Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
266 results
Android-Security-Masterclass preview

Android-Security-Masterclass

GitHubowasp/android-security-masterclass

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

android-securitycryptographyeducation+6
1
10 days ago
badkeys preview

badkeys

GitHubbadkeys/badkeys

Tool to find common vulnerabilities in cryptographic public keys

cryptographyencryption-decryption-toolshash-analysis+3
37616h 23m ago
CVE-2022-0778 preview

CVE-2022-0778

GitHubjeongjunsoo/cve-2022-0778

Proof-of-concept exploit for CVE-2022-0778, a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function, with Docker-based lab environment…

cryptographyeducationexploitation+2
12 years ago
heartbleed-lab preview

heartbleed-lab

GitHubvictoriacfigueiredo/heartbleed-lab

Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.

binary-exploitationcryptographyeducation+3
4 months ago
CVE-2026-13447 preview

CVE-2026-13447

GitHubabraxas/cve-2026-13447

Proof-of-concept exploit for CVE-2026-13447, a critical authentication bypass in the WordPress MStore API plugin via forged Firebase JWT tokens, with…

authenticationcryptographyexploitation+5
3 days ago
CVE-2026-5430 preview

CVE-2026-5430

GitHubabraxas/cve-2026-5430

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

api-securityauthenticationcryptography+6
18 days ago
PadBuster preview

PadBuster

GitHubstrozfriedberg/padbuster

Automated script for performing Padding Oracle attacks

cryptographyexploitationvulnerability-analysis+1
8125 years ago
rustpad preview

rustpad

GitHubkibouo/rustpad

Multi-threaded Padding Oracle attacks against any service. Written in Rust.

cryptographyexploitationpenetration-testing+1
1013 years ago
libfido2 preview

libfido2

GitHubyubico/libfido2

Provides library functionality for FIDO2, including communication with a device over USB or NFC.

authenticationcryptographyhardware-security+2
7382 months ago
cookiemonster preview

cookiemonster

GitHubiangcarroll/cookiemonster

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

cryptographypenetration-testingvulnerability-analysis+1
9971 year ago
padre preview

padre

GitHubglebarez/padre

Blazing fast, advanced Padding Oracle exploit

cryptographyexploitationpenetration-testing+1
2811 year ago
HSTP preview

HSTP

GitHubcagataycali/hstp

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

cryptographynetwork-securityutilities-frameworks+1
1552 years ago
badecparams preview

badecparams

GitHubsaleemrashid/badecparams

Proof of Concept for CVE-2020-0601

cryptographyexploitationpenetration-testing+2
665 months ago
CVE-2022-21449-TLS-PoC preview

CVE-2022-21449-TLS-PoC

GitHubnotkmhn/cve-2022-21449-tls-poc

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

cryptographyexploitationpenetration-testing+2
1216 months ago
RS256-2-HS256 preview

RS256-2-HS256

GitHub3v4si0n/rs256-2-hs256

JWT Attack to change the algorithm RS256 to HS256

cryptographyexploitationvulnerability-analysis+1
343 years ago
cve-2021-34558 preview

cve-2021-34558

GitHubalexzorin/cve-2021-34558

Proof-of-concept for CVE-2021-34558, demonstrating a TLS handshake panic in Go's crypto/tls via a malicious server with mismatched certificate and…

cryptographyexploitationpenetration-testing+2
455 years ago
php_mt_seed preview

php_mt_seed

GitHubal1ex/php_mt_seed

php_mt_seed is a PHP mt_rand() seed cracker

cryptographyexploitationpenetration-testing+2
76 years ago
docker-cve-2016-2107 preview

docker-cve-2016-2107

GitHubtmiklas/docker-cve-2016-2107

Docker container implementing tests for CVE-2016-2107 - LuckyNegative20

cryptographyexploitationpenetration-testing+2
210 years ago
Previous12…15Next