Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
15
1 year ago
Stitch preview

Stitch

GitHubnathanlopez/stitch

Python Remote Administration Tool (RAT)

educationpassword-crackingpayload-generation+2
3.7k9 years ago
cromos preview

cromos

GitHubjimywork/cromos

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

command-and-controldata-exfiltrationlateral-movement+5
1248 years ago
Invoke-WCMDump preview

Invoke-WCMDump

GitHubpeewpw/invoke-wcmdump

PowerShell Script to Dump Windows Credentials from the Credential Manager

information-gatheringpassword-crackingpenetration-testing+2
7328 years ago
yellowkey-bitlocker preview

yellowkey-bitlocker

GitHubdesireeontrial76/yellowkey-bitlocker

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

data-recoveryeducationencryption-decryption-tools+2
77h 40m ago
mimikatz preview

mimikatz

GitHubgentilkiwi/mimikatz

A little tool to play with Windows security

authenticationexploitationexploit-frameworks+10
21.9k5 months ago
CacheData_decrypt preview

CacheData_decrypt

GitHubsynacktiv/cachedata_decrypt

A simple Toolkit to BF and decrypt Windows EntraId CacheData

authenticationcryptographydigital-forensics+4
212 years ago
LaZagneForensic preview

LaZagneForensic

GitHubalessandroz/lazagneforensic

Windows passwords decryption from dump files

digital-forensicsencryption-decryption-toolsforensics+1
5153 years ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubrubbxalc/cve-2025-24071

Generates a ZIP file exploiting CVE-2025-24071 to capture netNTLMv2 credentials from Windows Explorer via malicious .library-ms files, intended for…

educationexploitationinformation-gathering+3
11 year ago
go-secdump preview

go-secdump

GitHubjfjallid/go-secdump

Tool to remotely dump secrets from the Windows registry

authenticationencryption-decryption-toolslateral-movement+4
5373 months ago
mscache preview

mscache

GitHubqax-a-team/mscache

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

authenticationpassword-crackingpost-exploitation
678 years ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubabdelrahman0sayed/cve-2025-24071

This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive…

exploitationinformation-gatheringpassword-cracking+4
19 months ago
ZeroLogon-to-Shell preview

ZeroLogon-to-Shell

GitHubc3rrberu5/zerologon-to-shell

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

exploitationpassword-crackingpenetration-testing+3
3 years ago
AutoRDPwn preview

AutoRDPwn

GitHubjoelgmsec/autordpwn

The Shadow Attack Framework

lateral-movementpassword-crackingpayload-generation+5
1.1k4 years ago
CVE-2025-24054 preview

CVE-2025-24054

GitHubuntouchable17/cve-2025-24054

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

exploitationpassword-crackingpayload-generation+4
210 months ago
DarthSidious preview
Archived

DarthSidious

GitHubchryzsh/darthsidious

Building an Active Directory domain and hacking it

defensive-toolseducationexploitation+7
6646 years ago
CVE-2025-24071-PoC preview

CVE-2025-24071-PoC

GitHublooky243/cve-2025-24071-poc

CVE-2025-24071 Proof Of Concept

data-exfiltrationexploitationinformation-gathering+3
31 year ago
CVE-2026-92680 preview

CVE-2026-92680

GitHubgrepstrength/cve-2026-92680

Proof-of-concept decrypting Araxis Merge's DPAPI-protected server credentials (CVE-2026-92680), demonstrating insufficiently protected credential…

cryptographyexploitationpassword-cracking+1
111 days ago
Previous12…8Next