Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
SAMDump preview

SAMDump

GitHubricardojoserf/samdump

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

data-exfiltrationencryption-decryption-toolspost-exploitation+3
381
3 days ago
archiver-MOTW-support-comparison preview

archiver-MOTW-support-comparison

GitHubnmantani/archiver-motw-support-comparison
adversarial-attackcurated-resourceseducation+2
27918 days ago
tgt-monitor-bof preview

tgt-monitor-bof

GitHubjakobfriedl/tgt-monitor-bof

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

authenticationlateral-movementpayload-development+3
13428 days ago
cookie-monster preview

cookie-monster

GitHubkingofthenops/cookie-monster

BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

data-exfiltrationpenetration-testingpost-exploitation+1
56928 days ago
nord-stream preview

nord-stream

GitHubsynacktiv/nord-stream

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

data-exfiltrationdevsecopsexploitation+5
3721 month ago
go-secdump preview

go-secdump

GitHubjfjallid/go-secdump

Tool to remotely dump secrets from the Windows registry

authenticationencryption-decryption-toolslateral-movement+4
5351 month ago
LogHound preview

LogHound

GitHubrnb-team/loghound

Post-Exploitation EVTX Analyzer for BloodHound Mapping

authenticationdigital-forensicsforensics+6
113 months ago
gpoParser preview

gpoParser

GitHubsynacktiv/gpoparser

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

configuration-auditinginformation-gatheringlateral-movement+7
3713 months ago
VMkatz preview

VMkatz

GitHubnikaiw/vmkatz

Extract Windows credentials directly from VM memory snapshots and virtual disks

digital-forensicsexploitationforensics+7
1.5k4 months ago
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.7k6 months ago
GhostKatz preview

GhostKatz

GitHubrainbowdynamix/ghostkatz

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

binary-exploitationexploitationmemory-forensics+4
3386 months ago
CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160 preview

CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

GitHubsimoesctt/ctt-heartbleed-temporal-resonance-memory-leak-exploit-heartbleed-cve-2014-0160

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…

educationexploitationinformation-gathering+6
6 months ago
DumpChromeSecrets preview
Archived

DumpChromeSecrets

GitHubmaldev-academy/dumpchromesecrets

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

data-exfiltrationdigital-forensicseducation+8
5607 months ago
Seth preview

Seth

GitHubsyss-research/seth

Perform a MitM attack and extract clear text credentials from RDP connections

authenticationeducationexploitation+4
1.5k9 months ago
WinRAR-CVE-2025-8088-PoC-RAR preview

WinRAR-CVE-2025-8088-PoC-RAR

GitHubknight0x07/winrar-cve-2025-8088-poc-rar

WinRAR 0day CVE-2025-8088 PoC RAR Archive

exploitationmalware-analysispayload-generation+3
441 year ago
CVE-2024-7954 preview

CVE-2024-7954

GitHubr0otk3r/cve-2024-7954
educationexploitationpenetration-testing+3
1 year ago
adiskreader-secretsdump preview

adiskreader-secretsdump

GitHubskelsec/adiskreader-secretsdump

Extract registry and NTDS secrets from local or remote disk images

digital-forensicsincident-responsepassword-attacks+3
451 year ago
SlackPirate preview

SlackPirate

GitHubemtunc/slackpirate

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

cloud-securitydata-exfiltrationinformation-gathering+3
7801 year ago
Previous12Next