Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
331 results
ingressnightmare-detection-poc preview

ingressnightmare-detection-poc

GitHubm-q-t/ingressnightmare-detection-poc

Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.

cloud-securityexploitationmisconfiguration+3
1 year ago
Certify preview

Certify

GitHubghostpack/certify

C# tool for enumerating and exploiting misconfigurations in Active Directory Certificate Services (AD CS), enabling certificate template abuse,…

authentication-authorizationexploitationpenetration-testing+3
2.0k1 month ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubbvcyber/cve-2020-1472

Python script using Impacket to test for CVE-2020-1472 (Zerologon) vulnerability via Netlogon authentication bypass on Windows domain controllers.

exploitationpenetration-testingvulnerability-analysis
1.8k1 year ago
PoC preview

PoC

GitHubmcw0/poc

Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.

binary-exploitationembedded-systems-securityexploitation+5
7823 years ago
ForgeCert preview

ForgeCert

GitHubghostpack/forgecert

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

authenticationexploitationpayload-generation+1
7133 years ago
SharpMapExec preview

SharpMapExec

GitHubcube0x0/sharpmapexec

Windows-native penetration testing swiss army knife for lateral movement, credential access, data exfiltration, and vulnerability scanning across…

authenticationdata-exfiltrationexploitation+9
6684 years ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
2013 hours ago
cve-2019-1040-scanner preview

cve-2019-1040-scanner

GitHubfox-it/cve-2019-1040-scanner

SMB vulnerability scanner that detects CVE-2019-1040 by sending invalid NTLM authentication packets, enabling MIC Remove relay attacks for domain…

authenticationexploitationnetwork-security+2
3006 years ago
DonPwner preview

DonPwner

GitHubmordavid/donpwner

Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database

educationexploitationinformation-gathering+4
26610 months ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubuziii2208/cve-2025-33073

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.

ctfexploitationexploit-frameworks+4
6710 months ago
badsuccessor preview

badsuccessor

GitHubcybrly/badsuccessor

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

adversarial-attackexploitationinformation-gathering+7
1211 year ago
CVE-2019-6467 preview

CVE-2019-6467

GitHubknqyf263/cve-2019-6467

Dockerized proof-of-concept exploit for CVE-2019-6467, a BIND nxdomain-redirect vulnerability, enabling DNS cache poisoning via non-existent domain…

dns-analysiseducationexploitation+2
267 years ago
CVE-2026-41089-Netlogon-RCE preview

CVE-2026-41089-Netlogon-RCE

GitHubhydrasoft/cve-2026-41089-netlogon-rce

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows…

educationexploitationincident-response+4
161 month ago
Zero-Logon-Exploit preview

Zero-Logon-Exploit

GitHubsq00ky/zero-logon-exploit

Python script exploiting Zerologon (CVE-2020-1472) to perform Netlogon authentication bypass and reset domain controller password to null.

exploitationexploit-frameworkspayload-development+2
383 years ago
kyocera-cve-2022-1026 preview

kyocera-cve-2022-1026

GitHubac3lives/kyocera-cve-2022-1026

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords

data-exfiltrationexploitationinformation-gathering+3
263 years ago
CVE-2020-3580 preview

CVE-2020-3580

GitHubadarshvs/cve-2020-3580

Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.

exploitationinformation-gatheringpenetration-testing+3
195 years ago
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
58 days ago
zeroscan preview

zeroscan

GitHubb34mr/zeroscan

Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.

exploitationnetwork-securitypenetration-testing+2
114 years ago
Previous1234…19Next