Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
98 results
CVE-2018-15131 preview

CVE-2018-15131

GitHub0x00-0x00/cve-2018-15131

Zimbra Collaboration Suite Username Enumeration

email-securityinformation-gatheringosint+2
1
8 years ago
cve-2024-21413-outlook-monikerlink-lab preview

cve-2024-21413-outlook-monikerlink-lab

GitHubviniciusfariasdev/cve-2024-21413-outlook-monikerlink-lab

Educational lab and PoC demonstrating CVE-2024-21413 Outlook Moniker Link attack to leak netNTLMv2 hashes via crafted HTML email.

educationemail-securityexploitation+3
7 months ago
EmailXpose preview

EmailXpose

GitLabroxanne_ardary/emailxpose

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

ai-securitydynamic-analysis-sandboxingemail-security+8
18 days ago
BadOutlook preview

BadOutlook

GitHubaahmad097/badoutlook

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

command-and-controlemail-securityexploitation+3
1375 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtrackflaw/cve-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

email-securityexploitationpassword-attacks+3
1323 years ago
cve-2026-45185-detection-script preview

cve-2026-45185-detection-script

GitHubmateraj2/cve-2026-45185-detection-script

These detection scripts are property of the SECPlayground Platform. Two safe detection scripts. Neither drives the close_notify-mid-BDAT trigger, so…

email-securityexploitationnetwork-security+3
4 months ago
espoofer preview

espoofer

GitHubchenjj/espoofer

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

educationemail-securitypapers-research+3
1.7k4 years ago
tmpmail preview

tmpmail

GitHubsdushantha/tmpmail

A temporary email right from your terminal written in POSIX sh

email-securitygeneral-purpose-utilitiesprivacy
4.2k4 years ago
StickyExim preview

StickyExim

GitHubbrets0150/stickyexim

Exim Honey Pot for CVE-2019-10149 exploit attempts.

email-securityincident-responsethreat-intelligence+1
37 years ago
CVE-2025-30349 preview

CVE-2025-30349

GitHubnatasaka/cve-2025-30349

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

email-securityexploitationphishing-tools+2
21 year ago
king-phisher preview

king-phisher

GitHubcrimsonforge-io/king-phisher

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

email-securityimpersonation-toolspenetration-testing+4
2.6k4 months ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtiepologian/cve-2023-23397

Proof of Concept for CVE-2023-23397 in Python

email-securityexploitationpayload-generation+3
253 years ago
Moniker-Link-CVE-2024-21413 preview

Moniker-Link-CVE-2024-21413

GitHubmqkgithub/moniker-link-cve-2024-21413

Step-by-step walkthrough of exploiting CVE-2024-21413 in Microsoft Outlook to bypass Protected View and leak NTLM credentials via Moniker Links,…

ctfeducationemail-security+5
1 year ago
crime-mapper preview

crime-mapper

GitHubmr-r3b00t/crime-mapper

A tool for mapping cyber crime

digital-forensicsemail-securityinformation-gathering+3
2427 months ago
CVE-2026-31283 preview

CVE-2026-31283

GitHubsaykino/cve-2026-31283

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

api-securityeducationemail-security+3
5 months ago
IP-Biter preview

IP-Biter

GitHubdamianofalcioni/ip-biter

IP-Biter: The Hacker-friendly E-Mail (but not only) Tracking Framework

email-securityinformation-gatheringosint+1
3271 year ago
spamscanner preview

spamscanner

GitHubspamscanner/spamscanner

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

anti-botdynamic-analysis-sandboxingemail-security+6
3738 months ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
21 month ago
Previous123456Next