Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
242 results
pyGPOAbuse preview

pyGPOAbuse

GitHubhackndo/pygpoabuse

Partial python implementation of SharpGPOAbuse

exploitationlateral-movementpenetration-testing+2
595
3 months ago
impersonate preview

impersonate

GitHubsensepost/impersonate

A windows token impersonation tool

adversarial-attackimpersonation-toolslateral-movement+3
3293 years ago
AutoPtT preview

AutoPtT

GitHubricardojoserf/autoptt

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust, Golang, Nim…

authenticationlateral-movementpost-exploitation+1
15523 days ago
BADministration preview

BADministration

GitHubthundergunexpress/badministration

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

command-and-controlexploitationinformation-gathering+6
1287 years ago
CPLDCOMTrigger preview

CPLDCOMTrigger

GitHubklsecservices/cpldcomtrigger

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

exploitationlateral-movementpenetration-testing+2
488 months ago
SAPKiln preview

SAPKiln

GitHubowasp/sapkiln

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

configuration-auditinglateral-movementosint+3
303 years ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

exploitationinformation-gatheringlateral-movement+6
161 month ago
UltraRealy_with_CVE-2019-1040 preview

UltraRealy_with_CVE-2019-1040

GitHublazaars/ultrarealy_with_cve-2019-1040

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

authenticationcommand-and-controlexploitation+7
207 years ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubjiushill/cve-2020-1472

Python exploit for CVE-2020-1472 (Zerologon) targeting Netlogon authentication bypass to escalate privileges and compromise Active Directory domain…

exploitationlateral-movementpenetration-testing+2
16 years ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubitssmikefm/cve-2020-1472

Python exploit for CVE-2020-1472 (Zerologon) targeting Netlogon authentication to compromise Active Directory domain controllers and escalate…

exploitationlateral-movementpenetration-testing+2
5 years ago
macro_pack preview
Archived

macro_pack

GitHubsevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exploit-frameworkslateral-movementpayload-generation+6
2.3k2 years ago
hermes preview
Archived

hermes

GitHub0xbbuddha/hermes

A Python agent targeting Linux for Mythic C2

command-and-controlencryption-decryption-toolslateral-movement+6
186 months ago
certipy-merged preview
Archived

certipy-merged

GitHubzimedev/certipy-merged

Tool for Active Directory Certificate Services enumeration and abuse

authenticationcryptographyexploitation+7
1671 year ago
eaphammer preview

eaphammer

GitHubs0lst1c3/eaphammer

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

lateral-movementpenetration-testingphishing+4
2.6k2 years ago
ATTPwn preview

ATTPwn

GitHubtelefonica/attpwn

ATTPwn

adversarial-attacklateral-movementpenetration-testing+3
2205 years ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
2401 month ago
keimpx preview

keimpx

GitHubnccgroup/keimpx

Check for valid credentials across a network over SMB

lateral-movementpenetration-testingpost-exploitation
2685 years ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
Previous123…14Next