Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
50 results
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

In-memory implant framework for Java and ASP.NET webshells with AES-encrypted communication, dynamic payload loading, and session-based execution for…

dynamic-code-analysiseducationencryption-decryption-tools+7
47
1 month ago
CodeIgniterXor preview

CodeIgniterXor

GitHubdionach/codeigniterxor

CodeIgniter <=2.1.4 session cookie decryption vulnerability

encryption-decryption-toolsexploitationpenetration-testing+3
3910 years ago
Extractor preview

Extractor

GitHubnccgroup/extractor

Burp Suite extension for interactive data extraction and transformation in HTTP traffic with configurable node tree supporting Base64, JSON, XML, URL…

encryption-decryption-toolspenetration-testingscripting-automation+3
417 years ago
Burp_AES_Plugin preview

Burp_AES_Plugin

GitHubjas502n/burp_aes_plugin

Decrypts AES-encrypted web requests and integrates with Intruder for automated brute-force cracking of login credentials via custom payload processor.

cryptographyencryption-decryption-toolsfuzzing+4
386 years ago
dotnetpaddingoracle preview

dotnetpaddingoracle

GitHubnccgroup/dotnetpaddingoracle

Python Implementation of a .NET Padding Oracle Assessment Tool

cryptographyencryption-decryption-toolsexploitation+3
3110 years ago
test-certs-site preview

test-certs-site

GitHubletsencrypt/test-certs-site

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

api-security-testingdevsecopsencryption-decryption-tools+1
252 months ago
CVE-2025-55182-RCE-shell preview

CVE-2025-55182-RCE-shell

GitHubruoji6/cve-2025-55182-rce-shell

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

command-and-controlencryption-decryption-toolsexploitation+5
318 months ago
laravel_cookie_killer preview

laravel_cookie_killer

GitHubsynacktiv/laravel_cookie_killer

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

encryption-decryption-toolsexploitationpayload-development+4
283 years ago
ecologyExp.jar preview

ecologyExp.jar

GitHubianxtianxt/ecologyexp.jar

Java-based exploit tool for reading and decrypting database configuration files from vulnerable Fanwei OA instances by accessing a specific JSP…

data-exfiltrationencryption-decryption-toolsinformation-gathering+3
176 years ago
CVE-2017-7921-Research-Toolkit preview

CVE-2017-7921-Research-Toolkit

GitHubwyl-cmd/cve-2017-7921-research-toolkit

Batch scanner for Hikvision cameras vulnerable to CVE-2017-7921, automating configuration file decryption and credential extraction, with…

encryption-decryption-toolsexploitationinformation-gathering+3
515 days ago
CVE-2019-5420 preview

CVE-2019-5420

GitHubj4k0m/cve-2019-5420

A vulnerability can allow an attacker to guess the automatically generated development mode secret token.

encryption-decryption-toolspassword-attackspenetration-testing+2
54 years ago
CVE-2021-43798 preview

CVE-2021-43798

GitHubokymi-x/cve-2021-43798

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

encryption-decryption-toolsexploitationinformation-gathering+3
2 months ago
CVE-2024-55555 preview

CVE-2024-55555

GitHubyucaerin/cve-2024-55555

Mass scanner for Laravel apps vulnerable to CVE-2024-55555, automating APP_KEY brute-force to detect unauthenticated RCE in Invoice Ninja.

encryption-decryption-toolsexploitationpassword-cracking+3
21 year ago
CVE-2018-0114 preview

CVE-2018-0114

GitHuberemiel/cve-2018-0114

Python script exploiting CVE-2018-0114 to forge JWT tokens by embedding attacker-controlled public keys in JWS headers, bypassing signature…

authenticationencryption-decryption-toolsexploitation+3
25 years ago
Cve-2026-27944-Tools-Exploit preview

Cve-2026-27944-Tools-Exploit

GitHubbimabalance/cve-2026-27944-tools-exploit

Exploit tool for CVE-2026-27944 targeting Nginx UI unauthenticated backup download and decryption, with mass scanning, credential extraction, and…

encryption-decryption-toolsexploitationinformation-gathering+4
11 month ago
nounours preview

nounours

GitHubsynacktiv/nounours

Rust-based brute-force scanner for Laravel APP_KEYs: inlines AES-NI decryption, supports single and batch key testing against encrypted ciphertexts.

cryptographyencryption-decryption-toolspassword-attacks+3
12 months ago
CVE_2019_18935 preview

CVE_2019_18935

GitHubthanhuutuan/cve_2019_18935

Combined exploit for Telerik UI ASP.NET AJAX, enabling arbitrary file upload and .NET deserialization attacks with encryption/decryption of…

encryption-decryption-toolsexploitationpayload-generation+3
26 years ago
CVE-2022-35513 preview

CVE-2022-35513

GitHubp1ckzi/cve-2022-35513

PoC exploit for CVE-2022-35513 that decrypts weakly encrypted passwords from the Blink1Control2 API server, reversing ciphertext found at the…

cryptographyencryption-decryption-toolsexploitation+3
24 years ago
Previous123Next