Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
215 results
GraphSpy preview

GraphSpy

GitHubredbyte1337/graphspy

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

authenticationcloud-securitydata-exfiltration+6
1.4k
11 days ago
WSASS preview

WSASS

GitHubtwosevenonet/wsass

This is the tool to dump the LSASS process on modern Windows 11

adversarial-attackexploitationpenetration-testing+2
5973 months ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2986 months ago
Crassus preview

Crassus

GitHubvu-ls/crassus

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

binary-analysisexploitationpenetration-testing+1
6327 months ago
snmp-shell preview

snmp-shell

GitHubmxrch/snmp-shell

Shell Simulation over Net-SNMP with extend functionality

command-and-controlexploitationnetwork-security+3
995 years ago
PowerSploit preview
Archived

PowerSploit

GitHubpowershellmafia/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

lateral-movementpayload-generationpenetration-testing+5
13.1k6 years ago
Terminator_Killer preview

Terminator_Killer

GitHubhika-sec/terminator_killer

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

exploitationids-ips-evasionpenetration-testing+3
113 days ago
ActiveReign preview

ActiveReign

GitHubm8sec/activereign

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

command-and-controlexploitationinformation-gathering+2
2462 years ago
KSLDBYOVDARK preview

KSLDBYOVDARK

GitHubanylnk/ksldbyovdark

Exploits a KSLD anti-rootkit driver vulnerability (IOCTL 0x222044) to bypass PPL protection and access sensitive process memory, enabling local…

exploitationpenetration-testingpost-exploitation+3
414 months ago
invoker preview
Archived

invoker

GitHubivan-sincek/invoker

Penetration testing utility and antivirus assessment tool.

binary-analysiseducationexploitation+6
3123 years ago
Firework preview
Archived

Firework

GitHubspiderlabs/firework

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

authenticationcommand-and-controlosint-social-engineering+5
436 years ago
LeakedHandlesFinder preview

LeakedHandlesFinder

GitHublab52io/leakedhandlesfinder

Leaked Windows processes handles identification tool

binary-analysisexploitationpenetration-testing+1
2994 years ago
spraykatz preview

spraykatz

GitHubaas-n/spraykatz

Credentials gathering tool automating remote procdump and parse of lsass process.

information-gatheringlateral-movementpenetration-testing+1
7836 years ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubkernelzeroday/cve-2026-29000

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

authentication-authorizationexploitationpayload-generation+5
96 months ago
nosferatu preview

nosferatu

GitHubkindtime/nosferatu

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

authenticationlateral-movementpenetration-testing+2
2431 year ago
fuxploider preview

fuxploider

GitHubalmandin/fuxploider

File upload vulnerability scanner and exploitation tool.

exploitationpenetration-testingvulnerability-scanners+1
3.3k1 year ago
herpaderping preview

herpaderping

GitHubjxy-s/herpaderping

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

defensive-toolsexploitationpenetration-testing
1.2k3 years ago
nanodump preview

nanodump

GitHubfortra/nanodump

The swiss army knife of LSASS dumping

exploitationmemory-forensicspayload-development+4
2.1k1 year ago
Previous12…12Next