that discloses device configuration including plaintext RADIUS…

authenticationconfiguration-auditingexploitation+2
1 month ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.0k2 days ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
desktop-2fa preview

desktop-2fa

GitHubwrogistefan/desktop-2fa

A secure offline desktop application for generating and managing TOTP 2FA codes. Features encrypted vault storage, modern cryptography (Argon2 +…

authenticationcryptographyencryption-decryption-tools+2
307 months ago
wordpress-really-simple-security-authn-bypass-vulnerable-application preview

wordpress-really-simple-security-authn-bypass-vulnerable-application

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

authenticationexploitationlabs-practice+3
81 year ago
NextJS-CVE-2025-29927 preview

NextJS-CVE-2025-29927

GitHubenochgitgamefied/nextjs-cve-2025-29927

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…

authenticationeducationlabs-practice+3
7 months ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
34 days ago
op4 preview

op4

GitHubopfour/op4

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

authenticationauthentication-authorizationcryptography+3
61 month ago
nextjs-vulnerable-app preview

nextjs-vulnerable-app

GitHubstrobes-security/nextjs-vulnerable-app

CVE-2025-29927 lab

authenticationeducationlabs-practice+3
61 year ago
Previous1…678Next