Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
361 results
nysm preview

nysm

GitHubeeriedusk/nysm

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

container-securitypost-exploitationred-teaming
2681 year ago
Invoke-RunAsWithCert preview

Invoke-RunAsWithCert

GitHubsynacktiv/invoke-runaswithcert

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

authenticationlateral-movementpenetration-testing+2
1782 years ago
REC2 preview

REC2

GitHubg0h4n/rec2

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

command-and-controlpayload-developmentpenetration-testing+3
1622 years ago
ADCSDevilCOM preview

ADCSDevilCOM

GitHub7hepr0fess0r/adcsdevilcom

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

authentication-authorizationexploitationpayload-generation+5
1689 months ago
SCOMDecrypt preview

SCOMDecrypt

GitHubnccgroup/scomdecrypt

SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers

encryption-decryption-toolspassword-attackspenetration-testing+2
1302 years ago
JavaPayload preview

JavaPayload

GitHubschierlm/javapayload

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

exploitationmisconfigurationpayload-development+3
1271 year ago
vba2clr preview

vba2clr

GitHubmed0x2e/vba2clr

Running .NET from VBA

adversarial-attackpayload-developmentpost-exploitation+2
1473 years ago
asminject preview

asminject

GitHubbishopfox/asminject

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

container-escapepayload-developmentpenetration-testing+2
1483 years ago
pupy preview

pupy

GitHubalessandroz/pupy

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

command-and-controldata-exfiltrationlateral-movement+7
918 years ago
BackupOperatorToolkit preview

BackupOperatorToolkit

GitHubimprosec/backupoperatortoolkit

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

lateral-movementpenetration-testingpost-exploitation+1
1803 years ago
RawHive preview

RawHive

GitHubnmht3t/rawhive

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data…

digital-forensicsdisk-forensicsexploitation+4
932 months ago
get_Team_Pass preview

get_Team_Pass

GitHubkr1shn4murt1/get_team_pass

Get teamviewer's ID and password from a remote computer in the LAN

information-gatheringpenetration-testingpost-exploitation+1
1356 years ago
CmdLineSpoofer preview

CmdLineSpoofer

GitHubplackyhacker/cmdlinespoofer

How to spoof the command line when spawning a new process from C#.

command-and-controleducationexploitation+5
1124 years ago
EtwSessionHijacking preview

EtwSessionHijacking

GitHubnul0x4c/etwsessionhijacking

A Poc on blocking Procmon from monitoring network events

adversarial-attackids-ips-evasionpost-exploitation+1
1121 year ago
HiveJack preview

HiveJack

GitHubviralmaniar/hivejack

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

lateral-movementpenetration-testingpost-exploitation
1116 years ago
gpg_reaper preview

gpg_reaper

GitHubkacperszurek/gpg_reaper

GPG Reaper - Obtain/Steal/Restore GPG Private Keys from gpg-agent cache/memory

exploitationmemory-forensicspenetration-testing+1
968 years ago
KslKatzBof preview

KslKatzBof

GitHubprinciplecheck/kslkatzbof

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

exploitationmemory-forensicspayload-development+4
884 months ago
unhook-bof preview

unhook-bof

GitHubcobalt-strike/unhook-bof

Remove API hooks from a Beacon process.

ids-ips-evasionpayload-developmentpenetration-testing-frameworks+2
774 years ago
Previous1…456…21Next