Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
jarm preview

jarm

GitHubsalesforce/jarm

Active TLS server fingerprinting tool that sends crafted Client Hello packets to generate unique JARM hashes for identifying server configurations,…

information-gatheringnetwork-securityreconnaissance+1
1.3k
1 month ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

exploitationinformation-gatheringlateral-movement+6
162 months ago
Krb5RoastParser preview

Krb5RoastParser

GitHubjalvarezz13/krb5roastparser

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

authenticationhash-analysisnetwork-security+3
1151 month ago
Email-exploit-Moniker-Link-CVE-2024-21413- preview

Email-exploit-Moniker-Link-CVE-2024-21413-

GitHubyass2400012/email-exploit-moniker-link-cve-2024-21413-

Proof-of-concept exploit for CVE-2024-21413 using Moniker Link in HTML email to trigger SMB connection and capture netNTLMv2 hashes via Responder.…

educationemail-securityexploitation+6
1 year ago
Shreder preview

Shreder

GitHubentysec/shreder

Shreder is a powerful multi-threaded SSH protocol password brute-force tool.

network-securitypassword-attackspassword-cracking
2192 years ago
NTLMRawUnHide preview

NTLMRawUnHide

GitHubmlgualtieri/ntlmrawunhide

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

forensicsinformation-gatheringnetwork-security+2
3932 years ago
PCredz preview

PCredz

GitHublgandx/pcredz

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

forensicsinformation-gatheringnetwork-security+3
2.6k7 months ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
1 month ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysishash-analysis+6
3.9k1 year ago
ncrack preview

ncrack

GitHubnmap/ncrack

Ncrack network authentication tool

authenticationhash-analysisnetwork-security+3
1.2k4 years ago
mtpass preview

mtpass

GitHubmanio/mtpass

MikroTik Password Recovery Tool

network-securitypassword-attackspassword-cracking+1
2912 years ago
shadowhammer preview

shadowhammer

GitHubwithsecurelabs/shadowhammer

Batch-mode checker for Shadowhammer malware indicators, scanning local or provided MAC addresses against known malicious hashes, with offline support…

defensive-toolsincident-responsemalware-analysis+2
87 years ago
CVE-2024-21754-Forti-RCE preview

CVE-2024-21754-Forti-RCE

GitHubcybersecuritist/cve-2024-21754-forti-rce

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

exploitationnetwork-securitypassword-cracking+2
22 years ago
CVE-2023-36144 preview

CVE-2023-36144

GitHubleonardobg/cve-2023-36144

Proof-of-concept exploit for CVE-2023-36144 demonstrating unauthenticated backup file download on Intelbras SG 2404 MR L2+ switch, exposing device…

exploitationinformation-gatheringmisconfiguration+3
13 years ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubf4dee-backup/cve-2025-24071

Exploit script for CVE-2025-24071 that leaks NTLM hashes from Windows by extracting a crafted ZIP/RAR file, exploiting .library-ms file handling.…

data-exfiltrationexploitationnetwork-security+2
1 year ago
net-creds preview

net-creds

GitHubdanmcinerney/net-creds

Sniffs sensitive data from interface or pcap

information-gatheringnetwork-securitypacket-sniffing-analysis+1
1.9k6 years ago
Exploiting-a-vulnerability-using-reverse-shell preview

Exploiting-a-vulnerability-using-reverse-shell

GitHubdampedcoast/exploiting-a-vulnerability-using-reverse-shell

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

ctfeducationexploitation+5
3 months ago
impostor preview

impostor

GitHublcky00/impostor

SMB1 server for NTLMv2 hash interception, written in C.

educationexploitationnetwork-security+3
61 month ago
Previous12Next