Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
ridenum preview

ridenum

GitHubtrustedsec/ridenum

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

authenticationinformation-gatheringnetwork-security+3
3176 years ago
CrackMapExecWin preview

CrackMapExecWin

GitHubmaaaaz/crackmapexecwin

The great CrackMapExec tool compiled for Windows

authenticationinformation-gatheringlateral-movement+4
26710 years ago
Wonka preview

Wonka

GitHubshac0x/wonka

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

authenticationinformation-gatheringpenetration-testing+3
1753 months ago
Carnivore preview

Carnivore

GitHubnccgroup/carnivore

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

authenticationinformation-gatheringpenetration-testing+1
1505 years ago
gssapi-abuse preview

gssapi-abuse

GitHubccob/gssapi-abuse

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

authenticationdns-analysisinformation-gathering+5
1891 year ago
AADOutsider-py preview

AADOutsider-py

GitHubsynacktiv/aadoutsider-py

Python3 rewrite of AsOutsider features of AADInternals

authenticationcloud-securitydns-analysis+7
6419 days ago
MITM6-Kerberos-CNAME-Abuse preview

MITM6-Kerberos-CNAME-Abuse

GitHubbenzamir/mitm6-kerberos-cname-abuse

Kerberos CNAME abuse PoC

authenticationcommand-and-controldns-analysis+5
1108 months ago
LDAPPER preview

LDAPPER

GitHubshellster/ldapper

LDAP Querying without the Suck

authenticationinformation-gatheringpassword-attacks+3
1161 year ago
NTLMRecon preview

NTLMRecon

GitHubpraetorian-inc/ntlmrecon

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.

authenticationinformation-gatheringpenetration-testing+2
1166 months ago
wpCrack preview

wpCrack

GitHubm4dm0e/wpcrack

wordpress hash cracker .

authenticationinformation-gatheringpassword-cracking+2
655 years ago
BloodHound.py-Kerberos preview

BloodHound.py-Kerberos

GitHubjazzpizazz/bloodhound.py-kerberos

A Python based ingestor for BloodHound

authenticationinformation-gatheringpenetration-testing+2
854 years ago
iDictPy preview

iDictPy

GitHubpilfer/idictpy

A salty-ass 100% verified hacker status python script to turn apple id's into apple crisp #nicememe

authenticationinformation-gatheringosint+3
436 years ago
sopa preview

sopa

GitHubmacmod/sopa

A practical client for ADWS in Golang.

authenticationinformation-gatheringpenetration-testing+3
562 months ago
adfly preview

adfly

GitHubzux0x3a/adfly

active directory query tool using LDAP Protocol , helps red teamer / penetration testers to validate users credentials , retrieve information about…

authenticationinformation-gatheringpenetration-testing
126 years ago
CVE-2023-2982-POC preview

CVE-2023-2982-POC

GitHubh4k6/cve-2023-2982-poc

WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证

authenticationcrawleremail-harvesting+3
93 years ago
nlahoney preview

nlahoney

GitHubnccgroup/nlahoney

NLA Honeypot Associated Research

authenticationinformation-gatheringnetwork-security+3
105 years ago
wpbf preview

wpbf

GitHubdejanlevaja/wpbf

WPBF - a multithreaded WP brute forcer

authenticationinformation-gatheringpassword-attacks+2
512 years ago
pritunl-CVE-2020-25200 preview

pritunl-CVE-2020-25200

GitHublukaszstu/pritunl-cve-2020-25200

Exploit for CVE-2020-25200: enumerates valid Pritunl VPN usernames by analyzing HTTP response code changes after repeated login attempts.

authenticationinformation-gatheringpenetration-testing+3
46 years ago
Previous12345Next