Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
253 results
CVE-2024-10924-PoC preview

CVE-2024-10924-PoC

GitHubhunt3r850/cve-2024-10924-poc

Proof-of-concept exploit for CVE-2024-10924, an authentication bypass vulnerability in the Really Simple Security WordPress plugin, enabling MFA…

authentication-authorizationexploitationpenetration-testing+2
1 year ago
API-Security-Checklist preview

API-Security-Checklist

GitHubshieldfy/api-security-checklist

Checklist of the most important security countermeasures when designing, testing, and releasing your API

api-securityauthentication-authorizationcurated-resources+4
23.3k2 months ago
xmlsec preview

xmlsec

GitHublsh123/xmlsec

XML Security Library

api-securityauthentication-authorizationcryptography+2
1646h 24m ago
agentsh preview

agentsh

GitHubcanyonroad/agentsh

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

ai-securityauthentication-authorizationcloud-security+7
38918 days ago
kontext-cli preview

kontext-cli

GitHubkontext-security/kontext-cli

Runtime security for AI agents: discover agents, map their permissions, and enforce what they can do.

ai-securityauthentication-authorizationcloud-security+3
2223 days ago
wardgate preview

wardgate

GitHubwardgate/wardgate

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

api-securityauthentication-authorizationcloud-security+8
1367 months ago
MakerChecker preview

MakerChecker

GitHubmakerchecker/makerchecker

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

ai-securityauthentication-authorizationcloud-security+7
542 months ago
database-sentinel preview

database-sentinel

GitHubfarenhytee/database-sentinel

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

ai-securityauthentication-authorizationcloud-security+8
455 months ago
mcp-security-checklist preview

mcp-security-checklist

GitHubhelixar-ai/mcp-security-checklist

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

ai-securityapi-securityauthentication-authorization+5
226 months ago
Password-Strength-Evaluator preview

Password-Strength-Evaluator

GitHubjenderal92/password-strength-evaluator

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

authentication-authorizationdefensive-toolseducation+1
4 months ago
OpenAM preview

OpenAM

GitHubopenidentityplatform/openam

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

api-securityauthentication-authorizationcloud-security+3
8962 days ago
Autorize preview

Autorize

GitHubquitten/autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

api-security-testingauthentication-authorizationpenetration-testing+2
1.2k6 months ago
bulwark preview

bulwark

GitHubsoftrams/bulwark

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

api-securityauthentication-authorizationconfiguration-auditing+3
18710 months ago
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

api-securityapi-security-testingauthentication-authorization+6
1801 year ago
CVE-2026-0073-PoC-Exploit preview

CVE-2026-0073-PoC-Exploit

GitHubtc4dy/cve-2026-0073-poc-exploit

Zero-click authentication bypass exploit for Android ADB Wireless Debugging (CVE-2026-0073). Provides interactive shell, command execution, and…

android-securityauthentication-authorizationeducation+6
148 days ago
scopeblind-gateway preview

scopeblind-gateway

GitHubtomjwxf/scopeblind-gateway

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

ai-securityapi-securityauthentication-authorization+6
105 months ago
wp-secure-mcp preview

wp-secure-mcp

GitHubles-k/wp-secure-mcp

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

ai-securityapi-securityauthentication-authorization+5
10 days ago
zappzarapp-php-security preview

zappzarapp-php-security

GitLabmarcstraube/zappzarapp-php-security

PHP 8.4+ security library (mirror)

api-securityauthentication-authorizationcode-analysis+6
1 month ago
Previous123…15Next