Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
44 results
web2py-e94946d-CVE-2016-3957 preview

web2py-e94946d-CVE-2016-3957

GitHubsj/web2py-e94946d-cve-2016-3957

web2py/web2py @ e94946d

authenticationcode-analysisdatabase-security+3
7 years ago
about-hmac preview

about-hmac

GitHubpassword123456/about-hmac

HMAC Implementation Example and Explanation

api-securityauthenticationcryptography+1
22 years ago
CVE-2026-73311 preview

CVE-2026-73311

GitHubbombobombone/cve-2026-73311

Proof-of-concept exploit demonstrating OAuth2 authorization code reuse in XenForo before 2.3.13, allowing token replay and multiple token families.

authenticationexploitationvulnerability-analysis+2
24 days ago
CVE-2026-4282-Scanner preview

CVE-2026-4282-Scanner

GitHubhex0user/cve-2026-4282-scanner

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

authenticationdefensive-toolsinformation-gathering+4
31 month ago
CP-PLUS-EZ-P21-CVE-2026-65893-65894 preview

CP-PLUS-EZ-P21-CVE-2026-65893-65894

GitHubcybervinner/cp-plus-ez-p21-cve-2026-65893-65894

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

authenticationeducationembedded-systems-security+5
2 months ago
PowerPriv preview

PowerPriv

GitHubg0ldengunsec/powerpriv

A Powershell implementation of PrivExchange designed to run under the current user's context

authenticationexploitationlateral-movement+2
1257 years ago
JWTweak preview

JWTweak

GitHubrishuranjanofficial/jwtweak

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

authenticationcryptographypayload-generation+3
1032 months ago
auth preview

auth

GitHubsupabase/auth

A JWT based API for managing users and issuing JWT tokens

authenticationauthentication-authorizationidentity-access-management+1
2.6k10 days ago
pentest-guide preview

pentest-guide

GitHubvoorivex/pentest-guide

Penetration tests guide based on OWASP including test cases, resources and examples.

authenticationcryptographyeducation+6
2.8k5 years ago
ad-ldap-enum preview

ad-ldap-enum

GitHubcrowecybersecurity/ad-ldap-enum

An LDAP based Active Directory user and group enumeration tool

authenticationinformation-gatheringpenetration-testing+1
3125 months ago
CVE-2022-33679 preview

CVE-2022-33679

GitHubbdenneu/cve-2022-33679

One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html

authenticationcryptographyexploitation+2
4151 year ago
ketshash preview

ketshash

GitHubcyberark/ketshash

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

authenticationdefensive-toolsincident-response+3
1681 year ago
knocker preview

knocker

GitHubfariszr/knocker

Knocker, a knock based access control service for your homelab

api-securityauthenticationcloud-security+2
1361 month ago
mscache preview

mscache

GitHubqax-a-team/mscache

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

authenticationpassword-crackingpost-exploitation
678 years ago
ShuckNT preview

ShuckNT

GitHubyanncam/shucknt

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

authenticationcryptographyhash-analysis+3
781 year ago
BloodHound.py-Kerberos preview

BloodHound.py-Kerberos

GitHubjazzpizazz/bloodhound.py-kerberos

A Python based ingestor for BloodHound

authenticationinformation-gatheringpenetration-testing+2
864 years ago
PaperCut-Authentication_Bypass_and_RCE preview

PaperCut-Authentication_Bypass_and_RCE

GitHubjoaoaugustom/papercut-authentication_bypass_and_rce

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

authenticationeducationexploitation+5
4 months ago
CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001 preview

CVE-2025-52691-PoC-SmarterMail-authentication-bypass-exploit-WT-2026-0001

GitHubninjazan420/cve-2025-52691-poc-smartermail-authentication-bypass-exploit-wt-2026-0001

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

authenticationexploitationpenetration-testing+4
8 months ago
Previous123Next