Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
361 results
SharpStartWebclient preview

SharpStartWebclient

GitHubeversinc33/sharpstartwebclient

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

lateral-movementpenetration-testingpost-exploitation+2
80
3 years ago
zig-pe preview

zig-pe

GitHubthoxy67/zig-pe

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

binary-exploitationexploitationpayload-development+3
675 months ago
BackupCreds preview

BackupCreds

GitHubleftp/backupcreds

A C# implementation of dumping credentials from Windows Credential Manager

impersonation-toolspassword-attackspenetration-testing+2
642 years ago
TeamViewer-dumper-in-CPP preview

TeamViewer-dumper-in-CPP

GitHubkkar/teamviewer-dumper-in-cpp

Dumps TeamViewer ID,Password and account settings from a running TeamViewer instance by enumerating child windows.

information-gatheringpassword-attackspost-exploitation+2
4511 years ago
GeckoDroid preview

GeckoDroid

GitHubblacksnufkin/geckodroid

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

android-securitycommand-and-controlmobile-security+4
385 months ago
kcmdump preview

kcmdump

GitHubsynacktiv/kcmdump

Dump Kerberos tickets from the KCM database of SSSD

authenticationlateral-movementpenetration-testing+2
597 months ago
adiskreader-secretsdump preview

adiskreader-secretsdump

GitHubskelsec/adiskreader-secretsdump

Extract registry and NTDS secrets from local or remote disk images

digital-forensicsincident-responsepassword-attacks+3
451 year ago
e013 preview

e013

GitHubkeyboard-slayer/e013

VBScript tool that extracts and displays saved Wi-Fi passwords from Windows systems, outputting credentials to a text file for local access.

information-gatheringpassword-attackspost-exploitation+1
275 years ago
appinfo-standalone preview

appinfo-standalone

GitHubredcivet/appinfo-standalone

method 59 from UACME in a standalone .C

exploitationpenetration-testingpost-exploitation+2
204 months ago
CVE-2025-7771-Vulnerability-Exploration preview

CVE-2025-7771-Vulnerability-Exploration

GitHubd4rkks/cve-2025-7771-vulnerability-exploration

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

binary-exploitationeducationexploitation+4
134 months ago
wp2exp-2026 preview

wp2exp-2026

GitHubrechandra/wp2exp-2026

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030…

exploit-frameworkspayload-developmentpenetration-testing+5
516 days ago
Metasploit-CVE-2026-54121-Certighost preview

Metasploit-CVE-2026-54121-Certighost

GitHubnafiez/metasploit-cve-2026-54121-certighost

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase"…

exploitationexploit-frameworkspenetration-testing+3
421 days ago
ml-kem-key-recovery preview

ml-kem-key-recovery

GitHub007bsd/ml-kem-key-recovery

Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)

binary-analysiscryptographyexploitation+3
5 days ago
Triple_Fetch-Kernel-Creds preview

Triple_Fetch-Kernel-Creds

GitHubjosephshenton/triple_fetch-kernel-creds

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

exploitationexploit-frameworksios-security+3
79 years ago
CVE-2026-58424 preview

CVE-2026-58424

GitHubbridgeralderson/cve-2026-58424

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

authentication-authorizationexploitationpayload-development+4
219 days ago
Exploiting-Samba-on-Metasploitable-2 preview

Exploiting-Samba-on-Metasploitable-2

GitHubvig9610/exploiting-samba-on-metasploitable-2

Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a…

educationexploitationexploit-frameworks+8
5 months ago
pentest-metasploitable2 preview

pentest-metasploitable2

GitHubemilebarnard242/pentest-metasploitable2

A documented penetration testing lab built on Kali Linux and Metasploitable2, walking through a full attack chain from network traffic analysis and…

educationexploitationlabs-practice+6
4 months ago
Optimum preview

Optimum

GitHubr3fr4kt/optimum

Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain…

educationexploitationinformation-gathering+7
5 months ago
Previous1…567…21Next