Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
CVE-2019-19633 preview

CVE-2019-19633

GitHubjra89/cve-2019-19633

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

ids-ips-evasioninformation-gatheringpassword-attacks+2
6 years ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicshash-analysis+8
11.0k11 months ago
odat preview

odat

GitHubquentinhardy/odat

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

command-and-controldatabase-securityexploitation+4
1.8k4 months ago
Wordpress-XMLRPC-Brute-Force-Exploit preview

Wordpress-XMLRPC-Brute-Force-Exploit

GitHub1n3/wordpress-xmlrpc-brute-force-exploit

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

exploitationinformation-gatheringpassword-attacks+3
4981 year ago
PXEThief preview

PXEThief

GitHubmwr-cybersec/pxethief

Toolset for extracting credentials from Microsoft ConfigMgr/SCCM Operating System Deployment via PXE boot attacks, including password cracking,…

exploitationinformation-gatheringpassword-attacks+5
4342 years ago
kraken preview

kraken

GitHubarcaneiceman/kraken

Distributed brute-force password cracking system that parallelizes dictionary and crunch-based attacks across multiple machines via web and desktop…

password-attackspassword-cracking
3323 years ago
ntdissector preview

ntdissector

GitHubsynacktiv/ntdissector

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

digital-forensicsencryption-decryption-toolsinformation-gathering+1
1824 months ago
secretsdump.py preview

secretsdump.py

GitHubfin3ss3g0d/secretsdump.py

Multithreaded Windows secret-dumping utility that pulls NTDS.dit, SAM, and SYSTEM hives from many hosts using Impacket-based remote access.

data-exfiltrationpassword-attackspenetration-testing+2
2593 years ago
Dagon preview

Dagon

GitHubekultek/dagon

Advanced hash cracking and manipulation system supporting bruteforce attacks, dictionary generation, automatic hash algorithm verification, and…

hash-analysispassword-attackspassword-cracking
1778 years ago
SCOMDecrypt preview

SCOMDecrypt

GitHubnccgroup/scomdecrypt

Decrypt RunAs credentials from Microsoft System Center Operations Manager (SCOM) servers for post-exploitation and red team operations.

encryption-decryption-toolspassword-attackspenetration-testing+2
1302 years ago
CVE-2023-43261 preview

CVE-2023-43261

GitHubwin3zz/cve-2023-43261

Proof-of-concept exploit for CVE-2023-43261 targeting Milesight industrial routers. Demonstrates credential leakage via unprotected system logs and…

exploitationiot-securitymisconfiguration+3
572 years ago
wildlogger preview

wildlogger

GitHubmustafadalga/wildlogger

This is a keylogger that collects all the data and e-mail it in a set time with system information which includes device S/N and hardware specs,…

data-exfiltrationinformation-gatheringpassword-attacks+1
4510 months ago
SkyRAT preview

SkyRAT

GitHubyschgroup/skyrat

PowerShell-based remote administration tool (RAT) with keylogging, remote shell, and file management capabilities for covert system control.

command-and-controldata-exfiltrationlateral-movement+5
348 years ago
witchcraft preview

witchcraft

GitHubcosmic-zip/witchcraft

Modular cybersecurity toolkit for OSINT, forensics, network scanning, and penetration testing with an automation engine, plugin system, and modules…

bluetooth-securityforensicsnetwork-mapping+8
521 year ago
CVE-2024-39211 preview

CVE-2024-39211

GitHubartemy-ccrsky/cve-2024-39211

User Enumeration vulnerability in Kaiten (workflow management system)

information-gatheringosintpassword-attacks+3
71 year ago
CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated preview

CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated

GitHubh4md153v63n/cve-2022-40032_simple-task-managing-system-v1.0-sql-injection-vulnerability-unauthenticated

Unauthenticated SQL injection exploit for Simple Task Managing System 1.0, targeting login and password parameters to dump database contents via…

database-securityexploitationpassword-attacks+3
52 years ago
Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets- preview

Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-

GitHubartemcyberlab/project-project-chimera-exploiting-a-modern-wordpress-xxe-to-pillage-secrets-

Demonstrates a complete WordPress attack chain exploiting CVE-2021-29447 (XXE) to achieve remote code execution, database compromise, and full system…

educationexploitationinformation-gathering+8
11 year ago
CVE-2022-31890 preview

CVE-2022-31890

GitHubreewardius/cve-2022-31890

Python-based exploit for CVE-2022-31890 in osTicket support ticketing system, enabling credential dumping via nickname and password enumeration…

exploitationinformation-gatheringpassword-attacks+2
3 years ago
Previous123Next