Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
17 results
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

ctfeducationexploitation+8
3 months ago
createdump preview

createdump

GitHubrweijnen/createdump

Dumps LSASS memory by abusing Microsoft-signed WindowsApp createdump.exe, using a custom dbgcore.dll hook and winlogon impersonation for credential…

impersonation-toolspassword-attackspost-exploitation+1
1491 year ago
chalumeau preview

chalumeau

GitHubcyberstruggle/chalumeau

Automated credential dumping tool with custom PowerShell payloads, in-memory execution, Mimikatz parsing, ticket dumping, and web-based dashboard for…

command-and-controlpassword-attackspayload-development+3
1026 years ago
combine_harvester preview

combine_harvester

GitHubm3f157o/combine_harvester

Rust-based Windows LSASS credential dumper using MiniDumpWriteDump with custom callbacks to bypass EDR; includes GUI, CMD, and decryption modes for…

password-attackspenetration-testingpost-exploitation+1
1093 years ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
6 days ago
WPForce preview

WPForce

GitHubn00py/wpforce

WordPress attack suite with API-based brute-force login, automated shell upload, post-exploitation modules including hash dumping, keylogger, BeEF…

password-attackspayload-generationpenetration-testing+2
9785 years ago
EvilAbigail preview

EvilAbigail

GitHubstrozfriedberg/evilabigail

Automated Linux evil maid attack tool that backdoors initrd images to drop a meterpreter shell and exfiltrate full-disk encryption passwords upon…

exploitationpassword-attackspayload-development+3
43510 years ago
TomcatScanPro preview

TomcatScanPro

GitHublizhianyuguangming/tomcatscanpro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

exploitationpassword-attackspayload-generation+3
2932 months ago
VBA-macro-experiments preview

VBA-macro-experiments

GitHubadepts-of-0xcc/vba-macro-experiments

Collection of VBA macro published in our twitter / blog

adversarial-attackpassword-attackspayload-development+2
1573 years ago
VeeamDumper-BOF preview

VeeamDumper-BOF

GitHubmwr-cybersec/veeamdumper-bof

A credential extraction BOF for Veeam Backup and Replication and Veeam One

password-attackspayload-developmentpenetration-testing+2
791 month ago
KerberosRun preview

KerberosRun

GitHubdev-2null/kerberosrun

C# tool for Kerberos protocol manipulation, enabling ticket requests, delegation (S4U), kerberoasting, AS-REP roasting, and golden/silver ticket…

authenticationexploitationpassword-attacks+5
663 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubvlad-a-man/cve-2023-23397

Proof-of-concept exploit for CVE-2023-23397 that crafts malicious Outlook emails to leak Net-NTLMv2 hashes via UNC path in…

exploitationpassword-attackspayload-generation+3
83 years ago
SMB_CVE-2025-24071 preview

SMB_CVE-2025-24071

GitHubex-cal1bur/smb_cve-2025-24071

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

exploitationpassword-attackspayload-generation+3
31 year ago
CVE-2016-16113-POC preview

CVE-2016-16113-POC

GitHubd3vn0mi/cve-2016-16113-poc

Automated exploit tool combining CVE-2019-17240 authentication bypass and CVE-2019-16113 arbitrary file upload to achieve remote code execution on…

exploitationpassword-attackspayload-generation+4
17 months ago
CVE-2023-6875 preview

CVE-2023-6875

GitHubhatlesswizard/cve-2023-6875

Go-based exploit for CVE-2023-6875 that intercepts admin password reset emails, logs in, and uploads a web shell to the target server.

exploitationpassword-attackspayload-generation+3
12 years ago
Ghost-CMS-Exploit preview

Ghost-CMS-Exploit

GitHubgl1tch0x1/ghost-cms-exploit

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

exploitationpassword-attackspayload-generation+4
1 year ago
CVE-2019-19609-POC-Python preview

CVE-2019-19609-POC-Python

GitHubn000xy/cve-2019-19609-poc-python

Python exploit for CVE-2019-19609 targeting Strapi CMS 3.0.0-beta.17.4. Resets admin password and executes remote commands via JWT token manipulation.

exploitationpassword-attackspayload-generation+3
4 years ago