Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
299 results
CVE-2026-71518 preview

CVE-2026-71518

GitHubilhomjonr/cve-2026-71518

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

authentication-authorizationexploitationpenetration-testing+3
1
3 days ago
CVE-2025-32433-PoC-Analysis preview

CVE-2025-32433-PoC-Analysis

GitHubliam-worsley/cve-2025-32433-poc-analysis

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

authentication-authorizationeducationexploitation+4
6 days ago
CVE-2026-13610 preview

CVE-2026-13610

GitHubghostpels/cve-2026-13610

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

authentication-authorizationexploitationpenetration-testing+4
5 days ago
CVE-2026-31816 preview

CVE-2026-31816

GitHubk3ystr0k3r/cve-2026-31816

PoC exploit for critical Budibase auth bypass: unanchored webhook regex lets attackers append ?/webhooks/trigger, reach protected APIs, and chain…

api-securityauthentication-authorizationexploitation+3
6 days ago
android-hardware-attestation-demo preview

android-hardware-attestation-demo

GitHubquarkslab/android-hardware-attestation-demo

An Android HW Attestation demo

android-securityauthentication-authorizationeducation+3
3915 days ago
cve-2026-39987 preview

cve-2026-39987

GitHubmatesz44/cve-2026-39987

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

authentication-authorizationexploitationpenetration-testing+2
8 days ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
5210 days ago
checkpoint-smartconsole-poc preview

checkpoint-smartconsole-poc

GitHubhackspeak/checkpoint-smartconsole-poc

CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

authentication-authorizationexploitationpenetration-testing+2
216 days ago
oauth-scan preview

oauth-scan

GitHubportswigger/oauth-scan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

authentication-authorizationconfiguration-auditinginformation-gathering+3
1921 year ago
cs-token-vault preview

cs-token-vault

GitHubhenkru/cs-token-vault

In-memory token vault BOF for Cobalt Strike

authentication-authorizationpenetration-testing-frameworkspost-exploitation+2
1514 years ago
LabS4U2Self preview

LabS4U2Self

GitHubotterhacker/labs4u2self
authentication-authorizationdatabase-securityeducation+5
313 years ago
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

api-securityapi-security-testingauthentication-authorization+6
1781 year ago
swicc preview

swicc

GitHubtomasz-lisowski/swicc

A framework for creating smart cards (ICC-based cards with contacts).

authentication-authorizationembedded-systems-securityhardware-security+2
1423 months ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k5 months ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
5464 years ago
BlockOpenHandle preview

BlockOpenHandle

GitHubsaadahla/blockopenhandle

Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory…

authentication-authorizationdefensive-toolsprivacy
1713 years ago
ldeep preview

ldeep

GitHubfranc-pentest/ldeep

In-depth ldap enumeration utility

authentication-authorizationconfiguration-auditingdns-analysis+4
6011 month ago
FlowAnalyzer preview

FlowAnalyzer

GitHubmanuelberrueta/flowanalyzer

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

api-securityapi-security-testingauthentication-authorization+5
1822 years ago
Previous12…17Next