Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
NTLMRecon preview

NTLMRecon

GitHubpwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

authenticationinformation-gatheringnetwork-security+3
5101 year ago
CVE-2017-14263 preview

CVE-2017-14263

GitHubzzz66686/cve-2017-14263

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

authenticationexploitationiot-security+3
59 years ago
route-detect preview

route-detect

GitHubmschwager/route-detect

Find authentication (authn) and authorization (authz) security bugs in web application routes.

authenticationstatic-analysisvulnerability-analysis+1
2801 year ago
totp-ssh-fluxer preview

totp-ssh-fluxer

GitHubbenjojo/totp-ssh-fluxer

Take security by obscurity to the next level (this is a bad idea, don't really use this please)

authenticationnetwork-securityred-teaming+1
94610 years ago
CentOS-Control-Web-Panel-CVE preview

CentOS-Control-Web-Panel-CVE

GitHubi3umi3iei3ii/centos-control-web-panel-cve

CentOS Control Web Panel, Root Privilege Escalation

authenticationeducationinformation-gathering+3
656 years ago
CVE-2026-PSA-2026-00043-1 preview

CVE-2026-PSA-2026-00043-1

GitHubhorkimhab/cve-2026-psa-2026-00043-1

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

authenticationeducationexploitation+3
27 days ago
cve-2026-34472-auth-bypass-zte-h188a-router preview

cve-2026-34472-auth-bypass-zte-h188a-router

GitHubminanagehsalalma/cve-2026-34472-auth-bypass-zte-h188a-router

Technical breakdown of CVE-2026-34472, an auth bypass via leaked credentials affecting ZTE H188A routers.

authenticationexploitationinformation-gathering+3
14 months ago
silph preview

silph

GitHubalmounah/silph

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

authenticationmemory-forensicspassword-cracking+3
1659 months ago
AzTokenFinder preview

AzTokenFinder

GitHubhackmichnet/aztokenfinder

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

authenticationcloud-securitymemory-forensics+3
1093 years ago
CVE-2025-12135 preview

CVE-2025-12135

GitHubd0n601/cve-2025-12135

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

authenticationcode-analysismisconfiguration+3
11 months ago
ldapnomnom preview

ldapnomnom

GitHublkarlslund/ldapnomnom

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

authenticationinformation-gatheringpassword-attacks+1
1.1k1 year ago
captaincredz preview

captaincredz

GitHubsynacktiv/captaincredz

CaptainCredz is a modular and discreet password-spraying tool.

authenticationidentity-access-managementpassword-attacks+2
1401 month ago
CVE-2025-47812 preview

CVE-2025-47812

GitHubpopyue/cve-2025-47812

RCE for WingFTP v4.7.3

authenticationexploitationpayload-development+3
7 months ago