Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
AzTokenFinder preview

AzTokenFinder

GitHubhackmichnet/aztokenfinder
authenticationcloud-securitymemory-forensics+3
1093 years ago
adiskreader-secretsdump preview

adiskreader-secretsdump

GitHubskelsec/adiskreader-secretsdump

Extract registry and NTDS secrets from local or remote disk images

digital-forensicsincident-responsepassword-attacks+3
451 year ago
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.7k6 months ago
archiver-MOTW-support-comparison preview

archiver-MOTW-support-comparison

GitHubnmantani/archiver-motw-support-comparison
adversarial-attackcurated-resourceseducation+2
27918 days ago
gpoParser preview

gpoParser

GitHubsynacktiv/gpoparser

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

configuration-auditinginformation-gatheringlateral-movement+7
3713 months ago
nord-stream preview

nord-stream

GitHubsynacktiv/nord-stream

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

data-exfiltrationdevsecopsexploitation+5
3721 month ago
SessionGopher preview

SessionGopher

GitHubarvanaghi/sessiongopher

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

information-gatheringlateral-movementpenetration-testing+3
1.3k3 years ago
njRAT preview

njRAT

GitHubmwsrc/njrat

njRAT SRC Extract

command-and-controldata-exfiltrationexploitation+9
3119 years ago
extractTVpasswords preview

extractTVpasswords

GitHubvah13/extracttvpasswords

tool to extract passwords from TeamViewer memory using Frida

exploitationmemory-forensicspassword-cracking+3
4638 years ago
CVE-2024-7954 preview

CVE-2024-7954

GitHubr0otk3r/cve-2024-7954
educationexploitationpenetration-testing+3
1 year ago
LogHound preview

LogHound

GitHubrnb-team/loghound

Post-Exploitation EVTX Analyzer for BloodHound Mapping

authenticationdigital-forensicsforensics+6
113 months ago
WinRAR-CVE-2025-8088-PoC-RAR preview

WinRAR-CVE-2025-8088-PoC-RAR

GitHubknight0x07/winrar-cve-2025-8088-poc-rar

WinRAR 0day CVE-2025-8088 PoC RAR Archive

exploitationmalware-analysispayload-generation+3
441 year ago
CVE-2024-44000 preview

CVE-2024-44000

GitHubgeniuszly/cve-2024-44000

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies

exploitationinformation-gatheringpenetration-testing+2
51 year ago
CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160 preview

CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

GitHubsimoesctt/ctt-heartbleed-temporal-resonance-memory-leak-exploit-heartbleed-cve-2014-0160

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…

educationexploitationinformation-gathering+6
6 months ago
GhostKatz preview

GhostKatz

GitHubrainbowdynamix/ghostkatz

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

binary-exploitationexploitationmemory-forensics+4
3386 months ago
tgt-monitor-bof preview

tgt-monitor-bof

GitHubjakobfriedl/tgt-monitor-bof

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

authenticationlateral-movementpayload-development+3
13428 days ago
VMkatz preview

VMkatz

GitHubnikaiw/vmkatz

Extract Windows credentials directly from VM memory snapshots and virtual disks

digital-forensicsexploitationforensics+7
1.5k4 months ago
SAMDump preview

SAMDump

GitHubricardojoserf/samdump

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

data-exfiltrationencryption-decryption-toolspost-exploitation+3
3813 days ago
Previous12Next