Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k
2 months ago
cve-2025-24054-lab preview

cve-2025-24054-lab

GitHubt0tooro/cve-2025-24054-lab

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

authenticationconfiguration-auditingeducation+7
2 months ago
wazuh preview

wazuh

GitHubwazuh/wazuh

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

anomaly-detectionanti-botcloud-security+12
16.8k1 day ago
mailinabox preview

mailinabox

GitHubmail-in-a-box/mailinabox

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

configuration-auditingdefensive-toolsemail-security+3
15.4k5 days ago
mailcow-dockerized preview

mailcow-dockerized

GitHubmailcow/mailcow-dockerized

Dockerized mail server suite with Postfix, Dovecot, Rspamd, and ClamAV. Provides secure email hosting with integrated spam filtering, antivirus, and…

authenticationcloud-infrastructure-securityconfiguration-auditing+4
13.4k19 days ago
ScubaGear preview

ScubaGear

GitHubcisagov/scubagear

Automation to assess the state of your M365 tenant against CISA's baselines

cloud-securityconfiguration-auditingdefensive-tools+3
2.7k2 days ago
p5-ssl-tools preview

p5-ssl-tools

GitHubnoxxi/p5-ssl-tools

Perl scripts for SSL/TLS analysis: check protocol and cipher support, verify certificates, test OCSP, and detect Heartbleed across SMTP, HTTPS, and…

configuration-auditingcryptographyemail-security+3
2014 years ago
M365-Assess preview

M365-Assess

GitHubgalvnyz/m365-assess

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

cloud-securityconfiguration-auditingdevsecops+4
1981 month ago
SpoofcheckSelfTest preview

SpoofcheckSelfTest

GitHubbishopfox/spoofcheckselftest

Web application that lets you test if your domain is vulnerable to email spoofing

configuration-auditingdns-analysisemail-security+1
439 years ago
CVE-2022-41040 preview

CVE-2022-41040

GitHubr3dcl1ff/cve-2022-41040

mitigation script for MS Exchange server vuln

configuration-auditingemail-securityexploitation+2
53 years ago
Dead.Letter-CVE-2026-45185 preview

Dead.Letter-CVE-2026-45185

GitHubliamromanis101/dead.letter-cve-2026-45185

Shell-based vulnerability scanner for CVE-2026-45185 (Dead.Letter) in Exim MTA. Detects use-after-free in GnuTLS builds, checks version, TLS library,…

configuration-auditingdevsecopsemail-security+5
23 months ago
cve-2025-32711 preview

cve-2025-32711

GitHubdaryllundy/cve-2025-32711

PowerShell-based detection and remediation toolkit for CVE-2025-32711 (EchoLeak), a critical zero-click AI command injection vulnerability in…

ai-securitycloud-securityconfiguration-auditing+4
31 year ago
CVE-2024-45519-Zimbra-Real-Fix preview

CVE-2024-45519-Zimbra-Real-Fix

GitHublionels-cyber/cve-2024-45519-zimbra-real-fix

Zimbra CVE-2024-45519 real fix - Official patch is incomplete

configuration-auditingdefensive-toolseducation+3
22 days ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubim007/cve-2023-23397

PowerShell script to detect and remediate CVE-2023-23397 privilege escalation vulnerability in Microsoft Outlook and Exchange environments.

cloud-securityconfiguration-auditingemail-security+3
3 years ago
asf__james-project_CVE-2022-22931_3-6-0 preview

asf__james-project_CVE-2022-22931_3-6-0

GitHubshoucheng3/asf__james-project_cve-2022-22931_3-6-0

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

authenticationcloud-securityconfiguration-auditing+5
1 year ago