Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
163 results
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k
2 days ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 days ago
CVE-2026-96451 preview

CVE-2026-96451

GitHubnxploited/cve-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

exploitationpassword-attackspenetration-testing+5
3 days ago
CVE-2026-15989 preview

CVE-2026-15989

GitHubantid00t/cve-2026-15989

Python PoC scanner for CVE-2026-15989, exploiting unauthenticated role injection in WordPress Super Forms to create admin accounts and verify access.

exploitationpassword-attackspenetration-testing+6
15 days ago
powerview.py preview

powerview.py

GitHubaniqfakhrul/powerview.py

Powerview on steroids

dns-analysisexploitationinformation-gathering+7
1.0k7 days ago
john preview

john

GitHubopenwall/john

John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems,…

cryptographyencryption-decryption-toolshash-analysis+4
13.7k8 days ago
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
4911 days ago
CVE-2026-14281 preview

CVE-2026-14281

GitHublangz337/cve-2026-14281

Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin…

exploitationpassword-attackspenetration-testing+6
112 days ago
evil-winrm-py preview

evil-winrm-py

GitHubadityatelange/evil-winrm-py

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

authenticationcommand-and-controllateral-movement+7
40617 days ago
ntlm_theft preview

ntlm_theft

GitHubgreenwolf/ntlm_theft

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

information-gatheringpassword-attackspenetration-testing+2
1.5k28 days ago
CVE-2026-63563 preview

CVE-2026-63563

GitHubredr0nin/cve-2026-63563

Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers

data-exfiltrationexploitationhardware-iot-security+3
21 month ago
brutespray preview

brutespray

GitHubx90skysn3k/brutespray

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+…

password-attackspassword-crackingpenetration-testing
2.5k1 month ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
1 month ago
CVE-2021-36460 preview

CVE-2021-36460

GitHubmartinfrancois/cve-2021-36460

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

authenticationexploitationmobile-security+2
2 months ago
CVE-2026-23005-Matter-Commissioning-Code-Brute-Force-Without-Rate-Limit preview

CVE-2026-23005-Matter-Commissioning-Code-Brute-Force-Without-Rate-Limit

GitHubgeorge0papasotiriou/cve-2026-23005-matter-commissioning-code-brute-force-without-rate-limit

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

embedded-systems-securityexploitationiot-security+2
2 months ago
Corporate_Masks preview

Corporate_Masks

GitHubgolem445/corporate_masks

8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

hash-analysispassword-attackspassword-cracking+3
2052 months ago
By-Poloss..-..CVE-2026-11551-PoC preview

By-Poloss..-..CVE-2026-11551-PoC

GitHubpolosss/by-poloss..-..cve-2026-11551-poc

Unauthenticated Privilege Escalation via Account Takeover

exploitationpassword-attackspenetration-testing+3
13 months ago
nounours preview

nounours

GitHubsynacktiv/nounours

Nounours is a tool designed to test APP_KEYs at scale on Laravel applications.

cryptographyencryption-decryption-toolspassword-attacks+3
13 months ago
Previous12…10Next