Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
SSH-Weak-DH preview

SSH-Weak-DH

GitHubstrozfriedberg/ssh-weak-dh

Audits SSH servers for weak Diffie-Hellman key exchange groups by testing multiple client configurations, identifying Logjam-vulnerable endpoints…

cryptographynetwork-securitypenetration-testing+1
104
5 months ago
dheater preview

dheater

GitHubc0r0n3r/dheater

Proof-of-concept denial-of-service tool that exploits the DHEat attack (CVE-2002-20001) by enforcing Diffie-Hellman key exchange against TLS and SSH…

cryptographyexploitationnetwork-security+1
2191 month ago
TP-Link-TL-WR820N-CVE-2025-14175 preview

TP-Link-TL-WR820N-CVE-2025-14175

GitHubcybervinner/tp-link-tl-wr820n-cve-2025-14175

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

cryptographyeducationembedded-systems-security+3
8 months ago
DHEater preview

DHEater

GitLabdheatattack/dheater

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

cryptographyexploitationnetwork-security+3
1 month ago
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
4 months ago
driftwood preview
Archived

driftwood

GitHubtrufflesecurity/driftwood

Private key usage verification

cryptographyencryption-decryption-toolspassword-cracking+2
4361 year ago
libssh-mirror preview

libssh-mirror

GitLablibssh/libssh-mirror

C library implementing the SSH protocol for secure remote access, authentication, and encrypted communication. Includes fuzzing support via OSS-Fuzz…

authenticationcryptographyencryption-decryption-tools+2
5310 days ago
PKCS11SSHAgent preview

PKCS11SSHAgent

GitHubsanmilie/pkcs11sshagent

SRO PKCS11 – SSH Agent CNG est un agent Windows souverain, ultra‑léger et zéro‑dépendance qui unifie PKCS#11, SSH-agent, Pageant et CNG/Smartcard…

authenticationcryptographyencryption-decryption-tools+3
247 months ago
ephemera preview

ephemera

GitHubqarait/ephemera

Zero-Trust SSH CA

authentication-authorizationcloud-infrastructure-securityconfiguration-auditing+6
297 months ago
USSH preview

USSH

GitHubx1colegal/ussh

Recreated SSH over USTPS

authenticationcryptographyencryption-decryption-tools+3
327 days ago
apache__mina-sshd_CVE-2023-35887_2-9-2 preview

apache__mina-sshd_CVE-2023-35887_2-9-2

GitHubshoucheng3/apache__mina-sshd_cve-2023-35887_2-9-2

Pure Java SSH client/server library implementing SSH-2 protocol with support for multiple ciphers, key exchanges, authentication methods, SFTP, SCP,…

authenticationcryptographyencryption-decryption-tools+5
1 year ago
openssh-portable preview

openssh-portable

GitHubopenssh/openssh-portable

Portable OpenSSH

authenticationcryptographynetwork-security+1
4.0k13h 50m ago
ssh-audit preview

ssh-audit

GitHubjtesta/ssh-audit

SSH server & client security auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)

configuration-auditingcryptographyinformation-gathering+6
4.3k2 months ago
CryptoLyzer preview

CryptoLyzer

GitLabcoroner/cryptolyzer

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

configuration-auditingcryptographydns-analysis+3
288 days ago
sshfinder preview

sshfinder

GitHubkabiri-labs/sshfinder

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

cryptographyinformation-gatheringnetwork-security+5
31 month ago
CVE-2024-22894 preview

CVE-2024-22894

GitHubjaarden/cve-2024-22894

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

cryptographyembedded-systems-securityexploitation+6
32 years ago
dsa preview

dsa

GitHubalexmullins/dsa

Analysis of CVE-2016-3959 and a Proof of Concept Attack Against a Go SSH Server.

cryptographyeducationexploitation+2
110 years ago