Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
CVE-2024-3596-Detector preview

CVE-2024-3596-Detector

GitHubalperenugurlu/cve-2024-3596-detector
authenticationcryptographynetwork-security+3
72 years ago
Seth preview

Seth

GitHubsyss-research/seth

Perform a MitM attack and extract clear text credentials from RDP connections

authenticationeducationexploitation+4
1.5k9 months ago
django-defender preview

django-defender

GitHubjazzband/django-defender

A simple super fast django reusable app that blocks people from brute forcing login attempts

authenticationdefensive-toolspassword-attacks+1
1.1k6 months ago
ADCollector preview

ADCollector

GitHubdev-2null/adcollector

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

authenticationconfiguration-auditinginformation-gathering+4
63810 months ago
ldapnomnom preview

ldapnomnom

GitHublkarlslund/ldapnomnom

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

authenticationinformation-gatheringpassword-attacks+1
1.1k1 year ago
DavRelayUp preview

DavRelayUp

GitHubdec0ne/davrelayup

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

authenticationexploitationlateral-movement+2
5763 years ago
ADCSPwn preview

ADCSPwn

GitHubbats3c/adcspwn

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

authenticationexploitationpenetration-testing+2
8785 years ago
RemotePotato0 preview

RemotePotato0

GitHubantoniococo/remotepotato0

Windows Privilege Escalation from User to Domain Admin.

authenticationexploitationlateral-movement+2
1.5k3 years ago
go-secdump preview

go-secdump

GitHubjfjallid/go-secdump

Tool to remotely dump secrets from the Windows registry

authenticationencryption-decryption-toolslateral-movement+4
5351 month ago
DumpGuard preview

DumpGuard

GitHubbytewreck/dumpguard

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

authenticationexploitationinformation-gathering+6
7323 months ago
SharpSuccessor preview

SharpSuccessor

GitHublogangoins/sharpsuccessor

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

authenticationexploitationidentity-access-management+4
42510 months ago
NTLMRecon preview

NTLMRecon

GitHubpwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

authenticationinformation-gatheringnetwork-security+3
50911 months ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

authenticationcloud-securitydevsecops+3
5015 months ago
Wonka preview

Wonka

GitHubshac0x/wonka

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

authenticationinformation-gatheringpenetration-testing+3
1752 months ago
Krb5RoastParser preview

Krb5RoastParser

GitHubjalvarezz13/krb5roastparser

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

authenticationhash-analysisnetwork-security+3
1091 month ago
dumpguard_bof preview

dumpguard_bof

GitHub0xedh/dumpguard_bof

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

authenticationexploitationpassword-attacks+3
2247 months ago
keypair preview

keypair

GitHubjuliangruber/keypair

Generate a RSA PEM key pair from pure JS

authenticationcryptographyencryption-decryption-tools+2
2763 years ago
Invoke-RunAsWithCert preview

Invoke-RunAsWithCert

GitHubsynacktiv/invoke-runaswithcert

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

authenticationlateral-movementpenetration-testing+2
1782 years ago
Previous1234567Next