Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
95 results
testssl.sh preview

testssl.sh

GitHubtestssl/testssl.sh

Testing TLS/SSL encryption anywhere on any port

cryptographynetwork-securitypenetration-testing+2
9.2k
16h 27m ago
TLS-Attacker preview

TLS-Attacker

GitHubtls-attacker/tls-attacker

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

cryptographyfuzzingnetwork-security+2
8811 month ago
SSH-Weak-DH preview

SSH-Weak-DH

GitHubstrozfriedberg/ssh-weak-dh

Audits SSH servers for weak Diffie-Hellman key exchange groups by testing multiple client configurations, identifying Logjam-vulnerable endpoints…

cryptographynetwork-securitypenetration-testing+1
1045 months ago
CVE-2014-0224 preview

CVE-2014-0224

GitHubsecretnonempty/cve-2014-0224

Go-based MITM exploit demo for OpenSSL CVE-2014-0224 (CCS Injection) targeting RC4-SHA cipher, with server/client proxy setup for testing TLS…

cryptographyexploitationnetwork-security+3
912 years ago
DHEater preview

DHEater

GitLabdheatattack/dheater

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

cryptographyexploitationnetwork-security+3
1 month ago
RedTeamCoin preview

RedTeamCoin

GitHubxyplex3/redteamcoin

Red Team Coin for crypto-mining operations.

command-and-controlcryptographyexploitation+3
256 months ago
crapsecrets preview

crapsecrets

GitHubirsdl/crapsecrets

A library for detecting known secrets across many web frameworks

cryptographypenetration-testingsecret-detection+2
229 months ago
SAMLRaider preview

SAMLRaider

GitHublindi2/samlraider

SAML2 Burp Extension

authenticationcryptographyidentity-access-management+4
37 years ago
xzbot preview

xzbot

GitHubamlweems/xzbot

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

binary-analysiscryptographyexploitation+3
3.6k2 years ago
Heartbleed preview

Heartbleed

GitHubfilosottile/heartbleed

A checker (site and tool) for CVE-2014-0160

cryptographynetwork-securitypenetration-testing+1
2.4k5 years ago
kekeo preview

kekeo

GitHubgentilkiwi/kekeo

A little toolbox to play with Microsoft Kerberos in C

authenticationcryptographyexploitation+1
1.5k4 years ago
O-Saft preview

O-Saft

GitHubowasp/o-saft

O-Saft - OWASP SSL advanced forensic tool

cryptographynetwork-securitypenetration-testing+1
3871 month ago
badsecrets preview

badsecrets

GitHubblacklanternsecurity/badsecrets

A library for detecting known secrets across many web frameworks

cryptographypenetration-testingsecret-detection+2
8252 months ago
cookiemonster preview

cookiemonster

GitHubiangcarroll/cookiemonster

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

cryptographypenetration-testingvulnerability-analysis+1
9911 year ago
TLS-Scanner preview

TLS-Scanner

GitHubtls-attacker/tls-scanner

Automated TLS server and client configuration scanner for pentesters and researchers. Evaluates cipher suites, protocol versions, and security…

cryptographynetwork-securitypenetration-testing+1
28414 days ago
miLazyCracker preview

miLazyCracker

GitHubnfc-tools/milazycracker

Mifare Classic Plus - Hardnested Attack Implementation for SCL3711 LibNFC USB reader

cryptographyexploitationhardware-hacking+2
3693 years ago
CVE-2022-33679 preview

CVE-2022-33679

GitHubbdenneu/cve-2022-33679

One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html

authenticationcryptographyexploitation+2
4141 year ago
pacemaker preview

pacemaker

GitHublekensteyn/pacemaker

Heartbleed (CVE-2014-0160) client exploit

cryptographyexploitationnetwork-security+3
33110 years ago
Previous123456Next