Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
184 results
DavRelayUp preview

DavRelayUp

GitHubdec0ne/davrelayup

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

authenticationexploitationlateral-movement+2
577
3 years ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
1945 days ago
PowerPriv preview

PowerPriv

GitHubg0ldengunsec/powerpriv

A Powershell implementation of PrivExchange designed to run under the current user's context

authenticationexploitationlateral-movement+2
1257 years ago
RpcProxyInvoke preview

RpcProxyInvoke

GitHubklezvirus/rpcproxyinvoke

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

binary-exploitationcommand-and-controlexploitation+8
1382 years ago
MSSQL-Analysis-Coerce preview

MSSQL-Analysis-Coerce

GitHubp0dalirius/mssql-analysis-coerce

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

adversarial-attackexploitationlateral-movement+3
1322 years ago
poc-proxycommand-vulnerable preview

poc-proxycommand-vulnerable

GitHubvin01/poc-proxycommand-vulnerable

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

command-and-controlexploitationlateral-movement+3
502 years ago
LocalPotato_CVE-2023-21746 preview

LocalPotato_CVE-2023-21746

GitHubmuhammad-ali007/localpotato_cve-2023-21746

Proof-of-concept exploit for Windows local privilege escalation (CVE-2023-21746) abusing NTLM local authentication to gain SYSTEM privileges via SMB…

binary-exploitationexploitationlateral-movement+5
33 years ago
CVE-2025-47962-POC preview

CVE-2025-47962-POC

GitHubq1uf3ng/cve-2025-47962-poc

Proof-of-concept for CVE-2025-47962 demonstrating local privilege escalation via DLL hijacking in Windows IpOverUsbSvc service due to insecure…

binary-exploitationexploitationlateral-movement+2
48 months ago
CVE-2026-54424 preview

CVE-2026-54424

GitHubtomadimitrie/cve-2026-54424

Exploiting Parsec for Windows to gain SYSTEM privileges

binary-exploitationcommand-and-controlexploitation+5
2 months ago
CVE-2020-25265-25266 preview

CVE-2020-25265-25266

GitHubrefi64/cve-2020-25265-25266

Proof-of-concept exploit demonstrating CVE-2020-25265 and CVE-2020-25266, using a crafted MP3 file to achieve arbitrary code execution via…

binary-exploitationexploitationlateral-movement+3
25 years ago
CVE-Vulnerability-Research-Exploit-Analysis preview

CVE-Vulnerability-Research-Exploit-Analysis

GitHubadk86/cve-vulnerability-research-exploit-analysis

Researched and executed real-world CVE exploits in a controlled sandbox: CVE-2000-0168 DoS on Windows 95, ARP Spoofing with NTLMv2 credential…

educationexploitationnetwork-security+3
5 months ago
CVE-2015-1769 preview

CVE-2015-1769

GitHubint0/cve-2015-1769

Proof-of-concept exploit for CVE-2015-1769 using a crafted VHD file and symbolic link to trigger a Windows privilege escalation via Mount Manager.

binary-exploitationexploitationlateral-movement+2
15 years ago
CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient preview

CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient

GitHubhagrid29/cve-2024-40586-windows-coerced-authentication-in-forticlient

Exploit for CVE-2024-40586: coerces Windows hosts to authenticate via a vulnerable FortiClient named pipe, enabling privilege escalation to SYSTEM or…

authenticationexploitationlateral-movement+4
11 year ago
CVE-2025-47810 preview

CVE-2025-47810

GitHubptrstr/cve-2025-47810

PunkBuster LPI to NT AUTHORITY\SYSTEM

binary-analysisexploitationlateral-movement+2
1 year ago
CVE-2020-27955 preview

CVE-2020-27955

GitHubz50913/cve-2020-27955

Proof-of-concept exploit for CVE-2020-27955 in Git-LFS, demonstrating remote code execution via a crafted git clone operation to obtain a reverse…

command-and-controlexploitationlateral-movement+3
3 years ago
CVE-2024-32002 preview

CVE-2024-32002

GitHubcharlesgargasson/cve-2024-32002

Exploit for CVE-2024-32002, a Git RCE vulnerability that uses recursive submodule cloning and symlinks to execute arbitrary commands on Windows and…

command-and-controlexploitationlateral-movement+6
2 years ago
krbrelayx preview

krbrelayx

GitHubdirkjanm/krbrelayx

Kerberos relaying and unconstrained delegation abuse toolkit

authenticationexploitationlateral-movement+3
1.7k6 months ago
NetNTLMtoSilverTicket preview

NetNTLMtoSilverTicket

GitHubnotmedic/netntlmtosilverticket

SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket

authenticationexploitationlateral-movement+5
9825 years ago
Previous1…678…11Next