Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
44 results
hmac-bcrypt preview

hmac-bcrypt

GitHubepixoip/hmac-bcrypt

The hmac-bcrypt password hashing function

authenticationcryptographydefensive-tools+1
661 year ago
lil-pwny preview

lil-pwny

GitHubpapermtn/lil-pwny

Fast offline auditing of Active Directory passwords using Python.

authenticationpassword-crackingvulnerability-analysis
1672 years ago
kerberoast preview

kerberoast

GitHubnidem/kerberoast

Toolkit for attacking MS Kerberos implementations: extract SPN accounts, request and export tickets, crack service passwords, rewrite tickets for…

authenticationexploitationpassword-attacks+1
1.5k3 years ago
mimikatz preview

mimikatz

GitHubparrotsec/mimikatz

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

authenticationexploitationlateral-movement+5
2.7k2 years ago
otp-bot preview

otp-bot

GitHuboriyomi12/otp-bot

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

authenticationimpersonation-toolspenetration-testing+3
3792 years ago
LDAP-Password-Hunter preview

LDAP-Password-Hunter

GitHuboldboy21/ldap-password-hunter

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

authenticationdatabase-securityinformation-gathering+1
1983 years ago
Teamsniper preview

Teamsniper

GitHubxret2pwn/teamsniper

Teamsniper is a tool for fetching keywords in a Microsoft Teams such as (passwords, emails, database, etc.).

authenticationdata-exfiltrationinformation-gathering+2
1994 years ago
Locky preview

Locky

GitHubs0md3v/locky

Locky generates "really" strong yet easy to remember passwords.

authenticationencryption-decryption-toolsgeneral-purpose-utilities+1
717 years ago
Invoke-CleverSpray preview

Invoke-CleverSpray

GitHubwavestone-cdt/invoke-cleverspray

Password Spraying Script detecting current and previous passwords of Active Directory User

authenticationpassword-attackspenetration-testing
657 years ago
pmanager preview

pmanager

GitHubyukselberkay/pmanager

Store and retrieve your passwords from a secure offline database. Check if your passwords has leaked previously to prevent targeted password reuse…

authenticationcryptographyencryption-decryption-tools+1
343 years ago
cisco7crack preview

cisco7crack

GitHubmadrisan/cisco7crack

Crypt and decrypt the cisco enable 7 passwords

authenticationencryption-decryption-toolsnetwork-security+2
1513 years ago
passgen preview

passgen

GitHubbilalbaraz/passgen

Generate passwords from the terminal

authenticationencryption-decryption-toolsgeneral-purpose-utilities+2
27 months ago
CTT-enhanced-Apache-mod_auth_digest-timing-attack-exploit preview

CTT-enhanced-Apache-mod_auth_digest-timing-attack-exploit

GitHubsimoesctt/ctt-enhanced-apache-mod_auth_digest-timing-attack-exploit

Remote timing attack exploit for Apache mod_auth_digest (CVE-2026-33006) that bypasses Digest authentication via a 33-layer temporal cascade,…

authenticationexploitationpenetration-testing+3
4 months ago
CVE-2025-58434-PoC preview

CVE-2025-58434-PoC

GitHubvincent-vbg/cve-2025-58434-poc

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

authenticationexploitationpassword-attacks+3
4 months ago
latch-plugin-openVPN-AS preview

latch-plugin-openVPN-AS

GitHubelevenpaths/latch-plugin-openvpn-as

Latch plugin for OpenVPN Access Server enabling two-factor authentication (2FA) to secure VPN connections with time-based one-time passwords (TOTP).

authenticationauthentication-authorizationcloud-security+2
112 years ago
cve-2022-31749 preview

cve-2022-31749

GitHubiveresk/cve-2022-31749

PoC checker for CVE-2022-31749 exploiting a parameter injection vulnerability in WatchGuard SSH interface to exfiltrate hashed user passwords via FTP.

authenticationdata-exfiltrationexploitation+3
14 years ago
CVE-2023-26984 preview

CVE-2023-26984

GitHubbypazs/cve-2023-26984

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted…

authenticationpenetration-testingprivilege-escalation+2
3 years ago
CVE-2021-3130 preview

CVE-2021-3130

GitHubjet-pentest/cve-2021-3130

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

authenticationmisconfigurationpenetration-testing+2
5 years ago
Previous123Next