Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
python-paddingoracle preview

python-paddingoracle

GitHubmwielgoszewski/python-paddingoracle

A portable, padding oracle exploit API

cryptographyencryption-decryption-toolsexploitation+2
331
3 years ago
basecrack preview

basecrack

GitHubmufeedvh/basecrack

Decode All Bases - Base Scheme Decoder

cryptographyctfeducation+1
5833 years ago
ed25519-unsafe-libs preview

ed25519-unsafe-libs

GitHubmystenlabs/ed25519-unsafe-libs

List of unsafe ed25519 signature libs

cryptographycurated-resourceseducation+3
2492 years ago
badecparams preview

badecparams

GitHubsaleemrashid/badecparams

Proof of Concept for CVE-2020-0601

cryptographyexploitationpenetration-testing+2
664 months ago
sslscan preview

sslscan

GitHubdinotools/sslscan

SSLScan tests SSL/TLS enabled services to discover supported cipher suites

cryptographyencryption-decryption-toolsnetwork-security+3
8612 years ago
private-landing preview

private-landing

GitHubvhscom/private-landing

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

api-securityauthenticationauthentication-authorization+8
793 months ago
HTTPSignatures preview

HTTPSignatures

GitHubnccgroup/httpsignatures

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

api-securityapi-security-testingauthentication+3
424 years ago
passwordcheck preview

passwordcheck

GitHubrclone/passwordcheck

Check rclone config files for insecure passwords

configuration-auditingcryptographypassword-cracking+2
273 months ago
ASSAMEE preview

ASSAMEE

GitHubsamhaxr/assamee

AES-256 file and directory encryption tool with automatic upload to Anonfiles cloud storage, requiring a download ID for decryption and retrieval.

cloud-securitycryptographyencryption-decryption-tools
163 years ago
legion preview

legion

GitHubdeadends/legion

Legion is a Zero-Knowledge Authentication Fabric built for privacy

authenticationcryptographyhardware-security+3
108 months ago
dyen preview

dyen

GitHubcenobyte-vincit/dyen

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

binary-analysiscryptographyids-ips-evasion+4
16 days ago
CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass preview

CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass

GitHubbiitts/cve-2026-49230-apisix-jwe-decrypt-auth-bypass

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

api-securityauthenticationcryptography+5
1 month ago
CVE-2020-0601 preview

CVE-2020-0601

GitHubyoanndqr/cve-2020-0601

CurveBall CVE exploitation

code-analysiscryptographyexploitation+3
26 years ago
StealthCrypter preview

StealthCrypter

GitLaba-real-virus/stealthcrypter

AES-256 file and directory encryption tool with interactive CLI, progress bar, and optional secure deletion of originals. Supports large files and…

cryptographyencryption-decryption-toolsscripting-automation+1
2 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubc0gnit00/cve-2026-29000

Python POC, Exploit for CVE-2026-29000

authentication-authorizationcryptographyeducation+5
13 months ago
CVE-2024-29868 preview

CVE-2024-29868

GitHubdevisions/cve-2024-29868

Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0

cryptographyexploitationpassword-attacks+3
12 years ago
apache__shiro_CVE-2023-34478_1-11-0 preview

apache__shiro_CVE-2023-34478_1-11-0

GitHubshoucheng3/apache__shiro_cve-2023-34478_1-11-0

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

authentication-authorizationcryptographyweb-security
1 year ago
CVE-2022-21449 preview

CVE-2022-21449

GitHubdavwwwx/cve-2022-21449

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

cryptographyexploitationpayload-generation+2
3 years ago
Previous1234567Next