Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
439 results
Terrminus-CVE-2026-2406 preview

Terrminus-CVE-2026-2406

GitHubridpath/terrminus-cve-2026-2406

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

exploitationinformation-gatheringiot-security+8
2
7 months ago
linuxprivchecker preview

linuxprivchecker

GitHubsleventyeleven/linuxprivchecker

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

ctfeducationinformation-gathering+3
1.8k5 years ago
SharpHound preview

SharpHound

GitHubspecterops/sharphound

Collects Active Directory object metadata, group memberships, sessions, ACLs, and trusts to feed BloodHound attack-path mapping for security…

information-gatheringlateral-movementpenetration-testing+4
1.3k2 days ago
ldap_shell preview

ldap_shell

GitHubpshlyundin/ldap_shell

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

authenticationinformation-gatheringpenetration-testing+1
4101 day ago
Wonka preview

Wonka

GitHubshac0x/wonka

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

authenticationinformation-gatheringpenetration-testing+3
1763 months ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
27 months ago
CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read preview

CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read

GitHubfazaroot/cve-2025-2539---file-away-wordpress-plugin-arbitrary-file-read

Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

ctfeducationexploitation+6
9 months ago
postenum preview

postenum

GitHubmostaphabahadou/postenum

A lightweight, portable, and modular tool for Linux enumeration and privilege escalation.

information-gatheringpenetration-testingpost-exploitation+1
2948 months ago
PrivescCheck preview

PrivescCheck

GitHubitm4n/privesccheck

Privilege Escalation Enumeration Script for Windows

configuration-auditinginformation-gatheringpenetration-testing+3
4.0k8 days ago
PowerUpSQL preview

PowerUpSQL

GitHubnetspi/powerupsql

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

configuration-auditingdatabase-securityexploitation+9
2.7k1 year ago
AD_Miner preview

AD_Miner

GitHubad-security/ad_miner

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

configuration-auditingeducationinformation-gathering+6
1.6k6 months ago
ADCollector preview

ADCollector

GitHubdev-2null/adcollector

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

authenticationconfiguration-auditinginformation-gathering+4
63611 months ago
BloodBash preview

BloodBash

GitHubsquidsec/bloodbash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

cloud-securityconfiguration-auditingidentity-access-management+6
49128 days ago
Cable preview

Cable

GitHublogangoins/cable

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

authenticationconfiguration-auditingexploitation+8
4021 year ago
ACEshark preview

ACEshark

GitHubt3l3machus/aceshark

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

configuration-auditinginformation-gatheringpenetration-testing+4
1511 year ago
MSSQLand preview

MSSQLand

GitHubn3rada/mssqland

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

configuration-auditingdatabase-securityimpersonation-tools+6
771 month ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
231 day ago
Windows-Local-Privilege-Escalation-Cookbook preview

Windows-Local-Privilege-Escalation-Cookbook

GitHubnickvourd/windows-local-privilege-escalation-cookbook

Windows Local Privilege Escalation Cookbook

configuration-auditingeducationexploitation+9
1.4k7 months ago
Previous12…25Next