Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
607 results
thanatos preview

thanatos

GitHubmythicagents/thanatos

Mythic C2 agent targeting Linux and Windows hosts written in Rust

penetration-testing-frameworksexploit-frameworkslateral-movement+4
408
11 months ago
SharpGPOAbuse preview

SharpGPOAbuse

GitHubreverseclabs/sharpgpoabuse

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

privilege-escalationpersistence-mechanismsexploitation+4
1.4k5 years ago
TChopper preview

TChopper

GitHubzux0x3a/tchopper

conduct lateral movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine

lateral-movementpenetration-testingred-teaming
565 years ago
Invoke-SessionHunter preview

Invoke-SessionHunter

GitHubleo4j/invoke-sessionhunter

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

reconnaissancelateral-movementinformation-gathering+2
2112 years ago
SharpADWS preview

SharpADWS

GitHubwh0amitz/sharpadws

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

privilege-escalationreconnaissancepersistence-mechanisms+6
6022 years ago
SharpToken preview

SharpToken

GitHubbeichendream/sharptoken

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

privilege-escalationlateral-movementpost-exploitation+1
4962 years ago
PersistAssist preview

PersistAssist

GitHubredsiege/persistassist

Fully modular persistence framework

penetration-testing-frameworksprivilege-escalationpersistence-mechanisms+7
2603 years ago
CrucibleC2 preview

CrucibleC2

GitHubdragoqcc/cruciblec2

A C# Command & Control framework

privilege-escalationexploit-frameworkspayload-generation+5
1.0k2 years ago
RemoteKeyStrokes preview

RemoteKeyStrokes

GitHubu53rw4r3/remotekeystrokes

A script to automate keystrokes through a graphical desktop program.

privilege-escalationpayload-generationpersistence-mechanisms+5
351 year ago
CIMplant preview

CIMplant

GitHubredsiege/cimplant

C# port of WMImplant which uses either CIM or WMI to query remote systems

lateral-movementinformation-gatheringpost-exploitation+4
2045 years ago
OffensiveNim preview

OffensiveNim

GitHubbyt3bl33d3r/offensivenim

My experiments in weaponizing Nim (https://nim-lang.org/)

privilege-escalationcode-analysislateral-movement+8
3.1k2 years ago
DavRelayUp preview

DavRelayUp

GitHubdec0ne/davrelayup

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

privilege-escalationexploitationlateral-movement+2
5753 years ago
evilrdp preview

evilrdp

GitHubskelsec/evilrdp

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

lateral-movementpost-exploitationpenetration-testing+3
3091 year ago
SSH-Private-Key-Looting-Wordlists preview

SSH-Private-Key-Looting-Wordlists

GitHubpinoywh1z/ssh-private-key-looting-wordlists

Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

password-crackinglateral-movementpenetration-testing
562 years ago
MultiDump preview

MultiDump

GitHubxre0us/multidump

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

privilege-escalationencryption-decryption-toolsmemory-forensics+4
5419 months ago
GhostTask preview

GhostTask

GitHubnetero1010/ghosttask

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

privilege-escalationpersistence-mechanismslateral-movement+1
6351 year ago
MSSqlPwner preview

MSSqlPwner

GitHubscorpioneslabs/mssqlpwner
password-attacksexploitationlateral-movement+5
4587 days ago
AD_Miner preview

AD_Miner

GitHubad-security/ad_miner

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

privilege-escalationreconnaissancevulnerability-analysis+6
1.6k5 months ago
Previous1…293031…34Next