Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
macOS-enterprise-privileges preview

macOS-enterprise-privileges

GitHubsap/macos-enterprise-privileges

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

authentication-authorizationconfiguration-auditingdefensive-tools+2
2.1k
1 day ago
opa preview

opa

GitHubopen-policy-agent/opa

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

api-securityauthenticationauthentication-authorization+10
12.3k1 day ago
warpgate preview

warpgate

GitHubwarp-tech/warpgate

Fully transparent SSH, HTTPS, Kubernetes, database and RDP/VNC bastion/PAM that doesn't need additional client-side software

authentication-authorizationcloud-infrastructure-securitydatabase-security+4
8.0k1 day ago
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k5 days ago
oauth2-proxy preview

oauth2-proxy

GitHuboauth2-proxy/oauth2-proxy

A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.

authenticationauthentication-authorizationcloud-security+4
15.1k9 days ago
wardn preview

wardn

GitHubrohansx/wardn

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

api-securityauthentication-authorizationcloud-security+6
3610 days ago
CVE-2026-102975 preview

CVE-2026-102975

GitHubbombobombone/cve-2026-102975

Sanitized report and local proof-of-concept script for CVE-2026-102975, a MediaWiki RevisionDelete API authorization bypass allowing suppression…

authentication-authorizationexploitationpapers-research+3
10 days ago
CVE-2026-102973 preview

CVE-2026-102973

GitHubbombobombone/cve-2026-102973

Sanitized report and local proof-of-concept script demonstrating the MediaWiki action=emailuser API EmailUserAuthorizeSend hook bypass…

api-securityauthentication-authorizationexploitation+3
10 days ago
bissap preview

bissap

GitHubsynacktiv/bissap

A new open-source tool to quickly audit SAP permissions.

authentication-authorizationconfiguration-auditingdatabase-security+4
917 days ago
cyrus-sasl preview

cyrus-sasl

GitHubcyrusimap/cyrus-sasl

Cyrus SASL API implementation providing client- and server-side authentication and authorization services via pluggable SASL mechanisms per RFC 4422.

authenticationauthentication-authorizationcryptography+3
1601 month ago
CVE-2026-21010-VoIP-SIP-Digest-Authentication-Replay preview

CVE-2026-21010-VoIP-SIP-Digest-Authentication-Replay

GitHubgeorge0papasotiriou/cve-2026-21010-voip-sip-digest-authentication-replay

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

adversarial-attackauthentication-authorizationexploitation+3
2 months ago
CVE-2026-20896 preview

CVE-2026-20896

GitHubeqstlab/cve-2026-20896

Gitea Docker Image Authentication Bypass

authentication-authorizationexploitationvulnerability-analysis+1
12 months ago
Kangaroo preview

Kangaroo

GitHubmonkeysec-sys/kangaroo

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

authentication-authorizationeducationexploitation+3
22 months ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubheltonpojo/cve-2025-32432

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

authentication-authorizationexploitationinformation-gathering+3
2 months ago
fwknop preview

fwknop

GitHubmrash/fwknop

Single Packet Authorization > Port Knocking

authenticationauthentication-authorizationcryptography+3
1.5k4 months ago
public-passwd preview

public-passwd

GitHubst4rburn/public-passwd

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

authenticationauthentication-authorizationbinary-exploitation+5
34 months ago
auth-header-trust-rules preview

auth-header-trust-rules

GitHubbk-security/auth-header-trust-rules

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

authentication-authorizationcode-analysiseducation+3
5 months ago
swicc preview

swicc

GitHubtomasz-lisowski/swicc

A framework for creating smart cards (ICC-based cards with contacts).

authentication-authorizationembedded-systems-securityhardware-security+2
1425 months ago
Previous123Next