Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
Sharp-SMBExec preview

Sharp-SMBExec

GitHubcheckymander/sharp-smbexec

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

authenticationexploitationlateral-movement+1
216
6 years ago
CVE-2019-12476 preview

CVE-2019-12476

GitHub0katz/cve-2019-12476

PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted…

authenticationexploitationpenetration-testing+2
436 years ago
DonPAPI preview

DonPAPI

GitHublogin-securite/donpapi

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

authenticationinformation-gatheringpassword-cracking+3
1.4k23 days ago
MSOLSpray preview

MSOLSpray

GitHubdafthack/msolspray

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a…

authenticationcloud-securityinformation-gathering+3
1.1k3 years ago
silph preview

silph

GitHubalmounah/silph

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

authenticationmemory-forensicspassword-cracking+3
1679 months ago
msspray preview
Archived

msspray

GitHubsecurityriskadvisors/msspray

Password attacks and MFA validation against various endpoints in Azure and Office 365

authenticationcloud-securityidentity-access-management+3
1523 years ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysishash-analysis+6
3.9k1 year ago
CVE-2026-11387-WooCommerce-SMS-OTP preview

CVE-2026-11387-WooCommerce-SMS-OTP

GitHubabraxas/cve-2026-11387-woocommerce-sms-otp

SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation…

authenticationexploitationpenetration-testing+4
414 days ago
poisontap preview

poisontap

GitHubsamyk/poisontap

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

authenticationcommand-and-controldata-exfiltration+7
6.5k7 years ago
Zimbra-Valid-Login-Checker preview

Zimbra-Valid-Login-Checker

GitHubjenderal92/zimbra-valid-login-checker

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

authenticationpassword-attackspenetration-testing+2
14 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
4 months ago
CVE-2026-71205-PoC preview

CVE-2026-71205-PoC

GitHubnel-droid/cve-2026-71205-poc

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

authenticationexploitationpassword-attacks+4
1 month ago
CVE-2025-10658 preview

CVE-2025-10658

GitHubjfriedli/cve-2025-10658

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

authenticationexploitationpassword-attacks+3
16 months ago
legba preview

legba

GitHubevilsocket/legba

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷

authenticationinformation-gatheringpassword-attacks+2
1.9k1 month ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
o365spray preview

o365spray

GitHub0xzdh/o365spray

Username enumeration and password spraying tool aimed at Microsoft O365.

authenticationcloud-securityinformation-gathering+2
1.1k2 years ago
Spray preview

Spray

GitHubgreenwolf/spray

A Password Spraying tool for Active Directory Credentials by Jacob Wilkin(Greenwolf)

authenticationinformation-gatheringpassword-attacks+1
7692 years ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
41317 days ago
Previous123Next