Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
refinery preview

refinery

GitHubbinref/refinery

High Octane Triage Analysis

binary-analysiscryptographyforensics+4
8762 days ago
Asyncrat-Venom-Dcrat-Config-Extractor preview

Asyncrat-Venom-Dcrat-Config-Extractor

GitHubembee-research/asyncrat-venom-dcrat-config-extractor

Config Extractor for Asyncrat/Dcrat/VenomRat

cryptographymalware-analysisreverse-engineering+2
13 years ago
DotNET_XorCryptor preview

DotNET_XorCryptor

GitHubdosx-dev/dotnet_xorcryptor

A new simple and powerfull packer for malware

adversarial-attackcryptographypayload-development+1
1072 years ago
HiveV5_file_decryptor preview

HiveV5_file_decryptor

GitHubreecdeep/hivev5_file_decryptor

Hive v5 file decryption algorithm

cryptographydata-recoveryencryption-decryption-tools+2
343 years ago
Icedid-file-decryptor preview

Icedid-file-decryptor

GitHubembee-research/icedid-file-decryptor

Static Decryptor for IcedID Malware

binary-analysiscryptographymalware-analysis+2
183 years ago
CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection preview

CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection

GitHubgeorge0papasotiriou/cve-2026-1122-iot-firmware-update-signature-bypass-via-low-order-point-injection

Demonstrates CVE-2026-1122 Ed25519 signature bypass via low-order point injection, forging malicious IoT firmware updates with Python and C verifier…

cryptographyembedded-systems-securityexploitation+4
1 month ago
NoMoreXOR preview

NoMoreXOR

GitHubhiddenillusion/nomorexor

Tool to help guess a files 256 byte XOR key by using frequency analysis

binary-analysiscryptographyforensics+3
908 years ago
GAMBA preview

GAMBA

GitHubdenuvosoftwaresolutions/gamba

Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA

binary-analysiscryptographymalware-analysis+2
2472 years ago
Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit preview

Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit

GitHubmostafasoliman/oracle-oam-padding-oracle-cve-2018-2879-exploit

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

authenticationcryptographyexploitation+5
115 years ago
MALW preview

MALW

GitHubooscaar/malw

CVE-2007-4559 - Polemarch exploit

command-and-controlcryptographyexploitation+3
3 years ago
CVE-2022-21449-TLS-PoC preview

CVE-2022-21449-TLS-PoC

GitHubnotkmhn/cve-2022-21449-tls-poc

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

cryptographyexploitationpenetration-testing+2
1216 months ago
CVE-2018-0114 preview

CVE-2018-0114

GitHubj4k0m/cve-2018-0114

Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.

cryptographyexploitationpayload-generation+3
45 years ago
CVE-2022-21449 preview

CVE-2022-21449

GitHubdavwwwx/cve-2022-21449

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

cryptographyexploitationpayload-generation+2
3 years ago
cve-2021-34558 preview

cve-2021-34558

GitHubalexzorin/cve-2021-34558

Proof-of-concept for CVE-2021-34558, demonstrating a TLS handshake panic in Go's crypto/tls via a malicious server with mismatched certificate and…

cryptographyexploitationpenetration-testing+2
455 years ago
CVE-2020-0601 preview

CVE-2020-0601

GitHubyoanndqr/cve-2020-0601

CurveBall CVE exploitation

code-analysiscryptographyexploitation+3
26 years ago
CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass preview

CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass

GitHubbiitts/cve-2026-49230-apisix-jwe-decrypt-auth-bypass

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

api-securityauthenticationcryptography+5
2 months ago
Minesweeper preview

Minesweeper

GitHubcodingo/minesweeper

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

cryptographythreat-intelligencevulnerability-scanners+1
2037 years ago
Coldfire preview

Coldfire

GitHubredcode-labs/coldfire

Golang malware development library

command-and-controlcryptographyexploitation+5
9851 year ago
Previous12Next