Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
57 results
pivotool preview

pivotool

GitHubartusec/pivotool

Bash-based post-exploitation tool for semi-automated network pivoting, enabling lateral movement through compromised systems during penetration tests.

lateral-movementpenetration-testingpost-exploitation+1
9
4 years ago
SharpWebServer preview

SharpWebServer

GitHubmgeeky/sharpwebserver

Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality

lateral-movementred-teaming
2883 years ago
ICMPTunnel preview

ICMPTunnel

GitHubal1ex/icmptunnel

icmptunnel

data-exfiltrationids-ips-evasionlateral-movement+3
26 years ago
PortForwarder preview

PortForwarder

GitHublsecqt/portforwarder

TCP Port Forwarding Utility on C

general-purpose-utilitiesids-ips-evasionlateral-movement+4
413 months ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubdr4g0n23/cve-2020-1472

Exploit script for CVE-2020-1472 (ZeroLogon) with automated privilege escalation, credential dumping via secretsdump, and lateral movement using…

exploitationlateral-movementpenetration-testing+3
3 years ago
pivotnacci preview

pivotnacci

GitHubblackarrowsec/pivotnacci

A tool to make socks connections through HTTP agents

lateral-movementpenetration-testingred-teaming+1
7255 years ago
WMEye preview

WMEye

GitHubpwn1sher/wmeye

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

lateral-movementpayload-generationpost-exploitation+1
3734 years ago
ThievingFox preview

ThievingFox

GitHubslowerzs/thievingfox

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

lateral-movementpenetration-testingpost-exploitation+1
5702 years ago
SharpWSUS preview

SharpWSUS

GitHubnettitude/sharpwsus

C# tool for lateral movement through WSUS by creating, approving, and deploying malicious updates to target Windows clients in Active Directory…

lateral-movementpenetration-testingred-teaming
5044 years ago
SharpToken preview

SharpToken

GitHubbeichendream/sharptoken

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

lateral-movementpost-exploitationprivilege-escalation+1
4952 years ago
PowershellKerberos preview

PowershellKerberos

GitHubmzhmo/powershellkerberos

Some scripts to abuse kerberos using Powershell

authenticationimpersonation-toolslateral-movement+3
3675 months ago
GhostTask preview

GhostTask

GitHubnetero1010/ghosttask

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

lateral-movementpersistence-mechanismsprivilege-escalation+1
6401 year ago
LiquidSnake preview

LiquidSnake

GitHubriccardoancarani/liquidsnake

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

lateral-movementpayload-generationred-teaming+1
3505 years ago
impersonate preview

impersonate

GitHubsensepost/impersonate

A windows token impersonation tool

adversarial-attackimpersonation-toolslateral-movement+3
3303 years ago
SharpNamedPipePTH preview

SharpNamedPipePTH

GitHubs3cur3th1ssh1t/sharpnamedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+5
3074 years ago
DragonCastle preview

DragonCastle

GitHubmdsecactivebreach/dragoncastle

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

lateral-movementpassword-crackingpost-exploitation
3073 years ago
NamedPipePTH preview

NamedPipePTH

GitHubs3cur3th1ssh1t/namedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+4
1465 years ago
BackupOperatorToolkit preview

BackupOperatorToolkit

GitHubimprosec/backupoperatortoolkit

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

lateral-movementpenetration-testingpost-exploitation+1
1803 years ago
Previous1234Next