Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection
api-securityauthentication-authorizationcryptography+4
21 days ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
RootQuest-CTF-Box-Multi-Stage-Exploitation-VM preview

RootQuest-CTF-Box-Multi-Stage-Exploitation-VM

GitHubthieveshkar/rootquest-ctf-box-multi-stage-exploitation-vm

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

binary-exploitationcryptographyctf+7
10 months ago
ClaimJumper preview

ClaimJumper

GitHubfevra-dev/claimjumper

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

authenticationcryptographyexploitation+6
17 months ago
SAMLRaider preview

SAMLRaider

GitHubcompasssecurity/samlraider

SAML2 Burp Extension

api-security-testingauthenticationcryptography+6
4486 months ago
CVE-2026-46395-haxcms-hmac-key-leak preview

CVE-2026-46395-haxcms-hmac-key-leak

GitHubshreyas-challa/cve-2026-46395-haxcms-hmac-key-leak

PoC and writeup for CVE-2026-46395: unauthenticated private key disclosure via broken HMAC in HAXcms Node.js (CWE-321/CWE-200). Authorized security…

cryptographyeducationexploitation+3
2 months ago
SAMLRaider preview

SAMLRaider

GitHublindi2/samlraider

SAML2 Burp Extension

authenticationcryptographyidentity-access-management+4
37 years ago
CVE-2022-35513 preview

CVE-2022-35513

GitHubp1ckzi/cve-2022-35513

CVE-2022-35513 | blink1-pass-decrypt

cryptographyencryption-decryption-toolsexploitation+3
24 years ago
sign-saboteur preview

sign-saboteur

GitHubd0ge/sign-saboteur

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

authentication-authorizationcryptographyfuzzing+7
1721 year ago
pax preview

pax

GitHubliamg/pax

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

cryptographyexploitationpenetration-testing+1
1425 years ago
dp_cryptomg preview

dp_cryptomg

GitHubblacklanternsecurity/dp_cryptomg

Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.

cryptographyexploitationpenetration-testing+3
604 months ago
SHIRO-721 preview

SHIRO-721

GitHubjas502n/shiro-721

RememberMe Padding Oracle Vulnerability RCE

cryptographyexploitationpenetration-testing+2
726 years ago
OAMBuster preview

OAMBuster

GitHubredtimmy/oambuster

Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)

cryptographyexploitationpenetration-testing+2
247 years ago
oracle-oam-authentication-bypas-exploit preview

oracle-oam-authentication-bypas-exploit

GitHubaymanelsherif/oracle-oam-authentication-bypas-exploit

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

authentication-authorizationcryptographyexploitation+3
77 years ago
CVE-2025-65945-poc preview

CVE-2025-65945-poc

GitHubjedisct1/cve-2025-65945-poc

PoC for CVE-2025-65945 (Improper Verification of Cryptographic Signature in node-jws)

authenticationcryptographyexploitation+3
58 months ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubtushargurav28/cve-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish…

authenticationcryptographyexploitation+5
32 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubc0gnit00/cve-2026-29000

Python POC, Exploit for CVE-2026-29000

authentication-authorizationcryptographyeducation+5
12 months ago
CVE-2020-10560-Key-Recovery preview

CVE-2020-10560-Key-Recovery

GitHubalex-seymour/cve-2020-10560-key-recovery
cryptographyexploitationpenetration-testing+2
26 years ago
Previous123Next