Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
CVE-2024-21378 preview

CVE-2024-21378

GitHubd0rb/cve-2024-21378

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

educationemail-securityexploitation+4
9
2 years ago
CVE-2019-16759 preview

CVE-2019-16759

GitHub0xdims/cve-2019-16759

This tools will extracts and dumps Email + SMTP from vBulletin database server

educationemail-harvestingexploitation+3
66 years ago
CVE-2017-14322 preview

CVE-2017-14322

GitHubjoesmithjaffa/cve-2017-14322

CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit

authentication-authorizationeducationexploitation+3
58 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
11 months ago
CVE-2025-25965 preview

CVE-2025-25965

GitHubsudo-sakib/cve-2025-25965

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

educationpenetration-testingvulnerability-analysis+2
1 year ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks…

educationexploitationlabs-practice+5
1 year ago
Event-ID-263-Rule-Name-SOC287---Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919- preview

Event-ID-263-Rule-Name-SOC287---Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-

GitHubahmedmansour93/event-id-263-rule-name-soc287---arbitrary-file-read-on-checkpoint-security-gateway-cve-2024-24919-

🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨…

educationexploitationincident-response+2
1 year ago
pepe preview
Archived

pepe

GitHubwoj-ciech/pepe

Collect information about email addresses from Pastebin

data-exfiltrationeducationemail-harvesting+5
395 years ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4783 years ago
Cybersecurity-Mastery-Roadmap preview

Cybersecurity-Mastery-Roadmap

GitHubhamed233/cybersecurity-mastery-roadmap

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

cryptographyctfcurated-resources+6
3.3k28 days ago
Phishing-Simulation preview

Phishing-Simulation

GitHubjenyraval/phishing-simulation

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

educationpenetration-testingphishing+2
1484 years ago
WhoCord preview

WhoCord

GitHubsiv-nick/whocord

Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…

curated-resourcesdns-subdomain-enumerationeducation+8
843 months ago
mtk-su-reverse-cve-2020-0069 preview

mtk-su-reverse-cve-2020-0069

GitHubtherealjunior/mtk-su-reverse-cve-2020-0069

reversing mtk-su

android-securitybinary-exploitationeducation+3
176 years ago
tandasat.github.io preview

tandasat.github.io

GitHubtandasat/tandasat.github.io
educationlearning-paths-coursesreverse-engineering+2
193 months ago
osint-menace preview

osint-menace

GitHubawesom3alex/osint-menace
cryptographycurated-resourcesdns-analysis+5
91 month ago
CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form preview

CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form

GitHubgeorge0papasotiriou/cve-2026-11113-smtp-header-injection-in-contact-form
educationemail-securityexploitation+4
17 days ago
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubabc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

command-and-controleducationemail-security+9
2 months ago
Previous123Next