Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
150 results
ATTPwn preview

ATTPwn

GitHubtelefonica/attpwn

ATTPwn

adversarial-attacklateral-movementpenetration-testing+3
2205 years ago
CVE-2026-54121-Certighost preview

CVE-2026-54121-Certighost

GitHubzerodayevil/cve-2026-54121-certighost

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

authenticationexploitationimpersonation-tools+6
248 days ago
mimikatz preview

mimikatz

GitHubparrotsec/mimikatz

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

authenticationexploitationlateral-movement+5
2.7k2 years ago
SetupHijack preview

SetupHijack

GitHubhackerhouse-opensource/setuphijack

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

exploitationlateral-movementpayload-generation+3
2677 months ago
backup_dc_registry preview

backup_dc_registry

GitHubhorizon3ai/backup_dc_registry

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

exploitationlateral-movementmisconfiguration+3
964 years ago
oxide_hive preview

oxide_hive

GitHubchron1k/oxide_hive

Exploit for CVE-2021-36934

exploitationlateral-movementpassword-cracking+3
34 years ago
CVE-2026-6875-PoC-Exploit preview

CVE-2026-6875-PoC-Exploit

GitHubtc4dy/cve-2026-6875-poc-exploit

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

exploitationlateral-movementpenetration-testing+7
32 months ago
samba-3.0.24-CVE-2007-2447-vunerable- preview

samba-3.0.24-CVE-2007-2447-vunerable-

GitHub3t4n/samba-3.0.24-cve-2007-2447-vunerable-

Vulnerable Samba 3.0.24 environment for reproducing CVE-2007-2447 command execution, intended for exploit testing and security research.

exploitationlateral-movementpenetration-testing+3
5 years ago
NPE-CS-V-CVE-2021-1675 preview

NPE-CS-V-CVE-2021-1675

GitHubsp4cedogy/npe-cs-v-cve-2021-1675

Exploit code for CVE-2021-1675, a Windows Print Spooler remote code execution vulnerability, demonstrating the attack and providing a…

exploitationlateral-movementpenetration-testing+2
1 year ago
MalSeclogon preview

MalSeclogon

GitHubantoniococo/malseclogon

A little tool to play with the Seclogon service

exploitationlateral-movementmemory-forensics+3
3264 years ago
powerglot preview

powerglot

GitHubmindcrypt/powerglot

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

defensive-toolsforensicslateral-movement+4
1836 years ago
getSPNless preview

getSPNless

GitHubjarnovandenbrink/getspnless

Python tool to automatically perform SPN-less RBCD attacks.

authenticationexploitationlateral-movement+3
1328 months ago
SharpNamedPipePTH preview

SharpNamedPipePTH

GitHubs3cur3th1ssh1t/sharpnamedpipepth

Pass the Hash to a named pipe for token Impersonation

authenticationimpersonation-toolslateral-movement+5
3074 years ago
TokenPlayer preview

TokenPlayer

GitHubs1ckb0y1337/tokenplayer

Manipulating and Abusing Windows Access Tokens.

impersonation-toolslateral-movementpenetration-testing+2
3005 years ago
GhostTask preview

GhostTask

GitHubnetero1010/ghosttask

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

lateral-movementpersistence-mechanismsprivilege-escalation+1
6401 year ago
SessionHop preview

SessionHop

GitHub3lp4tr0n/sessionhop

Windows Session Hijacking via COM

lateral-movementpenetration-testingpost-exploitation+2
3509 months ago
Rubeus preview

Rubeus

GitHubghostpack/rubeus

Trying to tame the three-headed dog.

authenticationexploitationlateral-movement+6
5.2k10 months ago
impersonate preview

impersonate

GitHubsensepost/impersonate

A windows token impersonation tool

adversarial-attackimpersonation-toolslateral-movement+3
3293 years ago
Previous12…9Next