Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
44 results
SSH-Weak-DH preview

SSH-Weak-DH

GitHubstrozfriedberg/ssh-weak-dh

Audits SSH servers for weak Diffie-Hellman key exchange groups by testing multiple client configurations, identifying Logjam-vulnerable endpoints…

cryptographynetwork-securitypenetration-testing+1
104
6h 39m ago
CryptoLyzer preview

CryptoLyzer

GitLabcoroner/cryptolyzer

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

configuration-auditingcryptographydns-analysis+3
281 day ago
IoT-Vulnerability-Research-Public preview

IoT-Vulnerability-Research-Public

GitHubbadchemical/iot-vulnerability-research-public

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.

cryptographyeducationembedded-systems-security+8
171 day ago
testssl.sh preview

testssl.sh

GitHubtestssl/testssl.sh

Testing TLS/SSL encryption anywhere on any port

cryptographynetwork-securitypenetration-testing+2
9.2k2 days ago
TLS-Scanner preview

TLS-Scanner

GitHubtls-attacker/tls-scanner

Automated TLS server and client configuration scanner for pentesters and researchers. Evaluates cipher suites, protocol versions, and security…

cryptographynetwork-securitypenetration-testing+1
2844 days ago
sslscan preview

sslscan

GitHubrbsec/sslscan

Fast SSL/TLS scanner that discovers supported cipher suites, protocols, and vulnerabilities (Heartbleed, POODLE, CRIME) with certificate chain…

cryptographynetwork-securityvulnerability-scanners
2.6k5 days ago
awesome-web-hacking preview

awesome-web-hacking

GitHubinfoslack/awesome-web-hacking

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

cryptographyctfcurated-resources+6
7.3k15 days ago
heartbleed-vulnerability-exploitation preview

heartbleed-vulnerability-exploitation

GitHubl1lf1ng3r/heartbleed-vulnerability-exploitation

hands on investigation of the heartbleed vulnerability (CVE-2014-0160).

cryptographyeducationexploitation+7
18 days ago
CVE-2026-15469 preview

CVE-2026-15469

GitHubtony102741/cve-2026-15469

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

authenticationcryptographyexploitation+5
21 month ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
21 month ago
the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt preview

the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

GitHubhunt-benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

authenticationcryptographyexploitation+4
1 month ago
meshtastic-cve-2025-52464-poc preview

meshtastic-cve-2025-52464-poc

GitHubmsdmehdipour/meshtastic-cve-2025-52464-poc

Software-only proof of concept for CVE-2025-52464 in Meshtastic Direct Messages

cryptographyeducationembedded-systems-security+4
11 month ago
sshfinder preview

sshfinder

GitHubkabiri-labs/sshfinder

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

cryptographyinformation-gatheringnetwork-security+5
32 months ago
CVE-2023-3350 preview

CVE-2023-3350

GitHubitres-labs/cve-2023-3350

Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]

cryptographyeducationexploitation+6
2 months ago
O-Saft preview

O-Saft

GitHubowasp/o-saft

O-Saft - OWASP SSL advanced forensic tool

cryptographynetwork-securitypenetration-testing+1
3882 months ago
CVE-2026-29114 preview

CVE-2026-29114

GitHubcrimsonfiedofficial/cve-2026-29114

Dahua CVE-2026-29114

cryptographyeducationhardware-security+3
12 months ago
badsecrets preview

badsecrets

GitHubblacklanternsecurity/badsecrets

A library for detecting known secrets across many web frameworks

cryptographypenetration-testingsecret-detection+2
8283 months ago
CVE-2025-63353 preview

CVE-2025-63353

GitHubzvckster/cve-2025-63353

Multi-language PoC (Python · Go · JS · C) and technical documentation for CVE-2025-63353, a critical predictable-default-PSK vulnerability in…

cryptographycurated-resourceseducation+8
4 months ago
Previous123Next