Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
743
5 years ago
DavRelayUp preview

DavRelayUp

GitHubdec0ne/davrelayup

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

authenticationexploitationlateral-movement+2
5783 years ago
DLLHijackHunter preview

DLLHijackHunter

GitHubghostvectoracademy/dllhijackhunter

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

binary-analysisdynamic-code-analysiseducation+8
40620 days ago
CredNinja preview

CredNinja

GitHubraikia/credninja

A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB, plus…

information-gatheringlateral-movementpenetration-testing
4497 years ago
SockTail preview

SockTail

GitHubyeeb1/socktail

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

command-and-controllateral-movementnetwork-security+4
5711 year ago
Farmer preview

Farmer

GitHubmdsecactivebreach/farmer

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

information-gatheringlateral-movementpassword-attacks+4
4295 years ago
Check-LocalAdminHash preview

Check-LocalAdminHash

GitHubdafthack/check-localadminhash

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

information-gatheringlateral-movementpassword-attacks+2
1797 years ago
AddUser-SAMR preview

AddUser-SAMR

GitHubricardojoserf/adduser-samr

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

authenticationidentity-access-managementlateral-movement+5
971 month ago
DLHell preview

DLHell

GitHubsynacktiv/dlhell

Local & remote Windows DLL Proxying

exploitationlateral-movementpayload-development+3
1712 years ago
RAITrigger preview

RAITrigger

GitHubrteccybersec/raitrigger

Local SYSTEM auth trigger for relaying

authenticationexploitationlateral-movement+2
1731 year ago
LACheck preview

LACheck

GitHubmitchmoser/lacheck

Multithreaded C# .NET assembly for enumerating local administrative privileges across Windows hosts via SMB, WMI, and WinRM, with BloodHound…

information-gatheringlateral-movementpenetration-testing+3
935 years ago
CVE-2026-24294 preview

CVE-2026-24294

GitHub0xndi/cve-2026-24294

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

exploitationlateral-movementpenetration-testing+3
595 months ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
2616 days ago
CVE-2026-58635-PoC preview

CVE-2026-58635-PoC

GitHubdavidcarliez/cve-2026-58635-poc

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

binary-exploitationcommand-and-controlexploitation+5
302 months ago
CVE-2024-37726-MSI-Center-Local-Privilege-Escalation preview

CVE-2024-37726-MSI-Center-Local-Privilege-Escalation

GitHubcarsonchan12345/cve-2024-37726-msi-center-local-privilege-escalation

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

binary-exploitationexploitationlateral-movement+4
361 year ago
CVE-2025-50505 preview

CVE-2025-50505

GitHuba0yami/cve-2025-50505

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

command-and-controldns-analysisexploitation+8
200 years ago
FortiLPE preview

FortiLPE

GitHubspaceplant/fortilpe

Local privilege escalation exploit for CVE-2025-62676.

binary-exploitationexploitationlateral-movement+4
47 months ago
CVE-2019-6329 preview

CVE-2019-6329

GitHubmanhndd/cve-2019-6329

Local Privilege Escalation in HP Support Assistant

binary-exploitationexploitationlateral-movement+4
44 years ago
Previous123Next