Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
334 results
Password-Strength-Evaluator preview

Password-Strength-Evaluator

GitHubjenderal92/password-strength-evaluator

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

authentication-authorizationdefensive-toolseducation+1
3 months ago
wordpress-bf preview

wordpress-bf

GitHubrandomrobbiebf/wordpress-bf

Brute Force Wordpress Blogs.

authentication-authorizationinformation-gatheringpassword-attacks+2
6 years ago
unshackle preview
Archived

unshackle

GitHubfadi002/unshackle

Open-source tool to bypass windows and linux passwords from bootable usb

authentication-authorizationeducationpassword-attacks+3
2.0k2 years ago
heartwood preview

heartwood

GitHubradicle-dev/heartwood

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

authentication-authorizationcode-analysisnetwork-security+2
2665 days ago
CVE-2026-10580 preview

CVE-2026-10580

GitHub0xgh057r3c0n/cve-2026-10580

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

authentication-authorizationeducationexploitation+4
2 months ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.9k20 days ago
CVE-2026-8347 preview

CVE-2026-8347

GitHubaj2108/cve-2026-8347

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0…

authentication-authorizationvulnerability-analysisweb-application-exploitation+1
1 month ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubjayngng/cve-2021-22911

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

authentication-authorizationexploitationpassword-attacks+2
4 years ago
kanidm preview

kanidm

GitHubkanidm/kanidm

Self-hosted identity management platform providing WebAuthn passkeys, OAuth2/OIDC SSO, SSH key distribution, RADIUS and LDAP integration for modern…

authenticationauthentication-authorizationidentity-access-management+2
5.4k12h 32m ago
CVE-2022-46169_unauth_remote_code_execution preview

CVE-2022-46169_unauth_remote_code_execution

GitHubsvchost9913/cve-2022-46169_unauth_remote_code_execution

Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0

authentication-authorizationcommand-and-controlexploitation+3
3 years ago
Axiom-protocol preview

Axiom-protocol

GitHubkl4v3/axiom-protocol

The goal of Axiom is to provide a completely anonymous, decentralized, and censorship-resistant social media platform. To make this possible, the…

authentication-authorizationcryptographyencryption-decryption-tools+3
5 months ago
SCTT-2026-33-0004-FortiCloud-SSO-Identity-Singularity preview

SCTT-2026-33-0004-FortiCloud-SSO-Identity-Singularity

GitHubsimoesctt/sctt-2026-33-0004-forticloud-sso-identity-singularity

While Fortinet's January 27, 2026 mitigation for **CVE-2026-24858** focuses on blocking specific accounts like `[email protected]`, it fails to…

authentication-authorizationexploitationred-teaming+2
7 months ago
whiskeysamlandfriends preview

whiskeysamlandfriends

GitHubsecureworks/whiskeysamlandfriends

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

authentication-authorizationcloud-securityexploit-frameworks+3
812 years ago
CVE-2019-19033 preview

CVE-2019-19033

GitHubricardojoserf/cve-2019-19033

CVE-2019-19033 description and scripts to check the vulnerability in Jalios JCMS 10 (Authentication Bypass)

authentication-authorizationexploitationinformation-gathering+4
36 years ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
581 month ago
CVE-2025-47227_CVE-2025-47228 preview

CVE-2025-47227_CVE-2025-47228

GitHubsynacktiv/cve-2025-47227_cve-2025-47228

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

authentication-authorizationcommand-and-controlexploitation+3
111 year ago
CVE-2021-34646 preview

CVE-2021-34646

GitHubmotikan2010/cve-2021-34646

CVE-2021-34646 PoC

authentication-authorizationexploitationpenetration-testing+2
25 years ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
5464 years ago
Previous12…19Next