Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
117 results
RedGhost preview

RedGhost

GitHubd4rk007/redghost

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

command-and-controllateral-movementpayload-generation+5
542
5 years ago
HiveJack preview

HiveJack

GitHubviralmaniar/hivejack

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

lateral-movementpenetration-testingpost-exploitation
1116 years ago
KrbRelayUp preview

KrbRelayUp

GitHubdec0ne/krbrelayup

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

authenticationexploitationimpersonation-tools+4
1.7k4 years ago
pyGPOAbuse preview

pyGPOAbuse

GitHubhackndo/pygpoabuse

Partial python implementation of SharpGPOAbuse

exploitationlateral-movementpenetration-testing+2
5892 months ago
ThievingFox preview

ThievingFox

GitHubslowerzs/thievingfox
lateral-movementpenetration-testingpost-exploitation+1
5712 years ago
DCOMrade preview

DCOMrade

GitHubsud0woodo/dcomrade

Powershell script for enumerating vulnerable DCOM Applications

lateral-movementpenetration-testingpost-exploitation+2
2647 years ago
PowerSploit preview
Archived

PowerSploit

GitHubpowershellmafia/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

lateral-movementpayload-generationpenetration-testing+5
13.1k6 years ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicsinformation-gathering+5
11.0k11 months ago
RedTeam-Tools preview

RedTeam-Tools

GitHuba-poc/redteam-tools

Tools and Techniques for Red Team / Penetration Testing

exploitationlateral-movementosint+7
9.6k4 months ago
eaphammer preview

eaphammer

GitHubs0lst1c3/eaphammer

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

lateral-movementpenetration-testingphishing+4
2.5k1 year ago
PoshC2 preview

PoshC2

GitHubnettitude/poshc2

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

command-and-controllateral-movementpayload-generation+3
2.1k9 months ago
Supershell preview

Supershell

GitHubtdragon6/supershell

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

command-and-controllateral-movementpayload-generation+5
1.8k4 months ago
Invoke-TheHash preview

Invoke-TheHash

GitHubkevin-robertson/invoke-thehash

PowerShell Pass The Hash Utils

authenticationlateral-movementnetwork-security+3
1.8k7 years ago
Internal-Monologue preview

Internal-Monologue

GitHubeladshamir/internal-monologue

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

lateral-movementpassword-attackspenetration-testing+2
1.7k7 years ago
RunasCs preview

RunasCs

GitHubantoniococo/runascs

RunasCs - Csharp and open version of windows builtin runas.exe

impersonation-toolslateral-movementpenetration-testing+3
1.4k2 years ago
fakelogonscreen preview

fakelogonscreen

GitHubbitsadmin/fakelogonscreen

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

password-attacksphishing-toolspost-exploitation+2
1.4k6 years ago
SharpGPOAbuse preview

SharpGPOAbuse

GitHubreverseclabs/sharpgpoabuse

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

exploitationlateral-movementpenetration-testing+4
1.4k5 years ago
Powershell-RAT preview

Powershell-RAT

GitHubviralmaniar/powershell-rat

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

data-exfiltrationeducationpayload-generation+4
1.2k6 years ago
Previous1234567Next