Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/moscowchill/lstar-en
Password CrackingPenetration Testing FrameworksPrivilege EscalationPersistence MechanismsExploitationIDS/IPS EvasionLateral MovementInformation GatheringPost-ExploitationCommand and ControlRed Teaming
233603 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Payload Development
GitHubmoscowchill/lstar-en

LSTAR-EN

LSTAR - CobaltStrike Translated to EN

View Repository

LSTAR - Aggressor Translated to English! By Google Translate and Deepl

For the purpose of simplifying CS right-click and facilitating self-integration, refer to a large number of post-infiltration plugins

Refactored and enriched host-related credential acquisition, multi-level intranet penetration, hidden scheduled tasks, anti-kill Mimikatz and cloning to add users and other functions

Features:

  • By cooperating with CobaltStrike's TCP, SMB, Proxy, etc., to penetrate the complex network environment
  • Provide multiple anti-kill execution methods for RDP-related, AddUser, LsassDump and other functions to deal with unpopular environments
  • **Integrate multiple anti-kill functions such as shadow users running in WinAPI or Assembly memory loading mode, hidden scheduled tasks, etc. **

Among others include the following functional modules:

image The rest of the pics below are unchanged!

Each module is added with a green dividing line before running to facilitate positioning and display information and improve collaboration efficiency

image-20211016170807973

CobaltStrike Host Launches Wechat Notification Plugin:

  • If you want to use a free method that supports WeChat template message push, you can go to: https://github.com/lintstar/CS-PushPlus
  • If there is an enterprise WeChat push channel that subscribes to ServerChan, you can move to: https://github.com/lintstar/CS-ServerChan

Disclaimer

This project is only applicable to security research and legal enterprise security construction. All consequences and responsibilities shall be borne by the user

2022.1.15 update

  • Add anti-kill clone user, add user, scheduled task function
  • Get the latest sunflower identification code and verification code
  • Integrated Ladon 9.1.1 version multi-protocol survival detection and other functions
  • Categorize the functions to simplify the secondary menu of the plugin

InfoCollect

Common commands are classified according to the scene

image-20220114101130300

SharpGetInfo

Integrated Ladon public latest version 9.1.1

image-20211229102143317

AntiVirusCheck

Antisoft information locally echoes Beacon status bar

Implementation principle: https://blog.csdn.net/weixin_42282189/article/details/121090055

image-20220112150926351

IntrScan

Added Ladon's multi-protocol liveness detection (SMB, WMI, SNMP, HTTP, DNS, MAC, MSSQL)

Intranet assets behind the firewall can be detected to a certain extent:Use MAC to bypass the firewall to detect surviving hosts

image-20211229171305053

Live IP detection

image-20211229171224738

AuthPromote

BadPotato (BeichenDream)

Fixed the bug that can only execute whoami, you can run the online System permission through parameters

image-20220113165021408

image-20220113165229359

Badpotato (Ladon)

Added Ladon's Badpotato

image-20211229104134559

Sweet Potato (Ladon)

image-20211229104432695

Note: The test found that the above two privilege escalation behaviors will be intercepted and killed by digital antivirus

image-20211229103727123

##AuthMaintain

SharpSchTask

**[Use with caution] Utilize Windows API to create hidden scheduled tasks with tools, and bypass the blocking of security software to achieve persistent control. **

Project address: https://github.com/0x727/SchTask_0x727

image-20220114100528645

SharpShadowUser

【Use with caution】Bypass remote memory loading clone hidden shadow users

Project address: https://github.com/An0nySec/ShadowUser

image-20220115175808998

EasyPersistent

Fix the PE file path problem, you can use the API method to delete the added user

image-20220115182612757

PassCapture

Categorize the functions according to the scene

image-20220115172016468

SunFlower

Get the latest sunflower identification code and verification code

The base_encry_pwd parameter of the latest version of Sunflower has been changed from config.ini to the registry

image-20220115173453909

RemoteLogin

Simplified secondary menu

image-20220115183414339

BypassCXK

SharpAddUser

Bypass AV utilizes the DirectoryService namespace to add users to the Administrators and Remote Desktop groups

Project address: https://github.com/An0nySec/UserAdd

image-20220113152442668

CloneX

A security detection tool for adding users and cloning users under the command line

Project address: https://github.com/0x727/CloneX_0x727

image-20220113155017688

2021.10.18 update

  • Reintegrated and optimized the overall functional modules
  • Lateral movement module adds BOF implementation of ZeroLogon vulnerability
  • Added some Assembly methods to run without file landing functions

InfoCollect

SharpGetInfo (one-click collection of host information)

Using Ladon for one-click collection includes host basic information, network information, user information, process information, whether it is in the domain, etc.

image-20211018111745511

SharpListRDP (RDP record query)

Download Tool