Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
Shocker-TJNULL-OSCP- preview

Shocker-TJNULL-OSCP-

GitHubr3fr4kt/shocker-tjnull-oscp-

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

educationexploitationlabs-practice+6
4 months ago
PwnTillDawn-Portal-Walkthrough preview

PwnTillDawn-Portal-Walkthrough

GitHubtr00jan99/pwntilldawn-portal-walkthrough

A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to…

ctfeducationexploitation+5
6 months ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubdr4g0n23/cve-2020-1472

Exploit script for CVE-2020-1472 (ZeroLogon) with automated privilege escalation, credential dumping via secretsdump, and lateral movement using…

exploitationlateral-movementpenetration-testing+3
3 years ago
CVE-2024-22274 preview

CVE-2024-22274

GitHubninhpn1337/cve-2024-22274

Exploit for CVE-2024-22274 that creates a privileged user and spawns a root SSH shell on a target host using provided credentials.

exploitationpayload-generationpenetration-testing+3
2 years ago
RunasCs preview

RunasCs

GitHubantoniococo/runascs

RunasCs - Csharp and open version of windows builtin runas.exe

impersonation-toolslateral-movementpenetration-testing+3
1.4k2 years ago
StopDefender preview

StopDefender

GitHublab52io/stopdefender

Stop Windows Defender programmatically

adversarial-attackimpersonation-toolspost-exploitation+2
9823 years ago
SharpImpersonation preview

SharpImpersonation

GitHubs3cur3th1ssh1t/sharpimpersonation

A User Impersonation tool - via Token or Shellcode injection

impersonation-toolspost-exploitationprivilege-escalation+1
4184 years ago
GhostTask preview

GhostTask

GitHubnetero1010/ghosttask

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

lateral-movementpersistence-mechanismsprivilege-escalation+1
6401 year ago
impersonate preview

impersonate

GitHubsensepost/impersonate

A windows token impersonation tool

adversarial-attackimpersonation-toolslateral-movement+3
3273 years ago
SharpToken preview

SharpToken

GitHubbeichendream/sharptoken

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

lateral-movementpost-exploitationprivilege-escalation+1
4932 years ago
SharpNamedPipePTH preview

SharpNamedPipePTH

GitHubs3cur3th1ssh1t/sharpnamedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+5
3084 years ago
PetitPotato preview

PetitPotato

GitHubwh0amitz/petitpotato

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

exploitationimpersonation-toolspenetration-testing+3
4643 years ago
BloodHound-Tools preview

BloodHound-Tools

GitHubzeronetworks/bloodhound-tools

Collection of tools that reflect the network dimension into Bloodhound's data

lateral-movementnetwork-mappingpenetration-testing+3
4513 years ago
SessionHop preview

SessionHop

GitHub3lp4tr0n/sessionhop

Windows Session Hijacking via COM

lateral-movementpenetration-testingpost-exploitation+2
34910 months ago
NamedPipePTH preview

NamedPipePTH

GitHubs3cur3th1ssh1t/namedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+4
1465 years ago
TokenPlayer preview

TokenPlayer

GitHubs1ckb0y1337/tokenplayer

Manipulating and Abusing Windows Access Tokens.

impersonation-toolslateral-movementpenetration-testing+2
2975 years ago
BackupOperatorToolkit preview

BackupOperatorToolkit

GitHubimprosec/backupoperatortoolkit

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

lateral-movementpenetration-testingpost-exploitation+1
1783 years ago
SpawnWith preview

SpawnWith

GitHubrasta-mouse/spawnwith

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

command-and-controlimpersonation-toolslateral-movement+2
1121 year ago
Previous123Next