Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
CVE-2026-8181-PoC preview

CVE-2026-8181-PoC

GitHubsquamity/cve-2026-8181-poc

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

authenticationdefensive-toolseducation+5
2 months ago
parsedmarc preview

parsedmarc

GitHubdomainaware/parsedmarc

A Python package and CLI for parsing aggregate and forensic DMARC reports

authenticationdefensive-toolsdns-analysis+2
1.3k2 days ago
MFASweep preview

MFASweep

GitHubdafthack/mfasweep

A tool for checking if MFA is enabled on multiple Microsoft Services

authenticationcloud-securitypenetration-testing+2
1.7k5 months ago
KeySniper preview

KeySniper

GitHubynsmroztas/keysniper

**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

authenticationexploitationpenetration-testing+4
1141 month ago
CVE-2023-27350-POC preview

CVE-2023-27350-POC

GitHubimancybersecurity/cve-2023-27350-poc

Proof-of-concept exploit for CVE-2023-27350 targeting authentication bypass in PaperCut MF/NG print management software. Includes Shodan dorks for…

authenticationexploitationreconnaissance+2
121 year ago
Zimbra-Valid-Login-Checker preview

Zimbra-Valid-Login-Checker

GitHubjenderal92/zimbra-valid-login-checker

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

authenticationpassword-attackspenetration-testing+2
14 months ago
CVE-2026-41940-AuthBypass-Detector preview

CVE-2026-41940-AuthBypass-Detector

GitHubunteikyou/cve-2026-41940-authbypass-detector

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

authenticationpenetration-testingreconnaissance+2
15 months ago
CVE-2024-27198-POC preview

CVE-2024-27198-POC

GitHubeynaexp/cve-2024-27198-poc

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

authenticationexploitationpenetration-testing+3
19 months ago
NTLMRecon preview

NTLMRecon

GitHubpwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

authenticationinformation-gatheringnetwork-security+3
5101 year ago
PyADRecon preview

PyADRecon

GitHubl4rm4nd/pyadrecon

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

authenticationinformation-gatheringpenetration-testing+4
682 months ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5619 days ago
CVE-2022-23342 preview

CVE-2022-23342

GitHubinitroot/cve-2022-23342

Proof-of-concept for Active Directory username enumeration vulnerability in Hyland OnBase via login endpoint response differences, enabling…

authenticationinformation-gatheringreconnaissance+2
34 years ago
SQLRecon preview

SQLRecon

GitHubskahwah/sqlrecon

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

authenticationdatabase-securityexploitation+5
8173 months ago
SharpADWS preview

SharpADWS

GitHubwh0amitz/sharpadws

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

authenticationexploitationlateral-movement+6
6052 years ago
Cable preview

Cable

GitHublogangoins/cable

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

authenticationconfiguration-auditingexploitation+8
4011 year ago
wordpress-cve-2024-10924-pentest preview

wordpress-cve-2024-10924-pentest

GitHubademto/wordpress-cve-2024-10924-pentest

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

authenticationeducationexploitation+5
31 year ago
Responder preview

Responder

GitHublgandx/responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

authenticationdns-analysisdns-fuzzing+10
6.6k3 months ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysishash-analysis+6
3.9k1 year ago
Previous12345Next