Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
355 results
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
2
5 years ago
MakeMeEnterpriseAdmin preview

MakeMeEnterpriseAdmin

GitHubal1ex/makemeenterpriseadmin

MakeMeEnterpriseAdmin

exploitationlateral-movementpayload-generation+3
25 years ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubgrupooruss/cve-2020-1472

PowerShell script to validate domain controllers against CVE-2020-1472 (Netlogon EoP) by checking installed hotfixes via WMI, outputting compliance…

exploitationlateral-movementpenetration-testing+2
5 years ago
Hook-PasswordChangeNotify preview

Hook-PasswordChangeNotify

GitHubal1ex/hook-passwordchangenotify

Hook PasswordChangeNotify

lateral-movementpassword-attackspenetration-testing+2
16 years ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubjiushill/cve-2020-1472

Python exploit for CVE-2020-1472 (Zerologon) targeting Netlogon authentication bypass to escalate privileges and compromise Active Directory domain…

exploitationlateral-movementpenetration-testing+2
16 years ago
PSTools preview

PSTools

GitHubal1ex/pstools

PSTools

lateral-movementpenetration-testingpost-exploitation+3
36 years ago
Invoke-DCSync preview

Invoke-DCSync

GitHubal1ex/invoke-dcsync

Invoke-DCSync

exploitationlateral-movementpassword-attacks+3
16 years ago
SharpSecDump preview

SharpSecDump

GitHubg0ldengunsec/sharpsecdump

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

lateral-movementpenetration-testingpost-exploitation
6136 years ago
CVE-2020-16152 preview

CVE-2020-16152

GitHuberiknl/cve-2020-16152

Proof-of-concept exploit for CVE-2020-16152: LFI-to-RCE in Aerohive/Extreme Networks HiveOS via PHP string truncation and log poisoning, enabling…

binary-exploitationexploitationlateral-movement+3
116 years ago
Sharp-SMBExec preview

Sharp-SMBExec

GitHubcheckymander/sharp-smbexec

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

authenticationexploitationlateral-movement+1
2166 years ago
PowerSploit preview
Archived

PowerSploit

GitHubpowershellmafia/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

lateral-movementpayload-generationpenetration-testing+5
13.1k6 years ago
mssqlproxy preview

mssqlproxy

GitHubblackarrowsec/mssqlproxy

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

database-securitylateral-movementpenetration-testing+1
7746 years ago
EvilNet preview

EvilNet

GitHubmatrix07ksa/evilnet

Network Attack wifi attack vlan attack arp attack Mac Attack Attack revealed etc../

information-gatheringnetwork-securitypassword-attacks+2
1486 years ago
ligolo preview

ligolo

GitHubsysdream/ligolo

Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/

lateral-movementpenetration-testingred-teaming
1.8k6 years ago
ARP-poisoning-packet-sniffer preview

ARP-poisoning-packet-sniffer

GitHubmustafadalga/arp-poisoning-packet-sniffer

Aynı ağda bulunan hedef bilgisayarlar üzerinde ARP zehirlemesi(poisoning) yapmak ve ağ trafiğini izlemenizi sağlamak için yazılmış iki scripttir.

information-gatheringnetwork-securitypacket-sniffing-analysis+1
56 years ago
raw-packet preview

raw-packet

GitHubraw-packet/raw-packet

Raw-packet Project

dns-analysiseducationnetwork-security+4
2356 years ago
CredSniper preview

CredSniper

GitHubustayready/credsniper

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

authenticationimpersonation-toolsphishing+3
1.4k6 years ago
WSMan-WinRM preview

WSMan-WinRM

GitHubbohops/wsman-winrm

A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

lateral-movementpenetration-testingred-teaming+1
2626 years ago
Previous1…161718…20Next