Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
Rubeus preview

Rubeus

GitHubghostpack/rubeus

Trying to tame the three-headed dog.

authenticationexploitationlateral-movement+6
5.2k9 months ago
chlonium preview

chlonium

GitHubrxwx/chlonium

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

data-exfiltrationencryption-decryption-toolsforensics+6
3163 years ago
LSTAR preview

LSTAR

GitHublintstar/lstar

LSTAR - CobaltStrike 综合后渗透插件

command-and-controlexploitationinformation-gathering+7
1.3k4 years ago
mimikatz preview

mimikatz

GitHubgentilkiwi/mimikatz

A little tool to play with Windows security

authenticationexploitationexploit-frameworks+10
21.8k4 months ago
pypykatz preview

pypykatz

GitHubskelsec/pypykatz

Mimikatz implementation in pure Python

authenticationdigital-forensicsencryption-decryption-tools+4
3.4k4 months ago
dploot preview

dploot

GitHubzblurx/dploot

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

cloud-securitydigital-forensicsencryption-decryption-tools+3
5679 days ago
DeepBlueCLI preview

DeepBlueCLI

GitHubsans-blue-team/deepbluecli

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

digital-forensicsincident-responseintrusion-detection+2
2.4k3 years ago
Internal-Monologue preview

Internal-Monologue

GitHubeladshamir/internal-monologue

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

lateral-movementpassword-attackspenetration-testing+2
1.7k7 years ago
SharpDPAPI preview

SharpDPAPI

GitHubghostpack/sharpdpapi

SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.

data-exfiltrationencryption-decryption-toolsexploitation+5
1.5k2 years ago
spraykatz preview

spraykatz

GitHubaas-n/spraykatz

Credentials gathering tool automating remote procdump and parse of lsass process.

information-gatheringlateral-movementpenetration-testing+1
7826 years ago
MaldevAcademyLdr.2 preview

MaldevAcademyLdr.2

GitHubmaldev-academy/maldevacademyldr.2

RunPE implementation with multiple evasive techniques (2)

cryptographyids-ips-evasionpayload-development+3
28611 months ago
SharpSploitConsole preview

SharpSploitConsole

GitHubanthemtotheego/sharpsploitconsole

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

command-and-controlexploitationinformation-gathering+9
1824 years ago
dcshadow preview

dcshadow

GitHubshutdownrepo/dcshadow

Python alternative to Mimikatz lsadump::dcshadow

defensive-toolspenetration-testingpersistence-mechanisms+2
1621 year ago
NtDumpBOF preview

NtDumpBOF

GitHubdeh00ni/ntdumpbof

Cobalt Strike BOF that creates an LSASS minidump in memory and exfiltrates it over the C2 callback for offline credential parsing with Mimikatz or…

data-exfiltrationpost-exploitationred-teaming
992 years ago
mscache preview

mscache

GitHubqax-a-team/mscache

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

authenticationpassword-crackingpost-exploitation
678 years ago
pingcastle preview

pingcastle

GitHubnetwrix/pingcastle

Active Directory security risk assessment tool that evaluates vulnerabilities, misconfigurations, and maturity using a streamlined methodology,…

configuration-auditingvulnerability-scanners
2.9k22 days ago
mimikatz preview

mimikatz

GitHubparrotsec/mimikatz

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

authenticationexploitationlateral-movement+5
2.6k2 years ago
A-Red-Teamer-diaries preview

A-Red-Teamer-diaries

GitHubihebski/a-red-teamer-diaries

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

curated-resourceseducationexploitation+7
1.9k10 months ago
Previous12Next