Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
209 results
CVE-2024-39929 preview

CVE-2024-39929

GitHubrxerium/cve-2024-39929

Detection method for Exim vulnerability CVE-2024-39929

email-securityexploitationpenetration-testing+2
3
10 months ago
CVE-2020-7247-POC preview

CVE-2020-7247-POC

GitHubsimonschoeni/cve-2020-7247-poc

Proof of concept for CVE-2020-7247 for educational purposes.

educationemail-securityexploitation+3
24 years ago
CVE-2023-51764-POC preview

CVE-2023-51764-POC

GitHubd4op/cve-2023-51764-poc

Python 3 proof-of-concept for CVE-2023-51764 SMTP smuggling vulnerability, enabling email spoofing via crafted SMTP sessions.

email-securityexploitationpayload-development+2
12 years ago
CVE-2018-15131 preview

CVE-2018-15131

GitHub0x00-0x00/cve-2018-15131

Zimbra Collaboration Suite Username Enumeration

email-securityinformation-gatheringosint+2
18 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubjacquesquail/cve-2023-23397

Proof-of-concept exploit for CVE-2023-23397, a Microsoft Outlook privilege escalation vulnerability. Sends a crafted email with a malicious UNC path…

email-securityexploitationpenetration-testing+2
3 years ago
SimpleEmailSpoofer preview
Archived

SimpleEmailSpoofer

GitHublunarca/simpleemailspoofer

A simple Python CLI to spoof emails.

email-securityosint-social-engineeringpenetration-testing+3
5624 years ago
mailchecker preview

mailchecker

GitHubfgribreau/mailchecker

:mailbox: Cross-language temporary (disposable/throwaway) email detection library. Covers 55 734+ fake email providers.

anti-botemail-security
1.9k10h 38m ago
yara-x preview

yara-x

GitHubvirustotal/yara-x

A rewrite of YARA in Rust.

binary-analysisdata-recoverydefensive-tools+14
1.3k10 days ago
o365-attack-toolkit preview

o365-attack-toolkit

GitHubmdsecactivebreach/o365-attack-toolkit

A toolkit to attack Office365

cloud-securitydata-exfiltrationemail-security+5
1.1k5 years ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubxaitax/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

email-securityexploitationinformation-gathering+5
7712 years ago
decode-spam-headers preview

decode-spam-headers

GitHubmgeeky/decode-spam-headers

A script that helps you understand why your E-Mail ended up in Spam

email-securityinformation-gatheringlog-analysis+2
7006 months ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubwyatu/cve-2018-8581

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

email-securityexploitationlateral-movement+4
3317 years ago
TrashEmail preview

TrashEmail

GitHubrosehgal/trashemail

A hosted disposable email telegram bot; Extremely privacy friendly; Proudly hosted for community.

email-securityinformation-gatheringosint+1
5674 years ago
NtlmRelayToEWS preview

NtlmRelayToEWS

GitHubarno0x/ntlmrelaytoews

ntlm relay attack to Exchange Web Services

email-securityexploitationinformation-gathering+4
3328 years ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3058 years ago
SpoofThatMail preview

SpoofThatMail

GitHubv4d1/spoofthatmail

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

dns-analysisemail-securityphishing-tools+1
3344 years ago
CVE-2023-23397-POC-Powershell preview

CVE-2023-23397-POC-Powershell

GitHubapi0cradle/cve-2023-23397-poc-powershell

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…

data-exfiltrationemail-securityexploitation+3
3453 years ago
inboxkitten preview

inboxkitten

GitHubuilicious/inboxkitten

Disposable email inbox powered by serverless mailgun kittens

anti-botemail-securitygeneral-purpose-utilities+1
5722 years ago
Previous1…789…12Next