Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
bitcracker preview

bitcracker

GitHube-ago/bitcracker

BitCracker is the first open source password cracking tool for memory units encrypted with BitLocker

cryptographyencryption-decryption-toolspassword-cracking
9734 years ago
pax preview

pax

GitHubliamg/pax

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

cryptographyexploitationpenetration-testing+1
1455 years ago
Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-0166 preview

Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-0166

GitHubdemining/vulnerable-to-debian-openssl-bug-cve-2008-0166

Search for BTC coins on earlier versions of Bitcoin Core with critical vulnerability OpenSSL 0.9.8 CVE-2008-0166

cryptographycurated-resourceseducation+3
93 years ago
mfoc preview

mfoc

GitHubnfc-tools/mfoc

Offline nested attack tool that recovers MIFARE Classic authentication keys using known default or user-supplied keys for assessing NFC/RFID card…

authenticationcryptographyhardware-hacking+3
1.4k2 years ago
hash-identifier preview

hash-identifier

GitHubblackploit/hash-identifier

Software to identify the different types of hashes used to encrypt data and especially passwords

cryptographyhash-analysisinformation-gathering+1
6368 years ago
dcipher-cli preview

dcipher-cli

GitHubk4m4/dcipher-cli

🔓Crack hashes using online rainbow & lookup table attack services, right from your terminal.

cryptographyctfhash-analysis+1
2335 years ago
dcipher preview

dcipher

GitHubk4m4/dcipher

Decipher hashes using online rainbow & lookup table attack services.

cryptographyctfhash-analysis+1
1515 years ago
ShuckNT preview

ShuckNT

GitHubyanncam/shucknt

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

authenticationcryptographyhash-analysis+3
781 year ago
crackerjack preview

crackerjack

GitHubsadreck/crackerjack

Web-based GUI for Hashcat that simplifies password cracking with session management, mask generation, wordlist support, and multi-user access.

cryptographyhash-analysispassword-cracking+3
651 year ago
RS256-2-HS256 preview

RS256-2-HS256

GitHub3v4si0n/rs256-2-hs256

JWT Attack to change the algorithm RS256 to HS256

cryptographyexploitationvulnerability-analysis+1
343 years ago
OAMBuster preview

OAMBuster

GitHubredtimmy/oambuster

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

cryptographyexploitationpenetration-testing+2
247 years ago
CVE-2023-33242 preview

CVE-2023-33242

GitHubd0rb/cve-2023-33242

Proof-of-concept exploit for CVE-2023-33242 demonstrating a bit extraction attack on the Lindell17 ECDSA protocol, enabling iterative private key…

binary-exploitationcryptographyexploitation+2
43 years ago
cve-2020-0601_poc preview

cve-2020-0601_poc

GitHubgremwell/cve-2020-0601_poc

Proof-of-concept exploit for CVE-2020-0601 (Windows CryptoAPI spoofing) that generates rogue CA certificates to intercept HTTPS traffic, with…

cryptographyeducationexploitation+2
26 years ago
ONe-TIME-ecb-oracle-attack-AES preview

ONe-TIME-ecb-oracle-attack-AES

GitHubspiralbl0ck/one-time-ecb-oracle-attack-aes

Implementation of the byte-at-a-time ECB oracle attack against AES-ECB encryption. Decrypts ciphertexts by feeding chosen plaintexts to a block…

cryptographyeducationexploitation+1
15 years ago
CVE-2024-5124 preview

CVE-2024-5124

GitHubgogo2464/cve-2024-5124

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

cryptographyexploitationfuzzing+3
11 year ago
Simple-Sweet32 preview

Simple-Sweet32

GitHubzakyhermawan/simple-sweet32

Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183)

cryptographyeducationexploitation+2
9 months ago
CVE-2020-16012-PoC preview

CVE-2020-16012-PoC

GitHubhelidem/cve-2020-16012-poc

Proof-of-concept for CVE-2020-16012: a side-channel attack recovering pixel data from cross-origin images using timing measurements in Chromium's…

cryptographyexploitationvulnerability-analysis+1
1 year ago
poodle-attack-sandbox preview

poodle-attack-sandbox

GitHubgorugoo/poodle-attack-sandbox

Test code for poodle attack (CVE-2014-3566)

cryptographyeducationexploitation+3
1 year ago
Previous1234Next