Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
hacktricks preview

hacktricks

GitHubhacktricks-wiki/hacktricks

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

ctfcurated-resourceseducation+11
12.4k
1 day ago
datasploit preview

datasploit

GitHubdatasploit/datasploit

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

dns-subdomain-enumerationemail-harvestinginformation-gathering+6
3.3k10 months ago
ldapnomnom preview

ldapnomnom

GitHublkarlslund/ldapnomnom

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

authenticationinformation-gatheringpassword-attacks+1
1.1k1 year ago
CVE-2017-2751 preview
Archived

CVE-2017-2751

GitHubbadersz/cve-2017-2751

Mini-paper on CVE-2017-2751, HP EFI password extraction.

educationexploitationfirmware-analysis+3
13 years ago
CamXploit preview

CamXploit

GitHubspyboy-productions/camxploit

Security reconnaissance and assessment tool for identifying potentially exposed IP cameras by analyzing open ports, service configurations, and…

information-gatheringiot-securitynetwork-mapping+4
1.2k8 months ago
CVE-2023-32784-kdbxpassdmp preview

CVE-2023-32784-kdbxpassdmp

GitHubamperclock/cve-2023-32784-kdbxpassdmp

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

digital-forensicsexploitationforensics+3
4 months ago
Cr3dOv3r preview

Cr3dOv3r

GitHubd4vinci/cr3dov3r

Know the dangers of credential reuse attacks.

information-gatheringosintpassword-attacks+1
2.1k9 months ago
nmap-nse-scripts preview

nmap-nse-scripts

GitHubcldrn/nmap-nse-scripts

My collection of nmap NSE scripts

curated-resourceseducationinformation-gathering+5
9944 years ago
Check-LocalAdminHash preview

Check-LocalAdminHash

GitHubdafthack/check-localadminhash

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

information-gatheringlateral-movementpassword-attacks+2
1797 years ago
BlackDir-Framework preview

BlackDir-Framework

GitHubjehadalqurashi/blackdir-framework

Web Application Vulnerability Scanner

encryption-decryption-toolshash-analysisinformation-gathering+5
1376 years ago
weakpass preview

weakpass

GitHubzzzteph/weakpass

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

hash-analysispassword-attackspassword-cracking+1
7401 month ago
SauronEye preview

SauronEye

GitHubvivami/sauroneye

Search tool to find specific files containing specific words, i.e. files containing passwords..

information-gatheringosintpassword-attacks+2
7635 years ago
RTSPbrute preview

RTSPbrute

GitLabwoolf/rtspbrute

Tool for RTSP that brute-forces routes and credentials, makes screenshots!

information-gatheringiot-securitypassword-attacks+1
275 years ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
1 month ago
LsassReflectDumping preview

LsassReflectDumping

GitHuboffensive-panda/lsassreflectdumping

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

memory-forensicspassword-attackspost-exploitation+1
2181 year ago
captaincredz preview

captaincredz

GitHubsynacktiv/captaincredz

CaptainCredz is a modular and discreet password-spraying tool.

authenticationidentity-access-managementpassword-attacks+2
1401 month ago
brutemap preview

brutemap

GitHubbrutemap-dev/brutemap

Let's find someone's account

information-gatheringpassword-attackspenetration-testing+1
1727 years ago
bw-dump preview

bw-dump

GitHubmarkuta/bw-dump

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

digital-forensicsexploitationforensics+4
422 years ago
Previous12Next