Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
56 results
SharpNoPSExec preview

SharpNoPSExec

GitHubjuliourena/sharpnopsexec

Get file less command execution for lateral movement.

lateral-movementpenetration-testingpost-exploitation+1
641
4 years ago
SpawnWith preview

SpawnWith

GitHubrasta-mouse/spawnwith

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

command-and-controlimpersonation-toolslateral-movement+2
1131 year ago
Py-RDP-Patcher preview

Py-RDP-Patcher

GitHubsp00kyskelet0n/py-rdp-patcher

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

lateral-movementpenetration-testingremote-access-tool
65 years ago
GTFOBLookup preview

GTFOBLookup

GitHubnccgroup/gtfoblookup

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

information-gatheringlateral-movementpenetration-testing+3
2913 years ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubkagancapar/cve-2022-29072

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

binary-exploitationcommand-and-controlexploitation+5
6724 years ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

exploitationinformation-gatheringlateral-movement+6
161 month ago
maalik preview
Archived

maalik

GitHubquantumcore/maalik

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

command-and-controlexploitationlateral-movement+6
935 years ago
CPLDCOMTrigger preview

CPLDCOMTrigger

GitHubklsecservices/cpldcomtrigger

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

exploitationlateral-movementpenetration-testing+2
488 months ago
PowerSploit preview
Archived

PowerSploit

GitHubpowershellmafia/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

lateral-movementpayload-generationpenetration-testing+5
13.1k6 years ago
CVE-2020-11652 preview

CVE-2020-11652

GitHubal1ex/cve-2020-11652

Exploit for SaltStack CVEs (CVE-2020-11651/11652) enabling remote command execution on master/minions, file read/upload, and reverse shell.

command-and-controlexploitationlateral-movement+3
65 years ago
CVE-2025-33053_PoC preview

CVE-2025-33053_PoC

GitHub4n4s4zi/cve-2025-33053_poc

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

command-and-controlexploitationlateral-movement+3
11 year ago
CVE-2017-8464-EXP preview

CVE-2017-8464-EXP

GitHubxssfile/cve-2017-8464-exp

Exploit for CVE-2017-8464 LNK remote code execution vulnerability. Generates malicious .lnk files for USB-based payload delivery, supporting x86 and…

exploitationlateral-movementpayload-generation+3
18 years ago
SetupHijack preview

SetupHijack

GitHubhackerhouse-opensource/setuphijack

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

exploitationlateral-movementpayload-generation+3
2677 months ago
CPLDCOMTrigger preview

CPLDCOMTrigger

GitHubsud0ru/cpldcomtrigger

CPL remote trigger

exploitationlateral-movementpenetration-testing+1
448 months ago
Medusa preview

Medusa

GitHubmythicagents/medusa

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

command-and-controlexploit-frameworkslateral-movement+8
2101 month ago
CVE-2026-54424 preview

CVE-2026-54424

GitHubtomadimitrie/cve-2026-54424

Exploiting Parsec for Windows to gain SYSTEM privileges

binary-exploitationcommand-and-controlexploitation+5
2 months ago
SSH-Private-Key-Looting-Wordlists preview

SSH-Private-Key-Looting-Wordlists

GitHubpinoywh1z/ssh-private-key-looting-wordlists

Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

lateral-movementpassword-crackingpenetration-testing
562 years ago
SigFlip preview

SigFlip

GitHubmed0x2e/sigflip

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

binary-analysiscode-analysisdefensive-tools+5
1.3k3 years ago
Previous1234Next