Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
Zydra preview

Zydra

GitHubhameda2/zydra

Multi-threaded password recovery tool for RAR, ZIP, PDF, and Linux shadow files using dictionary and brute-force methods with configurable character…

data-recoverypassword-attackspassword-cracking
4346 years ago
naive-hashcat preview

naive-hashcat

GitHubbrannondorsey/naive-hashcat

Plug-and-play hashcat wrapper that cracks password hashes using preconfigured dictionary, rule-based, combinator, and mask attacks, supporting dozens…

hash-analysispassword-attackspassword-cracking
1.4k8 years ago
fakelogonscreen preview

fakelogonscreen

GitHubbitsadmin/fakelogonscreen

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

password-attacksphishing-toolspost-exploitation+2
1.4k6 years ago
F-Scrack preview

F-Scrack

GitHubysrc/f-scrack

F-Scrack is a single file bruteforcer supports multi-protocol

network-securitypassword-attacks
3089 years ago
Farmer preview

Farmer

GitHubmdsecactivebreach/farmer

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

information-gatheringlateral-movementpassword-attacks+4
4295 years ago
pentest-machine preview

pentest-machine

GitHubdanmcinerney/pentest-machine

Automates some pentest jobs via nmap xml file

information-gatheringnetwork-securitypassword-attacks+3
3258 years ago
nanorobeus preview

nanorobeus

GitHubwavvs/nanorobeus

COFF file (BOF) for managing Kerberos tickets.

authenticationpassword-attackspost-exploitation+1
3263 years ago
secretsdump.py preview

secretsdump.py

GitHubfin3ss3g0d/secretsdump.py

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

data-exfiltrationpassword-attackspenetration-testing+2
2623 years ago
mcafee-sitelist-pwd-decryption preview

mcafee-sitelist-pwd-decryption

GitHubfunoverip/mcafee-sitelist-pwd-decryption

Password decryption tool for the McAfee SiteList.xml file

encryption-decryption-toolsmisconfigurationpassword-attacks+1
1752 years ago
dumpguard_bof preview

dumpguard_bof

GitHub0xedh/dumpguard_bof

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

authenticationexploitationpassword-attacks+3
2229 months ago
cve-2019-2618 preview

cve-2019-2618

GitHubjas502n/cve-2019-2618

Exploit script for CVE-2019-2618, a Weblogic arbitrary file upload vulnerability, with JSP webshell deployment and encrypted credential decryption.

encryption-decryption-toolsexploitationpassword-attacks+3
1737 years ago
Steghide-Brute-Force-Tool preview

Steghide-Brute-Force-Tool

GitHubva5c0/steghide-brute-force-tool

Execute a brute force attack with Steghide to file with hide information and password established

password-attackspenetration-testingsteganography
1239 years ago
ADSyncDump-BOF preview

ADSyncDump-BOF

GitHubparadoxis/adsyncdump-bof

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

cloud-securityencryption-decryption-toolsidentity-access-management+3
1831 year ago
IMAPLoginTester preview

IMAPLoginTester

GitHubrm1984/imaplogintester

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

email-securityinformation-gatheringpassword-attacks+1
732 years ago
Mikrotik-router-hack preview

Mikrotik-router-hack

GitHubhacker30468/mikrotik-router-hack

Proof-of-concept exploit for CVE-2018-14847 (MikroTik WinBox vulnerability) enabling arbitrary file read and plaintext password extraction via TCP/IP…

exploitationinformation-gatheringnetwork-security+3
555 years ago
mssqlbof preview

mssqlbof

GitHubmazx0p/mssqlbof

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

authenticationcommand-and-controldatabase-security+8
1005 months ago
e013 preview

e013

GitHubkeyboard-slayer/e013

VBScript tool that extracts and displays saved Wi-Fi passwords from Windows systems, outputting credentials to a text file for local access.

information-gatheringpassword-attackspost-exploitation+1
275 years ago
aes256_passwd_store preview

aes256_passwd_store

GitHubentry33/aes256_passwd_store

AES-256 encrypted password manager with scrypt/SHA256 key derivation, supporting create, edit, query, and master password change operations with…

cryptographyencryption-decryption-toolspassword-attacks+1
114 years ago
Previous1234Next