Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.8k
7 months ago
RomBuster preview

RomBuster

GitHubentysec/rombuster

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

exploitationinformation-gatheringiot-security+1
5632 years ago
wifi_leak preview

wifi_leak

GitHubdybrkr/wifi_leak

Proof-of-concept exploit for CVE-2018-4084, a WiFi credential leak vulnerability in macOS High Sierra, demonstrating interception of plaintext Wi-Fi…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
kerberoast preview

kerberoast

GitHubnidem/kerberoast

Toolkit for attacking MS Kerberos implementations: extract SPN accounts, request and export tickets, crack service passwords, rewrite tickets for…

authenticationexploitationpassword-attacks+1
1.5k3 years ago
mimikatz preview

mimikatz

GitHubparrotsec/mimikatz

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

authenticationexploitationlateral-movement+5
2.7k2 years ago
extractTVpasswords preview

extractTVpasswords

GitHubvah13/extracttvpasswords

tool to extract passwords from TeamViewer memory using Frida

exploitationmemory-forensicspassword-cracking+3
4648 years ago
PXEThief preview

PXEThief

GitHubmwr-cybersec/pxethief

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

exploitationinformation-gatheringpassword-attacks+5
4373 years ago
KslKatzBof preview

KslKatzBof

GitHubprinciplecheck/kslkatzbof

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

exploitationmemory-forensicspayload-development+4
8928 days ago
CVE-2018-14847 preview

CVE-2018-14847

GitHubjas502n/cve-2018-14847

Proof-of-concept exploit for CVE-2018-14847 allowing arbitrary file read of plaintext passwords from MikroTik RouterOS WinBox service, with TCP/IP…

exploitationinformation-gatheringnetwork-security+3
307 years ago
MoxaPass preview

MoxaPass

GitHubreidmefirst/moxapass

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

educationexploitationinformation-gathering+3
389 years ago
kyocera-cve-2022-1026 preview

kyocera-cve-2022-1026

GitHubac3lives/kyocera-cve-2022-1026

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords

data-exfiltrationexploitationinformation-gathering+3
263 years ago
cve-2019-6693 preview

cve-2019-6693

GitHubsaladandonionrings/cve-2019-6693

An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all…

educationencryption-decryption-toolsexploitation+2
302 years ago
NewMachineAccount preview

NewMachineAccount

GitHubdecoder-it/newmachineaccount

Creates Active Directory machine accounts with custom passwords, supporting optional OU placement, explicit credentials, and UAC flag configuration.

exploitationpenetration-testingpost-exploitation+1
401 year ago
bw-dump preview

bw-dump

GitHubmarkuta/bw-dump

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

digital-forensicsexploitationforensics+4
422 years ago
RemotePasswordWiFi preview

RemotePasswordWiFi

GitHubs0c5/remotepasswordwifi

Script in Ruby. Break Remote router wifi passwords.

exploitationinformation-gatheringpassword-attacks+2
149 years ago
TendaSpill preview

TendaSpill

GitHubshaheemirza/tendaspill

An exploitation tool to extract passwords using CVE-2015-5995.

educationexploitationpassword-attacks+3
107 years ago
Grafana-Decryptor-for-CVE-2021-43798 preview

Grafana-Decryptor-for-CVE-2021-43798

GitHubsic4rio/grafana-decryptor-for-cve-2021-43798

Decrypts Grafana DataSource passwords by exploiting CVE-2021-43798 directory traversal to retrieve configuration files and derive encryption keys.

encryption-decryption-toolsexploitationpassword-cracking+3
91 year ago
CVE-2026-19598- preview

CVE-2026-19598-

GitHub0xcyp1337/cve-2026-19598-

Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning…

exploitationpenetration-testingprivilege-escalation+2
226 days ago
Previous1234567Next