Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Phishing

Phishing simulation, detection, analysis, and security awareness training tools.

Kitploit recommended

Top tools

10 selected
gophish preview#1

gophish

GitHubgophish/gophish
14.1k2 years ago
evilginx2 preview#2

evilginx2

GitHubkgretzky/evilginx2
15.5k3 months ago
social-engineer-toolkit preview#3

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit
15.2k3 months ago
Modlishka preview#4

Modlishka

GitHubdrk1wi/modlishka
5.4k1 month ago
muraena preview#5

muraena

GitHubmuraenateam/muraena
1.1k1 year ago
zphisher preview#6

zphisher

GitHubhtr-tech/zphisher
16.6k2 years ago
wifiphisher preview#7

wifiphisher

GitHubwifiphisher/wifiphisher
14.8k4 months ago
chlonium preview#9

chlonium

GitHubrxwx/chlonium
3163 years ago
SocialFish preview#10

SocialFish

GitHubundeadsec/socialfish
4.8k4 months ago
CredSniper preview#11

CredSniper

GitHubustayready/credsniper
1.4k6 years ago
NewestRelevanceMost popularRecently updated
323 results
LazyOwn preview

LazyOwn

GitHubgrisuno/lazyown

Red team framework and multi-operator C2 platform with AI agents, malleable implants, rootkits, phishing engine, and 741 CLI commands covering the…

penetration-testing-frameworksvulnerability-scannersexploit-frameworks+8
2281 day ago
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

defensive-toolsphishing-toolspayload-generation+6
3914 days ago
azure-pentesting-suite preview

azure-pentesting-suite

GitHubhac01/azure-pentesting-suite

Go toolkit for authorized Azure security assessments: enumerates subscriptions and resources, audits misconfigurations, and attacks public Blob…

privilege-escalationreconnaissancepassword-attacks+9
8210 days ago
FullscreenBrowserPhishing preview

FullscreenBrowserPhishing

GitHubgmh5225/fullscreenbrowserphishing

PoC of the phishing through setting browser in the fullscreen mode

phishing-toolsphishingweb-security+3
3 years ago
thm-Moniker-Link-cve-2024-21413-writeup preview

thm-Moniker-Link-cve-2024-21413-writeup

GitHubshauryarathore357-hub/thm-moniker-link-cve-2024-21413-writeup

TryHackMe room walkthrough of CVE-2024-21413, covering the Outlook Moniker Link Protected View bypass, NTLM hash leaking, and credential capture with…

password-crackingvulnerability-analysisexploitation+6
14 days ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

penetration-testing-frameworksexploit-frameworkspersistence-mechanisms+8
6797 days ago
BlueBox preview

BlueBox

GitHubsvdwi/bluebox

Open-source threat intelligence platform for malware and observable analysis. Enriches IPs, domains, URLs, and hashes with external sources, performs…

ioc-managementosintstatic-analysis+4
504 years ago
wraith preview

wraith

GitHubarcanum-sec/wraith

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

exploitationphishingweb-security+6
1481 month ago
Yordam-Kutuphane-Otomasyonunda-Coklu-HTML-Enjeksiyonu preview

Yordam-Kutuphane-Otomasyonunda-Coklu-HTML-Enjeksiyonu

GitHubalkimcoskun/yordam-kutuphane-otomasyonunda-coklu-html-enjeksiyonu

CVE-2026-77818 - Yordam Kütüphane Otomasyon Sistemi - Üç ayrı noktada yansıtılmış HTML enjeksiyonu, form action ele geçirme ve kimlik bilgisi…

vulnerability-analysisexploitationweb-application-exploitation+2
25 days ago
skills preview

skills

GitHubspecterops/skills

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

osintreconnaissanceexploitation+9
6716 days ago
enhanced-iframe-protection preview

enhanced-iframe-protection

GitHubmalwarecube/enhanced-iframe-protection

A lightweight extension to automatically detect and provide verbose warnings for embedded iframe elements in order to protect against…

defensive-toolsphishingweb-security+1
503 years ago
Red-Team-Infrastructure-Wiki preview

Red-Team-Infrastructure-Wiki

GitHubbluscreenofjeff/red-team-infrastructure-wiki

Wiki to collect Red Team infrastructure hardening resources

cloud-infrastructure-securityosintphishing+5
4.5k0 years ago
flyphish preview

flyphish

GitHubvirtualsamuraii/flyphish

Deploy a phishing infrastructure on the fly.

cloud-infrastructure-securityphishing-toolsphishing+3
791 year ago
msdt-follina preview

msdt-follina

GitHubjohnhammond/msdt-follina

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

exploitationweb-application-exploitationphishing+2
1.6k4 years ago
cve-2023-23397-purple-team preview

cve-2023-23397-purple-team

GitHubpraneethnaidu1910-cmd/cve-2023-23397-purple-team

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

exploitationphishingeducation+3
1 month ago
CVE-2025-56218 preview

CVE-2025-56218

GitHubsaykino/cve-2025-56218

Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing…

vulnerability-analysisphishingweb-security+2
11 months ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

reconnaissancevulnerability-analysisexploitation+2
21 days ago
CVE-2025-40778 preview

CVE-2025-40778

GitHubnehkark/cve-2025-40778

Proof-of-concept demonstrating DNS cache poisoning via additional record injection in BIND 9, with tools to validate and exploit CVE-2025-40778 for…

vulnerability-analysisexploitationphishing+3
611 months ago
Previous12…18Next