Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
KeePwn preview

KeePwn

GitHuborange-cyberdefense/keepwn

A python tool to automate KeePass discovery and secret extraction.

exploitationpassword-crackingpost-exploitation+1
5311 year ago
silph preview

silph

GitHubalmounah/silph

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

authenticationmemory-forensicspassword-cracking+3
1679 months ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

exploitationinformation-gatheringlateral-movement+6
162 months ago
redsnarf preview

redsnarf

GitHubnccgroup/redsnarf

RedSnarf is a pen-testing / red-teaming tool for Windows environments

command-and-controlexploitationhash-analysis+9
1.2k9 years ago
DPAPISnoop preview

DPAPISnoop

GitHubleftp/dpapisnoop

A C# tool to output crackable DPAPI hashes from user MasterKeys

hash-analysispassword-attackspassword-cracking+2
1463 months ago
go-secdump preview

go-secdump

GitHubjfjallid/go-secdump

Tool to remotely dump secrets from the Windows registry

authenticationencryption-decryption-toolslateral-movement+4
5373 months ago
Internal-Monologue preview

Internal-Monologue

GitHubeladshamir/internal-monologue

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

lateral-movementpassword-attackspenetration-testing+2
1.7k7 years ago
DeadMatter preview

DeadMatter

GitHubqsecure-labs/deadmatter

Offset Independent Credential Extraction Tool

data-recoverydigital-forensicsforensics+7
691 year ago
mscache preview

mscache

GitHubqax-a-team/mscache

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

authenticationpassword-crackingpost-exploitation
678 years ago
osx-password-dumper preview

osx-password-dumper

GitHubjeanpeyremesmots/osx-password-dumper

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

ctfpassword-crackingpenetration-testing+2
531 year ago
DragonCastle preview

DragonCastle

GitHubmdsecactivebreach/dragoncastle

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

lateral-movementpassword-crackingpost-exploitation
3073 years ago
ZeroLogon-to-Shell preview

ZeroLogon-to-Shell

GitHubc3rrberu5/zerologon-to-shell

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

exploitationpassword-crackingpenetration-testing+3
3 years ago
cve-2020-1472_Tool-collection preview

cve-2020-1472_Tool-collection

GitHub0xcccc666/cve-2020-1472_tool-collection

cve-2020-1472_Tool collection

exploitationpassword-crackingpenetration-testing+3
26 years ago
sshLooter preview
Archived

sshLooter

GitHubmthbernardes/sshlooter

Script to steal passwords from ssh.

password-crackingpersistence-mechanismspost-exploitation+2
4887 years ago
Invoke-DCSync preview

Invoke-DCSync

GitHubal1ex/invoke-dcsync

Invoke-DCSync

exploitationlateral-movementpassword-attacks+3
16 years ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubz3rodayhacks/cve-2026-63030-cve-2026-60137

Pre-auth RCE proof-of-concept chaining a WordPress REST batch API auth bypass with WP_Query SQL injection to dump hashes, add admin users, or plant a…

exploitationpayload-developmentpenetration-testing+6
2 months ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
internal-penetration-testing-project-using-Metasploit preview

internal-penetration-testing-project-using-Metasploit

GitHubabdullah50i/internal-penetration-testing-project-using-metasploit

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

exploitationexploit-frameworksinformation-gathering+6
2 months ago
Previous12Next