Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
fakelogonscreen preview

fakelogonscreen

GitHubbitsadmin/fakelogonscreen

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

password-attacksphishing-toolspost-exploitation+2
1.4k6 years ago
exploits preview

exploits

GitHub0xdea/exploits

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

binary-exploitationdatabase-securityexploitation+3
6759 months ago
cookie_crimes preview

cookie_crimes

GitHubdefaultnamehere/cookie_crimes

Read local Chrome cookies without root or decrypting

information-gatheringpassword-attackspost-exploitation+1
6426 years ago
Farmer preview

Farmer

GitHubmdsecactivebreach/farmer

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

information-gatheringlateral-movementpassword-attacks+4
4295 years ago
Check-LocalAdminHash preview

Check-LocalAdminHash

GitHubdafthack/check-localadminhash

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

information-gatheringlateral-movementpassword-attacks+2
1797 years ago
IPSpinner preview

IPSpinner

GitHubsynacktiv/ipspinner

IPSpinner works as a local proxy that redirects requests through external services.

cloud-securityids-ips-evasionpassword-attacks+3
1251 year ago
adiskreader-secretsdump preview

adiskreader-secretsdump

GitHubskelsec/adiskreader-secretsdump

Extract registry and NTDS secrets from local or remote disk images

digital-forensicsincident-responsepassword-attacks+3
451 year ago
e013 preview

e013

GitHubkeyboard-slayer/e013

VBScript tool that extracts and displays saved Wi-Fi passwords from Windows systems, outputting credentials to a text file for local access.

information-gatheringpassword-attackspost-exploitation+1
255 years ago
CVE-2024-24488 preview

CVE-2024-24488

GitHublegacyobj/cve-2024-24488

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

embedded-systems-securityexploitationhardware-iot-security+3
52 years ago
LFI-Destruction preview

LFI-Destruction

GitHubrevshellxd/lfi-destruction

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

ctfeducationexploitation+8
47 months ago
CVE-2022-42176 preview

CVE-2022-42176

GitHubsoy-oreocato/cve-2022-42176

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

authenticationexploitationmisconfiguration+3
12 years ago
CVE-2024-56429 preview

CVE-2024-56429

GitHublisa-2905/cve-2024-56429

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

database-securityexploitationpassword-attacks+2
1 year ago
CVE-2021-27187 preview

CVE-2021-27187

GitHubjet-pentest/cve-2021-27187

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

data-exfiltrationexploitationinformation-gathering+3
5 years ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicshash-analysis+8
11.0k1 year ago
Xenotix-Python-Keylogger preview

Xenotix-Python-Keylogger

GitHubajinabraham/xenotix-python-keylogger

Xenotix Python Keylogger for Windows.

data-exfiltrationpassword-attackspayload-development+3
4637 years ago
Outpacket preview

Outpacket

GitHubn00py/outpacket

This cheatsheet maps common impacket workflows to their modern alternatives

authenticationcurated-resourceseducation+6
3064 months ago
combine_harvester preview

combine_harvester

GitHubm3f157o/combine_harvester

Rust in-memory dumper

password-attackspenetration-testingpost-exploitation+1
1093 years ago
Windows-Privilege-Escalation-Notes preview

Windows-Privilege-Escalation-Notes

GitHubsaisathvik1/windows-privilege-escalation-notes

My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJ…

ctfeducationexploitation+5
584 years ago
Previous12Next