Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
70 results
CVE-2026-29000 preview

CVE-2026-29000

GitHubc0gnit00/cve-2026-29000

Python POC, Exploit for CVE-2026-29000

authentication-authorizationcryptographyeducation+5
1
3 months ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

api-securityauthentication-authorizationcryptography+4
1 month ago
opennhp preview

opennhp

GitHubopennhp/opennhp

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

authentication-authorizationcloud-securitycryptography+3
13.9k2 days ago
libsignal preview

libsignal

GitHubsignalapp/libsignal

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

cryptographyencryption-decryption-toolshardware-security+2
6.0k1 day ago
fulcio preview

fulcio

GitHubsigstore/fulcio

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

authentication-authorizationcryptographyidentity-access-management+1
8841 day ago
sslx preview

sslx

GitHubglincker/sslx

A fast, modern alternative to OpenSSL's CLI - inspect, grade, and manage certificates from the terminal

cryptographydevsecopsencryption-decryption-tools+3
1019h 33m ago
Axiom-protocol preview

Axiom-protocol

GitHubkl4v3/axiom-protocol

The goal of Axiom is to provide a completely anonymous, decentralized, and censorship-resistant social media platform. To make this possible, the…

authentication-authorizationcryptographyencryption-decryption-tools+3
5 months ago
apache__shiro_CVE-2023-34478_1-11-0 preview

apache__shiro_CVE-2023-34478_1-11-0

GitHubshoucheng3/apache__shiro_cve-2023-34478_1-11-0

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

authentication-authorizationcryptographyweb-security
1 year ago
freeipa preview

freeipa

GitHubfreeipa/freeipa

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

authenticationauthentication-authorizationcryptography+2
1.3k2 months ago
NoEyes preview

NoEyes

GitHubymsniper/noeyes

Secure terminal chat. E2E encrypted, zero-metadata blind-forwarder server. PyNaCl XSalsa20-Poly1305 + Ed25519 + forward secrecy. Cross-platform…

authentication-authorizationcryptographyencryption-decryption-tools+3
1463 months ago
keeper preview

keeper

GitHubagberohq/keeper

Simple Secure Keeper for Secrets

authentication-authorizationcryptographyencryption-decryption-tools+1
1235 months ago
oracle-oam-authentication-bypas-exploit preview

oracle-oam-authentication-bypas-exploit

GitHubaymanelsherif/oracle-oam-authentication-bypas-exploit

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

authentication-authorizationcryptographyexploitation+3
77 years ago
SecureCivic preview

SecureCivic

GitLabroxanne_ardary/securecivic

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…

api-securityauthentication-authorizationcloud-security+7
2 months ago
pam_pkcs11 preview

pam_pkcs11

GitHubx41sec/pam_pkcs11

pam_pkcs11 Bugfix

authenticationauthentication-authorizationcryptography+2
28 years ago
RS256-2-HS256 preview

RS256-2-HS256

GitHub3v4si0n/rs256-2-hs256

JWT Attack to change the algorithm RS256 to HS256

cryptographyexploitationvulnerability-analysis+1
343 years ago
CVE-2018-0114 preview

CVE-2018-0114

GitHubj4k0m/cve-2018-0114

Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.

cryptographyexploitationpayload-generation+3
45 years ago
demo-cve-2022-21449 preview

demo-cve-2022-21449

GitHubvolodymyr-hladkyi-symphony/demo-cve-2022-21449

Educational demo of CVE-2022-21449 Java ECDSA signature bypass using real and fake JWT tokens to illustrate the vulnerability and its impact on…

authenticationcryptographyeducation+3
1 year ago
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
4 months ago
Previous1234Next