Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
158 results
smbclient-ng preview

smbclient-ng

GitHubp0dalirius/smbclient-ng

smbclient-ng, a fast and user friendly way to interact with SMB shares.

authenticationinformation-gatheringnetwork-security+2
1.0k
1 month ago
SQLRecon preview

SQLRecon

GitHubskahwah/sqlrecon

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

authenticationdatabase-securityexploitation+5
8152 months ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
4065 days ago
ldapnomnom preview

ldapnomnom

GitHublkarlslund/ldapnomnom

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

authenticationinformation-gatheringpassword-attacks+1
1.1k1 year ago
MSSqlPwner preview

MSSqlPwner

GitHubscorpioneslabs/mssqlpwner
authenticationdatabase-securityexploitation+5
4607 days ago
Go365 preview

Go365

GitHuboptiv/go365

An Office365 User Attack Tool

authenticationinformation-gatheringpassword-attacks+1
6514 years ago
ad-ldap-enum preview

ad-ldap-enum

GitHubcrowecybersecurity/ad-ldap-enum

An LDAP based Active Directory user and group enumeration tool

authenticationinformation-gatheringpenetration-testing+1
3133 months ago
DumpGuard preview

DumpGuard

GitHubbytewreck/dumpguard

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

authenticationexploitationinformation-gathering+6
7323 months ago
ZackAttack preview

ZackAttack

GitHuburbanesec/zackattack

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

authenticationexploitationinformation-gathering+6
26210 years ago
aardwolf preview

aardwolf

GitHubskelsec/aardwolf

Asynchronous RDP client for Python (headless)

authenticationinformation-gatheringlateral-movement+5
2387 days ago
smartbrute preview

smartbrute

GitHubshutdownrepo/smartbrute

Password spraying and bruteforcing tool for Active Directory Domain Services

authenticationinformation-gatheringpassword-attacks+1
3881 year ago
msldap preview

msldap

GitHubskelsec/msldap

Python library for auditing Microsoft Active Directory via LDAP, supporting NTLM, Kerberos, SSPI authentication, channel binding, encryption, and…

authenticationinformation-gatheringpenetration-testing+1
4986 months ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3058 years ago
NTLMRecon preview

NTLMRecon

GitHubpwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

authenticationinformation-gatheringnetwork-security+3
50911 months ago
kerberoast preview

kerberoast

GitHubskelsec/kerberoast

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

authenticationexploitationinformation-gathering+2
4332 years ago
brutus preview

brutus

GitHubpraetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

authenticationexploitationinformation-gathering+7
31116 hours ago
ridenum preview

ridenum

GitHubtrustedsec/ridenum

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

authenticationinformation-gatheringnetwork-security+3
3156 years ago
AzureRT preview

AzureRT

GitHubmgeeky/azurert

AzureRT - A Powershell module implementing various Azure Red Team tactics

authenticationcloud-securityinformation-gathering+5
2334 years ago
Previous123…9Next