Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
100 results
Blackash-CVE-2025-31161 preview

Blackash-CVE-2025-31161

GitHubdrelinss/blackash-cve-2025-31161

CVE-2025-31161

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2015-6967 preview

CVE-2015-6967

GitHubcuerv0x/cve-2015-6967

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2026-16348 preview

CVE-2026-16348

GitHubslagzz/cve-2026-16348

TP-Link Archer BE800 V1 — VPN Key Injection RCE

exploitationpenetration-testingred-teaming+2
8 days ago
BloodHound-Legacy preview

BloodHound-Legacy

GitHubspecterops/bloodhound-legacy

Six Degrees of Domain Admin

information-gatheringlateral-movementpenetration-testing+4
10.6k6 months ago
BloodHound preview

BloodHound

GitHubspecterops/bloodhound

Six Degrees of Domain Admin

defensive-toolsidentity-access-managementinformation-gathering+4
3.4k21h 2m ago
Adalanche preview

Adalanche

GitHublkarlslund/adalanche

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

penetration-testingreconnaissancered-teaming+1
2.2k8 days ago
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.8k6 months ago
Invoke-BSOD preview

Invoke-BSOD

GitHubpeewpw/invoke-bsod

For when you want a computer to be done - without admin!

exploitationpenetration-testingpost-exploitation+2
3148 years ago
SharpSCCM preview

SharpSCCM

GitHubmayyhem/sharpsccm

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

authenticationlateral-movementnetwork-security+3
7025 months ago
CVE-2021-34527 preview

CVE-2021-34527

GitHubjohnhammond/cve-2021-34527

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

binary-exploitationexploitationpayload-generation+4
3255 years ago
Invoke-SessionHunter preview

Invoke-SessionHunter

GitHubleo4j/invoke-sessionhunter

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

information-gatheringlateral-movementpenetration-testing+2
2112 years ago
serviceDetector preview

serviceDetector

GitHubtothi/servicedetector

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

information-gatheringnetwork-securitypenetration-testing+2
2412 years ago
MoveEdr preview

MoveEdr

GitHubduhirsch/moveedr

Permanently disable EDRs as local admin

anti-botdefensive-toolsids-ips-evasion+5
1288 months ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
4125 days ago
CVE-2020-15931 preview

CVE-2020-15931

GitHuboptiv/cve-2020-15931

Netwrix Account Lockout Examiner 4.1 Domain Admin Account Credential Disclosure Vulnerability

exploitationinformation-gatheringpenetration-testing+2
285 years ago
CVE-2022-44721-CsFalconUninstaller preview

CVE-2022-44721-CsFalconUninstaller

GitHubgmh5225/cve-2022-44721-csfalconuninstaller

Exploit for CVE-2022-44721 that bypasses CrowdStrike Falcon uninstall protection token check on Windows, allowing attackers with admin privileges to…

exploitationpenetration-testingpost-exploitation+3
243 years ago
CVE-2020-5148 preview

CVE-2020-5148

GitHubl0lsec/cve-2020-5148

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

authenticationexploitationinformation-gathering+6
1 month ago
supahunter preview

supahunter

GitHubproxydom/supahunter

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

cloud-securitydatabase-securitydata-exfiltration+8
27 months ago
Previous123456Next