Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
64 results
Heartbleed preview

Heartbleed

GitHubfilosottile/heartbleed

A checker (site and tool) for CVE-2014-0160

cryptographynetwork-securitypenetration-testing+1
2.4k
5 years ago
TLS-Attacker preview

TLS-Attacker

GitHubtls-attacker/tls-attacker

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

cryptographyfuzzingnetwork-security+2
8801 month ago
badsecrets preview

badsecrets

GitHubblacklanternsecurity/badsecrets

A library for detecting known secrets across many web frameworks

cryptographypenetration-testingsecret-detection+2
8212 months ago
cookiemonster preview

cookiemonster

GitHubiangcarroll/cookiemonster

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

cryptographypenetration-testingvulnerability-analysis+1
9831 year ago
CVE-2022-21449-TLS-PoC preview

CVE-2022-21449-TLS-PoC

GitHubnotkmhn/cve-2022-21449-tls-poc

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

cryptographyexploitationpenetration-testing+2
1215 months ago
rustpad preview

rustpad

GitHubkibouo/rustpad

Multi-threaded Padding Oracle attacks against any service. Written in Rust.

cryptographyexploitationpenetration-testing+1
1013 years ago
cve-2021-34558 preview

cve-2021-34558

GitHubalexzorin/cve-2021-34558

Proof-of-concept for CVE-2021-34558, demonstrating a TLS handshake panic in Go's crypto/tls via a malicious server with mismatched certificate and…

cryptographyexploitationpenetration-testing+2
455 years ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubtushargurav28/cve-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish…

authenticationcryptographyexploitation+5
32 months ago
CVE-2020-10560-Key-Recovery preview

CVE-2020-10560-Key-Recovery

GitHubalex-seymour/cve-2020-10560-key-recovery

Proof-of-concept exploit that recovers the site_key for OSSN 5.3 and above, exploiting CVE-2020-10560 arbitrary file read vulnerability.

cryptographyexploitationpenetration-testing+2
26 years ago
DHEater preview

DHEater

GitLabdheatattack/dheater

Proof-of-concept denial-of-service tool that enforces Diffie-Hellman ephemeral key exchange over TLS and SSH to saturate server CPU, implementing…

cryptographyexploitationnetwork-security+3
26 days ago
CVE-2024-5124 preview

CVE-2024-5124

GitHubgogo2464/cve-2024-5124

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

cryptographyexploitationfuzzing+3
11 year ago
CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit preview

CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit

GitHubpl4tyz/cve-2025-14611-centrestack-and-triofox-full-poc-exploit

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

authenticationcryptographyexploitation+6
8 months ago
CVE-2020-0601_PoC preview

CVE-2020-0601_PoC

GitHubjoelbts/cve-2020-0601_poc

Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and…

code-analysiscryptographyexploitation+3
2 years ago
crapsecrets preview

crapsecrets

GitHubirsdl/crapsecrets

A library for detecting known secrets across many web frameworks

cryptographypenetration-testingsecret-detection+2
228 months ago
messari-crack preview

messari-crack

GitHubtimuronlinq/messari-crack

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

authenticationcryptographyexploitation+3
21910 days ago
ssllabs.rb preview
Archived

ssllabs.rb

GitHubshopify/ssllabs.rb

Ruby client for the Qualys SSL Labs API enabling automated SSL/TLS server assessment, vulnerability detection (e.g., BEAST), and security grade…

cryptographypenetration-testingvulnerability-scanners+2
379 years ago
kekeo preview

kekeo

GitHubgentilkiwi/kekeo

A little toolbox to play with Microsoft Kerberos in C

authenticationcryptographyexploitation+1
1.5k4 years ago
miLazyCracker preview

miLazyCracker

GitHubnfc-tools/milazycracker

Mifare Classic Plus - Hardnested Attack Implementation for SCL3711 LibNFC USB reader

cryptographyexploitationhardware-hacking+2
3693 years ago
Previous1234Next