Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
95 results
awesome-privacy preview

awesome-privacy

GitHubpluja/awesome-privacy

Awesome Privacy - A curated list of services and alternatives that respect your privacy because PRIVACY MATTERS.

curated-resourceseducationencryption-decryption-tools+5
19.6k
1 month ago
cupp preview

cupp

GitHubmebus/cupp

Interactive password profiler that generates targeted wordlists by gathering personal details about a user, used for penetration testing and forensic…

information-gatheringosintpassword-attacks+1
6.5k1 month ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicsinformation-gathering+5
11.0k11 months ago
EvilnoVNC preview

EvilnoVNC

GitHubjoelgmsec/evilnovnc

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

information-gatheringpassword-crackingphishing+3
1.2k1 year ago
emploleaks preview

emploleaks

GitHubinfobyte/emploleaks

An OSINT tool that helps detect members of a company with leaked credentials

data-exfiltrationemail-harvestinginformation-gathering+8
7873 months ago
ADenum preview

ADenum

GitHubsecuproject/adenum

AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with kerberos.

misconfigurationpassword-crackingpenetration-testing
3183 years ago
creddump7 preview

creddump7

GitHubciscocxsecurity/creddump7

Offline Windows credential extractor that dumps LM/NT hashes, cached domain passwords, and LSA secrets from registry hives without relying on system…

forensicspassword-cracking
4125 years ago
DragonCastle preview

DragonCastle

GitHubmdsecactivebreach/dragoncastle

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

lateral-movementpassword-crackingpost-exploitation
3063 years ago
kraken preview

kraken

GitHubarcaneiceman/kraken

Distributed brute-force password cracking system that parallelizes dictionary and crunch-based attacks across multiple machines via web and desktop…

password-attackspassword-cracking
3323 years ago
Chrome-Extractor preview

Chrome-Extractor

GitHubd4vinci/chrome-extractor

Python script that will extract all saved passwords from your google chrome database on windows only

data-exfiltrationdigital-forensicsforensics+2
8710 years ago
prefetch-hash-cracker preview

prefetch-hash-cracker

GitHubharelsegev/prefetch-hash-cracker

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

digital-forensicsforensicsincident-response+1
784 years ago
tiandy-research preview

tiandy-research

GitHubzb3/tiandy-research

This repository contains the results of my August 2020 research of Tiandy's IPC/NVR firmware. I found two vulnerabilities that could be used to…

authenticationembedded-systems-securityexploitation+7
305 years ago
bw-dump preview

bw-dump

GitHubmarkuta/bw-dump

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

digital-forensicsexploitationforensics+4
422 years ago
CVE-2025-24071_PoC preview

CVE-2025-24071_PoC

GitHubmarcejr117/cve-2025-24071_poc

A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes

exploitationinformation-gatheringpassword-cracking+2
251 year ago
lama preview

lama

GitHubtatam/lama

Lama, the application that does not mache these words.

information-gatheringpassword-attackspassword-cracking
237 years ago
VSHG preview

VSHG

GitHubflothesysadmin/vshg

Shell script addon for GnuPG that strengthens symmetric encryption with Argon2 memory-hard KDF, SHA-384 iterations, and cascaded AES-256/CAST5…

cryptographyencryption-decryption-toolspassword-cracking
177 years ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
SSI-CVE-2022-21661 preview

SSI-CVE-2022-21661

GitHubwellingtonespindula/ssi-cve-2022-21661

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

educationexploitationlabs-practice+3
62 years ago
Previous123456Next