Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
84 results
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
4 months ago
CVE-2026-29000-pac4j-jwt-auth-bypass preview

CVE-2026-29000-pac4j-jwt-auth-bypass

GitHubptechamanja/cve-2026-29000-pac4j-jwt-auth-bypass

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

authenticationctfexploitation+3
15 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubclayofgilgamesh/cve-2026-29000

CTF lab and exploit toolkit for CVE-2026-29000, a pac4j-jwt JWE authentication bypass. Includes vulnerable Flask target, token forging library,…

authenticationctfeducation+5
5 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHub0xw1ld/cve-2026-29000

Rust-based exploit generator for CVE-2026-29000, an authentication bypass in pac4j-jwt via alg:none JWT nested in JWE, automating JWKS retrieval and…

authenticationctfexploitation+3
5 months ago
HTB-TwoMillion-machine preview

HTB-TwoMillion-machine

GitHubabedallarawashdeh/htb-twomillion-machine

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

api-security-testingctfeducation+4
22 days ago
how-to-bypass-aslr-on-linux-x86_64 preview

how-to-bypass-aslr-on-linux-x86_64

GitHubnick0ve/how-to-bypass-aslr-on-linux-x86_64

ASLR bypass without infoleak

binary-exploitationctfeducation+1
1674 years ago
Frida-Labs preview

Frida-Labs

GitHubdere-ad2001/frida-labs

The repo contains a series of challenges for learning Frida for Android Exploitation.

android-securitybinary-analysisctf+6
1.3k6 months ago
onetwoseven-writeup preview

onetwoseven-writeup

GitHubdopaminauta/onetwoseven-writeup

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

ctfeducationexploitation+7
126 days ago
tryhackme-monikerlink-writeup preview

tryhackme-monikerlink-writeup

GitHubomarmahmoud1024/tryhackme-monikerlink-writeup

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

ctfeducationexploitation+4
28 days ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubvanhari/cve-2026-39987

Proof-of-concept exploit for an authentication bypass in marimo's terminal WebSocket endpoint, enabling unauthenticated command execution in versions…

authentication-authorizationctfexploitation+3
1 month ago
otto-support preview

otto-support

GitHubbishopfox/otto-support

An implementation of a vulnerable MCP server using mcp-go

api-securityauthentication-authorizationctf+5
204 months ago
cve-2025-53779-kerberos_bypass_reproduction preview

cve-2025-53779-kerberos_bypass_reproduction

GitHubrazureink/cve-2025-53779-kerberos_bypass_reproduction

Reproduction of cve-2025-53779-kerberos_bypass_reproduction

authenticationctfeducation+7
1 month ago
CVE-2026-9198 preview

CVE-2026-9198

GitHubywh-jfellus/cve-2026-9198

Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass

ctfeducationexploitation+4
1 month ago
CVE-2023-52654 preview

CVE-2023-52654

GitHubfoxyproxys/cve-2023-52654

Automated privilege escalation script exploiting misconfigured setuid/sgid binaries, sudo, cron, and LD_PRELOAD on Unix systems. Designed for CTF and…

ctfexploitationpenetration-testing+3
2 years ago
bad-epoll preview

bad-epoll

GitHubj-jaeyoung/bad-epoll

Linux kernel privilege-escalation exploit for CVE-2026-46242, a race-condition use-after-free in epoll, with 99% reliable root on desktops, servers,…

android-securitybinary-exploitationctf+4
5132 months ago
Exploits preview

Exploits

GitHub1n3/exploits

Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity

ctfexploitationexploit-frameworks+3
2084 years ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
mas-crackmes preview

mas-crackmes

GitHubowasp/mas-crackmes

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

android-securitybinary-analysisctf+6
363 years ago
Previous12345Next