Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
120 results
SharpSploitConsole preview

SharpSploitConsole

GitHubanthemtotheego/sharpsploitconsole

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

command-and-controlexploitationinformation-gathering+9
181
4 years ago
aced preview

aced

GitHubgarrettfoster13/aced

Parses and resolves a single Active Directory principal's DACL to identify inbound access privileges, resolve SIDs, and log LDAP attributes for…

information-gatheringpenetration-testingprivilege-escalation+1
2021 year ago
EvilMist preview

EvilMist

GitHublogisek/evilmist

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

authenticationcloud-securityidentity-access-management+7
1647 months ago
Kestrel preview

Kestrel

GitHubssteelfactor-oss/kestrel

Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast…

defensive-toolsinformation-gatheringpenetration-testing+5
1036 days ago
wasmforge preview

wasmforge

GitHubpraetorian-inc/wasmforge

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

binary-analysiscommand-and-controlexploit-frameworks+9
1313 months ago
SilentNimvest preview

SilentNimvest

GitHubfrkngksl/silentnimvest

Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)

data-exfiltrationlateral-movementpassword-cracking+3
1075 months ago
LDAPPER preview

LDAPPER

GitHubshellster/ldapper

LDAP Querying without the Suck

authenticationinformation-gatheringpassword-attacks+3
1151 year ago
backup_dc_registry preview

backup_dc_registry

GitHubhorizon3ai/backup_dc_registry

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

exploitationlateral-movementmisconfiguration+3
964 years ago
LACheck preview

LACheck

GitHubmitchmoser/lacheck

Multithreaded C# .NET assembly for enumerating local administrative privileges across Windows hosts via SMB, WMI, and WinRM, with BloodHound…

information-gatheringlateral-movementpenetration-testing+3
935 years ago
Get-RBCD-Threaded preview

Get-RBCD-Threaded

GitHubfatrodzianko/get-rbcd-threaded

Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments

penetration-testingprivilege-escalationreconnaissance+1
1345 years ago
EventLogin-CVE-2025-29969 preview

EventLogin-CVE-2025-29969

GitHubsafebreach-labs/eventlogin-cve-2025-29969

Exploitation of CVE-2025-29969

exploitationlateral-movementpenetration-testing+3
687 months ago
ghosthound preview

ghosthound

GitHubjvbotelho/ghosthound

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

exploitationinformation-gatheringlateral-movement+5
441 month ago
reave preview

reave

GitHubpsmths/reave

WIP Post-exploitation framework tailored for hypervisors.

command-and-controldata-exfiltrationexploit-frameworks+8
513 years ago
CVE-2026-58635-PoC preview

CVE-2026-58635-PoC

GitHubdavidcarliez/cve-2026-58635-poc

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

binary-exploitationcommand-and-controlexploitation+5
302 months ago
CVE-2026-54121-PoC-Exploit preview

CVE-2026-54121-PoC-Exploit

GitHubtc4dy/cve-2026-54121-poc-exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

authentication-authorizationexploitationexploit-frameworks+5
2913 days ago
PyPsPipeJack preview

PyPsPipeJack

GitHube-fin/pypspipejack

Python implementation of OpenPsPipeJack

lateral-movementpenetration-testingpost-exploitation+3
231 month ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
201 month ago
CVE-2026-8732-POC preview

CVE-2026-8732-POC

GitHubp3nt3st3r-star/cve-2026-8732-poc

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

exploitationinformation-gatheringpenetration-testing+4
83 months ago
Previous1234567Next