Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
744
5 years ago
keepassxc preview

keepassxc

GitHubkeepassxreboot/keepassxc

Secure offline storage of credentials with encrypted vaults, password generator, TOTP, YubiKey/OnlyKey support, browser integration, and CLI.

authenticationcryptographyencryption-decryption-tools+1
29.0k3 days ago
PIVert preview

PIVert

GitHubccob/pivert

Emulates NIST SP 800-73 PIV smart cards on Windows using a PFX certificate and private key, enabling smart-card authentication for RDP, Citrix, and…

authenticationhardware-securityidentity-access-management+2
1082 years ago
CS-Remote-OPs-BOF preview

CS-Remote-OPs-BOF

GitHubtrustedsec/cs-remote-ops-bof

Remote operations commands implemented using Beacon Object Files

authenticationencryption-decryption-toolslateral-movement+6
1.2k1 day ago
WonkaVision preview

WonkaVision

GitHub0xe7/wonkavision

Detects forged Kerberos tickets by dumping session and ticket data, scoring anomalies, and generating Windows event-log indicators for SIEM-based…

anomaly-detectionauthenticationdefensive-tools+4
893 years ago
GraphSpy preview

GraphSpy

GitHubredbyte1337/graphspy

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

authenticationcloud-securitydata-exfiltration+6
1.4k1 month ago
PetitPotam preview

PetitPotam

GitHubcorelight/petitpotam

Detects NTLM relay attacks via PetitPotam exploit using Zeek, distinguishing successful and unsuccessful attempts by analyzing DCERPC return codes.

anomaly-detectionauthenticationdefensive-tools+2
15 years ago
cve-2024-1708-connectwise_rce_reproduction preview

cve-2024-1708-connectwise_rce_reproduction

GitHubrazureink/cve-2024-1708-connectwise_rce_reproduction

Reproduction of cve-2024-1708-connectwise_rce_reproduction

authenticationeducationexploitation+5
2 months ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysishash-analysis+6
3.9k1 year ago
CVE-2025-33073-checker preview

CVE-2025-33073-checker

GitHubmatejsmycka/cve-2025-33073-checker

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

authenticationexploitationinformation-gathering+3
1 year ago
Active-Directory-BadSuccessor preview

Active-Directory-BadSuccessor

GitHubmusa-xvi/active-directory-badsuccessor

A TryHackme room covering the CVE-2025-53779 exploitation using windows

authenticationctfeducation+6
3 months ago
AddUser-SAMR preview

AddUser-SAMR

GitHubricardojoserf/adduser-samr

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

authenticationidentity-access-managementlateral-movement+5
9726 days ago
webauthn_tpm_portable preview

webauthn_tpm_portable

GitHubmimi89999/webauthn_tpm_portable

Portable, hardware-backed WebAuthn credentials using TPM 2.0. Deterministic parent key derived from a master seed enables cross-device credential…

authenticationcryptographyencryption-decryption-tools+2
46 months ago
signal-without-smartphone preview

signal-without-smartphone

GitHubalmet/signal-without-smartphone

Desktop application to register a Signal account and link Signal Desktop without requiring a smartphone, using Signal's cryptographic protocols for…

authenticationencryption-decryption-toolsmobile-security+2
761 month ago
orb preview

orb

GitHubzayan-mohamed/orb

Orb is a secure, terminal-first utility that allows you to share a local folder across the internet using end-to-end encryption. No accounts, no…

authenticationencryption-decryption-toolsgeneral-purpose-utilities+3
177 months ago
DFSCoerce preview

DFSCoerce

GitHubwh04m1001/dfscoerce

Proof-of-concept tool that coerces Windows authentication via MS-DFSNM NetrDfsRemoveStdRoot and NetrDfsAddStdRoot methods for credential relay…

authenticationexploitationpenetration-testing+1
8514 years ago
MFASweep preview

MFASweep

GitHubdafthack/mfasweep

A tool for checking if MFA is enabled on multiple Microsoft Services

authenticationcloud-securitypenetration-testing+2
1.7k5 months ago
RDPassSpray preview

RDPassSpray

GitHubxfreed0m/rdpassspray

Python3 tool to perform password spraying using RDP

authenticationpassword-attackspenetration-testing+1
6753 years ago
Previous12Next