Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
246 results
LinEnum preview

LinEnum

GitHubrebootuser/linenum

Scripted Local Linux Enumeration & Privilege Escalation Checks

penetration-testingpost-exploitationprivilege-escalation
8.0k6 years ago
PrivFu preview

PrivFu

GitHubdaem0nc0re/privfu

Kernel mode WinDbg extension and PoCs for token privilege investigation.

exploitationpost-exploitationprivilege-escalation
1.0k8 days ago
PowerTools preview

PowerTools

GitHubpowershellempire/powertools

Collection of offensive PowerShell projects for reconnaissance, privilege escalation, and post-exploitation during penetration testing engagements.

penetration-testingpost-exploitationprivilege-escalation+1
2.2k9 years ago
SharpUp preview

SharpUp

GitHubghostpack/sharpup

C# tool for auditing Windows privilege escalation vulnerabilities, porting PowerUp checks for misconfigurations like unquoted service paths,…

penetration-testingpost-exploitationprivilege-escalation+1
1.5k2 years ago
enumy preview

enumy

GitHubluke-goddard/enumy

Linux post exploitation privilege escalation enumeration

penetration-testingpost-exploitationprivilege-escalation+1
2556 years ago
slui-file-handler-hijack-privilege-escalation preview

slui-file-handler-hijack-privilege-escalation

GitHubbytecode77/slui-file-handler-hijack-privilege-escalation

Slui File Handler Hijack UAC Bypass Local Privilege Escalation

exploitationpost-exploitationprivilege-escalation+1
921 year ago
Hijack-service-binaries preview

Hijack-service-binaries

GitHubsec-zone/hijack-service-binaries

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

penetration-testingpost-exploitationprivilege-escalation+2
7 months ago
S4UTomato preview

S4UTomato

GitHubwh0amitz/s4utomato

Escalate Service Account To LocalSystem via Kerberos

exploitationpost-exploitationprivilege-escalation+1
4023 years ago
Change-Lockscreen preview

Change-Lockscreen

GitHubnccgroup/change-lockscreen

Offensive tool to trigger network authentications as SYSTEM

exploitationpost-exploitationprivilege-escalation+1
1444 years ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Weaponized web shell

penetration-testingpost-exploitationprivilege-escalation+4
3.5k1 year ago
BackupOperatorToDA preview

BackupOperatorToDA

GitHubmpgn/backupoperatortoda

From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller

penetration-testingpost-exploitationprivilege-escalation
4471 year ago
POSTDump preview

POSTDump

GitHubyolop0wn/postdump

C# tool for LSASS minidump with multiple evasion techniques including indirect syscalls, ETW patching, and PPL bypass via driver or WER fault.…

post-exploitationprivilege-escalationred-teaming
3463 months ago
Sharpmad preview

Sharpmad

GitHubkevin-robertson/sharpmad

C# version of Powermad

penetration-testingpost-exploitationprivilege-escalation+1
1723 years ago
DuplicateDump preview

DuplicateDump

GitHubhagrid29/duplicatedump

Dumping LSASS with a duplicated handle from custom LSA plugin

post-exploitationprivilege-escalationred-teaming
2064 years ago
ZombifyProcess preview

ZombifyProcess

GitHubmalwaretech/zombifyprocess

Inject code into a legitimate process

post-exploitationprivilege-escalationred-teaming
14411 years ago
electroniz3r preview

electroniz3r

GitHubr3ggi/electroniz3r

Take over macOS Electron apps' TCC permissions

exploitationpost-exploitationprivilege-escalation+1
2233 years ago
PPLFaultDumpBOF preview

PPLFaultDumpBOF

GitHubtrustedsec/pplfaultdumpbof

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

exploitationpost-exploitationprivilege-escalation+1
1463 years ago
TrollDump preview

TrollDump

GitHubcybersectroll/trolldump

Injects x64 managed DLLs into GUI processes via SetWindowsHook, with a modular C# payload runner and LSASS dump POC for red-team/offensive Windows…

payload-developmentpost-exploitationprivilege-escalation+1
842 years ago
Previous12…14Next