Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
82 results
enumerate-iam preview

enumerate-iam

GitHubandresriancho/enumerate-iam

Enumerate the permissions associated with AWS credential set

authentication-authorizationcloud-securityconfiguration-auditing+6
1.3k
2 years ago
jataayu preview

jataayu

GitHubgmh5225/jataayu

LLM-backed AI agent security — inbound injection detection + outbound privacy protection

ai-securityauthentication-authorizationdata-exfiltration+6
2 months ago
phpBB-CVE-2026-48611 preview

phpBB-CVE-2026-48611

GitHubethicalgrey/phpbb-cve-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

authentication-authorizationexploitationinformation-gathering+5
1 month ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
5 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubkernelzeroday/cve-2026-29000

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

authentication-authorizationexploitationpayload-generation+5
97 months ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
21 month ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
1457 days ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
582 months ago
caos-os preview

caos-os

GitHubdigicred-oss/caos-os

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

authentication-authorizationdefensive-toolsinformation-gathering+2
12 months ago
oauth-scan preview

oauth-scan

GitHubportswigger/oauth-scan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

authentication-authorizationconfiguration-auditinginformation-gathering+3
1921 year ago
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

api-securityapi-security-testingauthentication-authorization+6
1811 year ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
5494 years ago
ldeep preview

ldeep

GitHubfranc-pentest/ldeep

In-depth ldap enumeration utility

authentication-authorizationconfiguration-auditingdns-analysis+4
6071 month ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
332 months ago
POC-CVE-2026-56164-exploit preview

POC-CVE-2026-56164-exploit

GitHubsam00/poc-cve-2026-56164-exploit

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…

authentication-authorizationexploitationinformation-gathering+5
22 months ago
CVE-2026-15964-PoC preview

CVE-2026-15964-PoC

GitHubinstructor-admin/cve-2026-15964-poc

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

authentication-authorizationexploitationinformation-gathering+5
12 months ago
CVE-2026-8239 preview

CVE-2026-8239

GitHubaj2108/cve-2026-8239

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

authentication-authorizationeducationinformation-gathering+3
2 months ago
import-users-from-csv-with-meta preview

import-users-from-csv-with-meta

GitHubrandomrobbiebf/import-users-from-csv-with-meta

Import Users From CSV with Meta 1.15 - Unauthorised Authenticated Users Export

authentication-authorizationexploitationinformation-gathering+3
3 years ago
Previous12345Next