Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
Get-NetNTLM preview

Get-NetNTLM

GitHubelnerd/get-netntlm

Powershell module to get the NetNTLMv2 hash of the current user

hash-analysisinformation-gatheringpassword-attacks+4
974 years ago
DeadMatter preview

DeadMatter

GitHubqsecure-labs/deadmatter

Offset Independent Credential Extraction Tool

data-recoverydigital-forensicsforensics+7
691 year ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubz3rodayhacks/cve-2026-63030-cve-2026-60137

Pre-auth RCE proof-of-concept chaining a WordPress REST batch API auth bypass with WP_Query SQL injection to dump hashes, add admin users, or plant a…

exploitationpayload-developmentpenetration-testing+6
2 months ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
1 month ago
DPAPISnoop preview

DPAPISnoop

GitHubleftp/dpapisnoop

A C# tool to output crackable DPAPI hashes from user MasterKeys

hash-analysispassword-attackspassword-cracking+2
1463 months ago
HashDump-BypassEDR preview

HashDump-BypassEDR

GitHubaabysszg/hashdump-bypassedr

Windows绕过EDR实现DumpHash

hash-analysisids-ips-evasionpassword-attacks+3
2652 months ago
Invoke-DCSync preview

Invoke-DCSync

GitHubal1ex/invoke-dcsync

Invoke-DCSync

exploitationlateral-movementpassword-attacks+3
16 years ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

exploitationinformation-gatheringlateral-movement+6
162 months ago
internal-penetration-testing-project-using-Metasploit preview

internal-penetration-testing-project-using-Metasploit

GitHubabdullah50i/internal-penetration-testing-project-using-metasploit

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

exploitationexploit-frameworksinformation-gathering+6
2 months ago
cve-2020-1472 preview

cve-2020-1472

GitHubmstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

exploitationpassword-crackingpenetration-testing+3
1136 years ago
Domain-Controller-DC-Exploitation-with-Metasploit-Impacket preview

Domain-Controller-DC-Exploitation-with-Metasploit-Impacket

GitHubnyambiblaise/domain-controller-dc-exploitation-with-metasploit-impacket

End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes,…

educationexploit-frameworkslabs-practice+6
11 months ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubnaxg/cve-2020-1472

CVE-2020-1472复现流程

exploitationpassword-crackingpenetration-testing+3
45 years ago
Why-so-Serious-SAM preview

Why-so-Serious-SAM

GitHubp1rat3r00t/why-so-serious-sam

PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

ctfeducationexploitation+6
1 year ago
vss-fr2system preview

vss-fr2system

GitHubsailay1996/vss-fr2system

test

exploitationpassword-crackingpenetration-testing+4
1075 months ago
CVE-2020-1472-Easy preview

CVE-2020-1472-Easy

GitHubmidpipps/cve-2020-1472-easy

A simple implementation/code smash of a bunch of other repos

exploitationpassword-crackingpenetration-testing+3
16 years ago
dumpguard_bof preview

dumpguard_bof

GitHub0xedh/dumpguard_bof

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

authenticationexploitationpassword-attacks+3
2219 months ago
silph preview

silph

GitHubalmounah/silph

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

authenticationmemory-forensicspassword-cracking+3
1679 months ago
ZeroLogon-to-Shell preview

ZeroLogon-to-Shell

GitHubc3rrberu5/zerologon-to-shell

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

exploitationpassword-crackingpenetration-testing+3
3 years ago
Previous12Next