Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
738 results
CVE-2023-36899 preview

CVE-2023-36899

GitHubmidisec/cve-2023-36899

Reproduction environment and exploit tool for CVE-2023-36899, demonstrating ASP.NET Framework cookieless session authentication bypass and IIS app…

authentication-authorizationexploitationids-ips-evasion+3
33
3 years ago
OutOfTune preview

OutOfTune

GitHubstra-x/outoftune

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

authentication-authorizationcloud-securityconfiguration-auditing+9
315 months ago
mcp-security-checklist preview

mcp-security-checklist

GitHubhelixar-ai/mcp-security-checklist

Community-maintained security checklist for Model Context Protocol (MCP) deployments. Covers authentication, input validation, prompt injection, tool…

ai-securityapi-securityauthentication-authorization+5
225 months ago
MS14-068 preview

MS14-068

GitHubianxtianxt/ms14-068

Tool for exploiting MS14-068 Kerberos vulnerability to escalate privileges in Windows Active Directory domains.

authentication-authorizationexploitationpenetration-testing+2
226 years ago
Backdooring-ZMM100-FingerPrint-Devices preview

Backdooring-ZMM100-FingerPrint-Devices

GitHub9aylas/backdooring-zmm100-fingerprint-devices

Automated tool for bypassing authentication and deploying backdoors on ZKSoftware ZMM100 fingerprint access control devices via Telnet, with database…

authentication-authorizationdatabase-securityembedded-systems-security+4
167 years ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubkazaf6s/cve-2022-23131

Exploit tool for CVE-2022-23131, an unsafe session storage vulnerability in Zabbix frontend enabling privilege escalation via SAML SSO authentication…

authentication-authorizationexploitationpenetration-testing+3
114 years ago
envsec preview

envsec

GitHubdavidnussio/envsec

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

authentication-authorizationcloud-securitydevsecops+3
154 months ago
azpim preview

azpim

GitHubtapanmeena/azpim

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

authentication-authorizationcloud-infrastructure-securitycloud-security+3
66 months ago
bissap preview

bissap

GitHubsynacktiv/bissap

A new open-source tool to quickly audit SAP permissions.

authentication-authorizationconfiguration-auditingdatabase-security+4
84 months ago
CVE-2026-29000-PoC-Exploit preview

CVE-2026-29000-PoC-Exploit

GitHubtc4dy/cve-2026-29000-poc-exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

authentication-authorizationeducationexploitation+6
32 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubyurahshell/cve-2026-41940

Interactive exploitation tool for CVE-2026-41940, a critical pre-auth authentication bypass in cPanel & WHM via CRLF injection. Designed for…

authentication-authorizationeducationexploitation+3
2 months ago
Shadow-Vault preview

Shadow-Vault

GitHubjenderal92/shadow-vault

Web-based tool for adding shadow users with SHA-512 password hashing and auto-aging detection, featuring multiple write fallback methods for system…

authentication-authorizationemail-securityidentity-access-management+3
3 months ago
CVE-2023-27524 preview

CVE-2023-27524

GitHubsumaiyafathima-code/cve-2023-27524

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

authentication-authorizationexploitationpenetration-testing+2
5 months ago
sudowp-adminer preview

sudowp-adminer

GitHubsudo-wp/sudowp-adminer

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

authentication-authorizationcloud-securitydatabase-security+3
15 months ago
Thank-u-Next preview

Thank-u-Next

GitHubmickhacking/thank-u-next

CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit

authentication-authorizationeducationexploitation+3
1 year ago
hotpot preview

hotpot

GitHubyen223/hotpot

A simple and secure command-line tool for managing TOTP-based two-factor authentication codes.

authenticationauthentication-authorizationencryption-decryption-tools+3
3 months ago
wordpress-bf preview

wordpress-bf

GitHubrandomrobbiebf/wordpress-bf

Python-based WordPress author enumeration and login brute-force tool for penetration testing.

authentication-authorizationinformation-gatheringpassword-attacks+2
6 years ago
CVE-2023-2437 preview

CVE-2023-2437

GitHubrxrcoder/cve-2023-2437

Exploit tool for CVE-2023-2437 targeting UserPro <= 5.1.1 authentication bypass, allowing attackers to gain admin access and create new…

authentication-authorizationexploitationpassword-attacks+3
2 years ago
Previous123…41Next