Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.8k
6 months ago
CamOver preview

CamOver

GitHubentysec/camover

Exploits vulnerabilities in popular IP cameras (CCTV, GoAhead, Netwave) to disclose admin passwords. Supports single targets, file-based lists, and…

exploitationinformation-gatheringiot-security+1
5942 years ago
RomBuster preview

RomBuster

GitHubentysec/rombuster

Exploits known vulnerabilities in popular routers (D-Link, Zyxel, TP-Link, Cisco, Huawei) to extract admin credentials, with support for single…

exploitationinformation-gatheringiot-security+1
5602 years ago
automato preview

automato

GitHubskahwah/automato

Ruby-based LDAP enumeration tool for internal penetration tests. Automates user, computer, and group discovery, password spraying, LAPS retrieval,…

information-gatheringpassword-attackspenetration-testing
716 years ago
CVE-2020-15906 preview

CVE-2020-15906

GitHubs1lkys/cve-2020-15906

Proof-of-concept exploit and detailed writeup for CVE-2020-15906, an authentication bypass in Tiki Wiki CMS Groupware 16.x-21.1 allowing…

authentication-authorizationexploitationpassword-attacks+3
515 years ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalucard0x1/cve-2024-28000

Proof-of-concept exploit for CVE-2024-28000, a privilege escalation vulnerability in LiteSpeed Cache WordPress plugin, allowing unauthenticated…

educationexploitationpassword-attacks+4
232 years ago
CVE-2025-2304 preview

CVE-2025-2304

GitHubalien0ne/cve-2025-2304

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

educationexploitationpassword-attacks+4
196 months ago
AdminSnatcher preview

AdminSnatcher

GitHubsyedshehzadgillani/adminsnatcher

Let's Snatch The Admin Panel Of Any Website In Seconds.

information-gatheringpassword-attackspenetration-testing+2
186 years ago
zerologon preview

zerologon

GitHubsho-luv/zerologon

Python exploit for CVE-2020-1472 (Zerologon) that checks, exploits, and restores domain controller machine account passwords, enabling DCSync and…

exploitationpassword-attackspenetration-testing+3
184 years ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubzen-kun04/cve-2025-49132

Exploit script for CVE-2025-49132 that retrieves database credentials from vulnerable Pterodactyl panels via unauthenticated arbitrary file read,…

exploitationinformation-gatheringpassword-attacks+3
171 year ago
CVE-2021-36394 preview

CVE-2021-36394

GitHubdinhbaouit/cve-2021-36394

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

exploitationpassword-attackspenetration-testing+3
134 years ago
CVE-2017-14262 preview

CVE-2017-14262

GitHubzzz66686/cve-2017-14262

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

embedded-systems-securityexploitationiot-security+3
68 years ago
CVE-2025-47227 preview

CVE-2025-47227

GitHubouts1d3r-net/cve-2025-47227

Python exploit for CVE-2025-47227 targeting ScriptCase pre-authentication password reset vulnerability (CVSS 9.8) to gain unauthorized admin access.

authentication-authorizationexploitationpassword-attacks+3
62 months ago
wpbf preview

wpbf

GitHubdejanlevaja/wpbf

Multithreaded WordPress brute-force tool that tests admin credentials against a list of sites using configurable threads, timeouts, and verbose…

authenticationinformation-gatheringpassword-attacks+2
512 years ago
cve-2023-42820 preview

cve-2023-42820

GitHubstartr4ck/cve-2023-42820

Exploit for JumpServer CVE-2023-42820 that resets admin password and chains with CVE-2023-42819 to achieve remote code execution on affected versions.

exploitationpassword-attackspenetration-testing+3
22 years ago
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
25 years ago
CVE-2026-27886-PoC-Account-Takeover preview

CVE-2026-27886-PoC-Account-Takeover

GitHubthesw0rd/cve-2026-27886-poc-account-takeover

Automated PoC exploit for CVE-2026-27886 in Strapi CMS. Performs email enumeration, password reset token exfiltration, and full admin account…

exploitationinformation-gatheringpassword-attacks+4
22 months ago
wp-def preview

wp-def

GitHubjenderal92/wp-def

Fast WordPress default credential checker: uses common username/password pairs to detect weak admin accounts.

misconfigurationpassword-attacksvulnerability-analysis+1
22 months ago
Previous123Next