Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
impersonate preview

impersonate

GitHubsensepost/impersonate

Windows token impersonation tool to list tokens, execute commands as impersonated users, and add domain admin users during Active Directory pentests.

adversarial-attackimpersonation-toolslateral-movement+3
329
3 years ago
MakeMeEnterpriseAdmin preview

MakeMeEnterpriseAdmin

GitHubal1ex/makemeenterpriseadmin

Automated Active Directory privilege escalation tool using DCSync to extract krbtgt hash and forge a golden ticket for enterprise admin access.

exploitationlateral-movementpayload-generation+3
25 years ago
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
25 years ago
CVE-2022-26923 preview

CVE-2022-26923

GitHubeliasdekiniweek/cve-2022-26923

Automated exploitation of CVE-2022-26923 (Certifried) for privilege escalation via AD CS abuse, RBCD, and Kerberos ticket extraction to dump NTLM…

authenticationeducationexploitation+6
16 months ago
Find-AdminAccess preview

Find-AdminAccess

GitHublsecqt/find-adminaccess

This C# tool sprays for admin access over the entire domain

information-gatheringlateral-movementnetwork-mapping+4
908 months ago
oxide_hive preview

oxide_hive

GitHubchron1k/oxide_hive

Rust-based exploit for CVE-2021-36934 (HiveNightmare) that dumps SAM, SECURITY, and SYSTEM registry hives from shadow copies for privilege escalation…

exploitationlateral-movementpassword-cracking+3
34 years ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
3816 days ago
CVE-2019-1040 preview

CVE-2019-1040

GitHubridter/cve-2019-1040

Python exploit for CVE-2019-1040 that abuses Exchange and relay vulnerabilities to achieve RCE and Domain Admin, with options for credential dumping…

exploitationlateral-movementpenetration-testing+2
2505 years ago
CVE-2019-1040-dcpwn preview

CVE-2019-1040-dcpwn

GitHubridter/cve-2019-1040-dcpwn

Python tool exploiting CVE-2019-1040 to perform Kerberos delegation attacks, enabling relay attacks for RCE and domain admin compromise.

authenticationcommand-and-controlexploitation+5
336 years ago
Exchange2domain preview

Exchange2domain

GitHubridter/exchange2domain

Automated tool to exploit CVE-2018-8581 (PrivExchange) to escalate privileges from Exchange to Domain Admin via NTLM relay, with options for DCSync…

exploitationlateral-movementpenetration-testing+4
3693 years ago
BloodHound-Legacy preview

BloodHound-Legacy

GitHubspecterops/bloodhound-legacy

Graph-based tool that maps hidden relationships and attack paths in Active Directory environments to identify and quantify privilege escalation…

information-gatheringlateral-movementpenetration-testing+4
10.6k5 months ago
CredNinja preview

CredNinja

GitHubraikia/credninja

A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB, plus…

information-gatheringlateral-movementpenetration-testing
4484 years ago
SharpSCCM preview

SharpSCCM

GitHubmayyhem/sharpsccm

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

authenticationlateral-movementnetwork-security+3
7044 months ago
Invoke-SessionHunter preview

Invoke-SessionHunter

GitHubleo4j/invoke-sessionhunter

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

information-gatheringlateral-movementpenetration-testing+2
2112 years ago
BackupOperatorToolkit preview

BackupOperatorToolkit

GitHubimprosec/backupoperatortoolkit

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

lateral-movementpenetration-testingpost-exploitation+1
1803 years ago
RemotePotato0 preview

RemotePotato0

GitHubantoniococo/remotepotato0

Windows Privilege Escalation from User to Domain Admin.

authenticationexploitationlateral-movement+2
1.5k3 years ago