Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
openvpn preview

openvpn

GitHubopenvpn/openvpn

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

authentication-authorizationcryptographynetwork-security+2
14.6k
1 day ago
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

ai-securityauthentication-authorizationcloud-security+7
8.6k1 day ago
headscale preview

headscale

GitHubjuanfont/headscale

An open source, self-hosted implementation of the Tailscale control server

authentication-authorizationcloud-infrastructure-securityidentity-access-management+2
43.9k2 days ago
cve-2026-41940-PoC-Linux preview

cve-2026-41940-PoC-Linux

GitHubxrzmodz444/cve-2026-41940-poc-linux

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports custom payloads and verbose logging, compatible with…

authentication-authorizationexploitationpenetration-testing+2
7 days ago
reproxy preview

reproxy

GitHubumputun/reproxy

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

api-securityauthentication-authorizationgeneral-purpose-utilities+2
1.3k10 days ago
The Vault by Focused Hunts preview

The Vault by Focused Hunts

GitLabfocused.hunts/the.vault

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

authentication-authorizationcloud-securityencryption-decryption-tools+3
17 days ago
envsec preview

envsec

GitHubdavidnussio/envsec

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

authentication-authorizationcloud-securitydevsecops+3
1617 days ago
ResetNightmare preview

ResetNightmare

GitHubsemperis-community/resetnightmare

POC tool for ResetNightmare (CVE-2026-27912)

authentication-authorizationexploitationpassword-attacks+3
21727 days ago
Kerberos-CVE-2026-27912 preview

Kerberos-CVE-2026-27912

GitHuboxstussz-eng/kerberos-cve-2026-27912

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

authentication-authorizationexploitationpassword-attacks+2
41 month ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
581 month ago
Kangaroo preview

Kangaroo

GitHubmonkeysec-sys/kangaroo

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

authentication-authorizationeducationexploitation+3
21 month ago
HardeningKitty preview

HardeningKitty

GitHubscipag/hardeningkitty

HardeningKitty - Checks and hardens your Windows configuration

authentication-authorizationconfiguration-auditingdefensive-tools+2
1.8k1 month ago
sdk preview

sdk

GitLabcosignet/sdk

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

api-securityauthenticationauthentication-authorization+3
2 months ago
CVE-2026-50338 preview

CVE-2026-50338

GitHubjohanneslks/cve-2026-50338

Proof-of-concept exploit for CVE-2026-50338: cross-issuer authentication bypass in Spring Cloud Azure B2C resource servers. Demonstrates token…

authentication-authorizationeducationexploitation+3
2 months ago
YourMemory preview

YourMemory

GitHubsachitrafa/yourmemory

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

ai-securityauthentication-authorizationforensics+5
2682 months ago
op4 preview

op4

GitHubopfour/op4

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

authenticationauthentication-authorizationcryptography+3
62 months ago
fwknop preview

fwknop

GitHubmrash/fwknop

Single Packet Authorization > Port Knocking

authenticationauthentication-authorizationcryptography+3
1.5k3 months ago
agartha preview

agartha

GitHubvolkandindar/agartha

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

authentication-authorizationpayload-generationpenetration-testing+4
4133 months ago
Previous123Next