Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
131 results
jwtear preview

jwtear

GitHubkingsabri/jwtear

Modular command-line tool to parse, create and manipulate JWT tokens for hackers

educationpassword-crackingpenetration-testing+2
1055 years ago
cookiemonster preview

cookiemonster

GitHubiangcarroll/cookiemonster

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

cryptographypenetration-testingvulnerability-analysis+1
9971 year ago
flask-session-cookie-manager preview

flask-session-cookie-manager

GitHubnoraj/flask-session-cookie-manager

🍪 Flask Session Cookie Decoder/Encoder

encryption-decryption-toolspenetration-testingweb-security
7701 year ago
sessionprobe preview

sessionprobe

GitHubdub-flow/sessionprobe

Multi-threaded web authorization testing tool that evaluates user privileges by checking session token access across a list of URLs, highlighting…

penetration-testingweb-security
4662 years ago
jwt-reauth preview

jwt-reauth

GitHubnccgroup/jwt-reauth

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

api-securityauthenticationpenetration-testing+3
1063 years ago
crackerjack preview

crackerjack

GitHubsadreck/crackerjack

Web-based GUI for Hashcat that simplifies password cracking with session management, mask generation, wordlist support, and multi-user access.

cryptographyhash-analysispassword-cracking+3
641 year ago
CodeIgniterXor preview

CodeIgniterXor

GitHubdionach/codeigniterxor

CodeIgniter <=2.1.4 session cookie decryption vulnerability

encryption-decryption-toolsexploitationpenetration-testing+3
3910 years ago
laravel_cookie_killer preview

laravel_cookie_killer

GitHubsynacktiv/laravel_cookie_killer

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

encryption-decryption-toolsexploitationpayload-development+4
283 years ago
InstagramMutualFollowerChecker preview

InstagramMutualFollowerChecker

GitHuboscarfromnz/instagrammutualfollowerchecker

Checks mutual followers between ig accounts (local hosted, use your own session id)

information-gatheringosintsocial-engineering+1
234 months ago
CVE-2021-32099 preview

CVE-2021-32099

GitHubibnuuby/cve-2021-32099

Proof-of-concept exploit for CVE-2021-32099, a SQL injection vulnerability in Pandora FMS, demonstrating session hijacking via crafted UNION query.

exploitationpenetration-testingvulnerability-analysis+2
214 years ago
FiddleZAP preview

FiddleZAP

GitHubmalwareinfosec/fiddlezap

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

intrusion-detectionmalware-analysisthreat-intelligence+2
174 years ago
OpenShell preview

OpenShell

GitHubiss4cf0ng/openshell

Lightweight Go-based reverse shell management server with a web GUI for interactive shell sessions, session management, and multi-tab terminal…

command-and-controlpenetration-testingred-teaming+3
267 months ago
TOTPAuthenticate preview

TOTPAuthenticate

GitHubhannah-portswigger/totpauthenticate

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

api-security-testingauthenticationpenetration-testing+1
92 years ago
By-Poloss..-..CVE-2026-19125 preview

By-Poloss..-..CVE-2026-19125

GitHubpolosss/by-poloss..-..cve-2026-19125

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

authenticationexploitationpassword-attacks+5
15 days ago
CVE-2026-19516 preview

CVE-2026-19516

GitHubhorkimhab/cve-2026-19516

Proof-of-concept for CVE-2026-19516, demonstrating session spoofing and SSRF in Grafana MCP. Intended for authorized security research and education…

curated-resourceseducationexploitation+2
1 month ago
CVE-2021-32099 preview

CVE-2021-32099

GitHubzjicmdarkwing/cve-2021-32099

Proof-of-concept exploit for CVE-2021-32099, a SQL injection vulnerability in Pandora FMS, demonstrating session hijacking via crafted HTTP requests.

exploitationpenetration-testingvulnerability-analysis+2
54 years ago
Cookie-Swapper preview

Cookie-Swapper

GitHub0xbartita/cookie-swapper

Burp Suite extension that auto-replaces cookies and headers in requests using configurable rules. Eliminates manual copy-pasting of session tokens…

penetration-testingscripting-automationutilities-frameworks+2
66 months ago
CVE-2026-36392 preview

CVE-2026-36392

GitHubmoksh-nfsu/cve-2026-36392

Proof-of-concept for stored XSS in RISE CRM item title field (CVE-2026-36392), demonstrating session hijacking and account takeover with remediation…

exploitationpenetration-testingvulnerability-analysis+2
11 month ago
Previous12…8Next