Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
SAMDump preview

SAMDump

GitHubricardojoserf/samdump

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Crystal, Python,…

data-exfiltrationencryption-decryption-toolspost-exploitation+3
386
1 month ago
ShadowSpray preview

ShadowSpray

GitHubdec0ne/shadowspray

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the…

authenticationexploitationpenetration-testing+3
4973 years ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
2089 days ago
ransomware-simulator preview

ransomware-simulator

GitHubnextronsystems/ransomware-simulator

Safe ransomware simulation tool for testing antivirus detection. Simulates macro staging, volume shadow copy deletion, document encryption, and note…

defensive-toolseducationmalware-analysis+2
4844 years ago
zBang preview

zBang

GitHubcyberark/zbang

Active Directory risk assessment tool that scans for privileged account threats, shadow admins, Skeleton Key malware, SID history abuse, risky SPNs,…

penetration-testingprivilege-escalationvulnerability-analysis
3434 years ago
shadow-workers preview

shadow-workers

GitHubshadow-workers/shadow-workers

Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service…

command-and-controlpenetration-testingpersistence-mechanisms+2
2463 years ago
libvshadow preview

libvshadow

GitHublibyal/libvshadow

Library and tools to access the Volume Shadow Snapshot (VSS) format

data-recoverydigital-forensicsdisk-forensics+2
11910 days ago
AIOstack preview

AIOstack

GitHubaurva-io/aiostack

AI runtime inventory: discover shadow AI, trace LLM calls

ai-securitycloud-securitycontainer-security+8
651 month ago
red-shadow preview

red-shadow

GitHublightspin-tech/red-shadow

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

cloud-infrastructure-securitycloud-securityidentity-access-management+3
955 years ago
kin preview

kin

GitHubfirelock-ai/kin

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

ai-securitycode-analysiscurated-resources+4
676 days ago
Mimic preview

Mimic

GitHub0x4meliorate/mimic

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

impersonation-toolspenetration-testingphishing+4
511 month ago
AgrusScanner preview

AgrusScanner

GitHubnybaywatch/agrusscanner

Windows network reconnaissance scanner with ping sweeps, TCP port scanning, and deep AI/ML service detection for finding shadow AI, rogue LLM…

ai-securitydefensive-toolsinformation-gathering+6
283 days ago
shadow-fleet-tracker-light preview

shadow-fleet-tracker-light

GitHubformerlab/shadow-fleet-tracker-light

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

data-exfiltrationdigital-forensicsdns-analysis+9
445 months ago
Januscape-Hotfix preview

Januscape-Hotfix

GitHubaoripus-ltd/januscape-hotfix

Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel…

cloud-infrastructure-securityconfiguration-auditingincident-response+2
62 months ago
ShadowMem preview

ShadowMem

GitHubzjuwyh/shadowmem

Defensive framework that maintains a safety-focused shadow memory to detect and block prompt-injection and long-horizon threats against LLM agents…

ai-securitydefensive-toolseducation+4
24 days ago
poc_CVE-2021-36934 preview

poc_CVE-2021-36934

GitHubgrishinpv/poc_cve-2021-36934

POC experiments with Volume Shadow copy Service (VSS)

data-recoveryexploitationforensics+2
25 years ago
ESCepcion preview

ESCepcion

GitHubhackwarts12/escepcion

Passive AD CS auditor detecting ESC1–ESC16 and Shadow Credentials via read-only LDAP/ACL/registry checks, with prioritized remediation and SIEM-ready…

configuration-auditingdefensive-toolsmisconfiguration+4
23 months ago
CVE-2021-36934 preview

CVE-2021-36934

GitHubirissentinel/cve-2021-36934

PowerShell script to detect and remediate the CVE-2021-36934 HiveNightmare privilege escalation vulnerability on Windows 10 by checking SAM hive…

configuration-auditingincident-responseprivilege-escalation+2
15 years ago
Previous123Next