Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
DonPAPI preview

DonPAPI

GitHublogin-securite/donpapi

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

authenticationinformation-gatheringpassword-cracking+3
1.4k
12 days ago
CS-Remote-OPs-BOF preview

CS-Remote-OPs-BOF

GitHubtrustedsec/cs-remote-ops-bof

Remote operations commands implemented using Beacon Object Files

authenticationencryption-decryption-toolslateral-movement+6
1.2k2 months ago
ForgeCert preview

ForgeCert

GitHubghostpack/forgecert

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

authenticationexploitationpayload-generation+1
7133 years ago
Krb5RoastParser preview

Krb5RoastParser

GitHubjalvarezz13/krb5roastparser

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

authenticationhash-analysisnetwork-security+3
11129 days ago
GlobalUnProtect preview

GlobalUnProtect

GitHubrotarydrone/globalunprotect

Decrypt GlobalProtect configuration and cookie files.

authenticationdigital-forensicsencryption-decryption-tools+5
1622 years ago
SharePointDumper preview

SharePointDumper

GitHubzh54321/sharepointdumper

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

authenticationcloud-securitydata-exfiltration+7
1917 months ago
TokenMan preview

TokenMan

GitHubsecureworks/tokenman

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

authenticationcloud-securityinformation-gathering+2
1033 years ago
AzTokenFinder preview

AzTokenFinder

GitHubhackmichnet/aztokenfinder

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

authenticationcloud-securitymemory-forensics+3
1093 years ago
pivit preview

pivit

GitHubcashapp/pivit

Manage x509 certificates on PIV-enabled YubiKeys, generate keys and certificate requests, and sign or verify git commits and files.

authenticationcryptographyhardware-security
1003 months ago
PyADRecon preview

PyADRecon

GitHubl4rm4nd/pyadrecon

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

authenticationinformation-gatheringpenetration-testing+4
682 months ago
authkeysync preview

authkeysync

GitHubeduardolat/authkeysync

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

authenticationauthentication-authorizationcloud-infrastructure-security+3
289 months ago
secure-vault-for-commercial preview

secure-vault-for-commercial

GitHubkeerthivasan-sankar/secure-vault-for-commercial

secure vault for your files

authenticationcryptographydata-recovery+3
31 day ago
CVE-2023-47504-POC preview

CVE-2023-47504-POC

GitHubdavidxbors/cve-2023-47504-poc

Proof-of-concept exploit for CVE-2023-47504 targeting Elementor WordPress plugin. Requires subscriber credentials and wp-config.php access to delete…

authenticationexploitationpenetration-testing+2
12 years ago
CVE-2024-4040 preview

CVE-2024-4040

GitHubmufti22/cve-2024-4040

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote…

authenticationexploitationpenetration-testing+3
2 years ago
Firework preview
Archived

Firework

GitHubspiderlabs/firework

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

authenticationcommand-and-controlosint-social-engineering+5
436 years ago
keeweb preview

keeweb

GitHubkeeweb/keeweb

Free cross-platform password manager compatible with KeePass

authenticationencryption-decryption-toolsgeneral-purpose-utilities+1
13.0k4 months ago
OpenSC preview

OpenSC

GitHubopensc/opensc

Open source smart card tools and middleware. PKCS#11/MiniDriver

authenticationcryptographyencryption-decryption-tools+2
3.1k12 days ago
filekey preview

filekey

GitHubrockwellshah/filekey

Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

authenticationcryptographydata-recovery+2
4831 month ago
Previous12Next