Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
impacket preview

impacket

GitHubfortra/impacket

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

authenticationcommand-and-controlexploitation+8
16.0k
4 days ago
BloodBash preview

BloodBash

GitHubsquidsec/bloodbash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

cloud-securityconfiguration-auditingidentity-access-management+6
4064 days ago
oscp-notes-2026 preview

oscp-notes-2026

GitLabwattocyber/oscp-notes-2026

OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

curated-resourceseducationinformation-gathering+7
5 days ago
AutoPtT preview

AutoPtT

GitHubricardojoserf/autoptt

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, Python and…

authenticationlateral-movementpost-exploitation+1
1556 days ago
AddUser-SAMR preview

AddUser-SAMR

GitHubricardojoserf/adduser-samr

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

authenticationidentity-access-managementlateral-movement+5
966 days ago
aardwolf preview

aardwolf

GitHubskelsec/aardwolf

Asynchronous RDP client for Python (headless)

authenticationinformation-gatheringlateral-movement+5
2387 days ago
NoiseHound preview

NoiseHound

GitHubwarpedatom/noisehound

Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.

adversarial-attackdefensive-toolslateral-movement+4
5311 days ago
PyPsPipeJack preview

PyPsPipeJack

GitHube-fin/pypspipejack

Python implementation of OpenPsPipeJack

lateral-movementpenetration-testingpost-exploitation+3
2013 days ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
10014 days ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

AD AutoPwn v4.10.0 — automated AD attack chain, zero-auth to Domain Admin. Discover/Kerberoast/AS-REP/AD CS ESC1-16/Shadow…

command-and-controlexploitationlateral-movement+7
3815 days ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker
authentication-authorizationcloud-infrastructure-securitycloud-security+7
1717 days ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide
exploitationinformation-gatheringlateral-movement+6
1618 days ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
20824 days ago
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
1 month ago
conquest preview

conquest

GitHubjakobfriedl/conquest

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

command-and-controleducationexploit-frameworks+7
4181 month ago
CVE-2026-13768 preview

CVE-2026-13768

GitHubj4ck3lsyn-gen2/cve-2026-13768

Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices.…

cloud-securitycommand-and-controleducation+9
11 month ago
Neo preview

Neo

GitHubstillbigjosh/neo

The NeoC2 Framework

command-and-controlexploit-frameworksids-ips-evasion+8
351 month ago
harpyTools preview

harpyTools

GitHubjssngc/harpytools
command-and-controlexploitationlateral-movement+6
201 month ago
Previous1234567Next