Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
mailinabox preview

mailinabox

GitHubmail-in-a-box/mailinabox

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

configuration-auditingdefensive-toolsemail-security+3
15.4k
4 days ago
CVE-2023-23397-POC-Powershell preview

CVE-2023-23397-POC-Powershell

GitHubapi0cradle/cve-2023-23397-poc-powershell

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…

data-exfiltrationemail-securityexploitation+3
3453 years ago
inboxkitten preview

inboxkitten

GitHubuilicious/inboxkitten

Disposable email inbox powered by serverless mailgun kittens

anti-botemail-securitygeneral-purpose-utilities+1
5722 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtrackflaw/cve-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

email-securityexploitationpassword-attacks+3
1323 years ago
CVE-2020-16947 preview

CVE-2020-16947

GitHub0neb1n/cve-2020-16947

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

binary-exploitationemail-securityexploitation+3
1225 years ago
IMAPLoginTester preview

IMAPLoginTester

GitHubrm1984/imaplogintester

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

email-securityinformation-gatheringpassword-attacks+1
732 years ago
detections preview

detections

GitHubdelivr-to/detections

A home for detection content developed by the delivr.to team

email-securityintrusion-detectionmalware-analysis+2
751 year ago
PasteMonitor preview

PasteMonitor

GitHubpixelbubble/pastemonitor

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.

email-securityinformation-gatheringosint+1
511 year ago
CVE-2020-1493 preview

CVE-2020-1493

GitHub0neb1n/cve-2020-1493

Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

binary-exploitationemail-securityexploitation+3
256 years ago
Ashwesker-CVE-2025-68645 preview

Ashwesker-CVE-2025-68645

GitHubashwesker/ashwesker-cve-2025-68645

POC BLH Magelang CSIRT 2026 by babyrootkid

email-securityexploitationvulnerability-analysis+2
29 days ago
EmailXpose preview

EmailXpose

GitLabroxanne_ardary/emailxpose

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

ai-securitydynamic-analysis-sandboxingemail-security+8
9 days ago
CYBERDUDEBIVASH-Cisco-AsyncOS-CVE-2025-20393-Scanner preview

CYBERDUDEBIVASH-Cisco-AsyncOS-CVE-2025-20393-Scanner

GitHubcyberdudebivash/cyberdudebivash-cisco-asyncos-cve-2025-20393-scanner

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

email-securityexploitationincident-response+4
7 months ago
smtp_userenum preview

smtp_userenum

GitHubh3x0v3rl0rd/smtp_userenum

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

email-harvestingemail-securityinformation-gathering+4
1 year ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubbyt3l0rd/cve-2026-73570

Python proof-of-concept for testing SMTP command injection (CVE-2026-73570) by sending malformed RCPT TO addresses to detect shell command…

email-securityexploitationpenetration-testing+2
3 days ago
suricata preview

suricata

GitHuboisf/suricata

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

anomaly-detectionanti-botdefensive-tools+9
6.6k1 day ago
rspamd preview

rspamd

GitHubrspamd/rspamd

Spam filtering and email processing framework with regex rules, statistical analysis, custom Lua plugins, and external blocklists for MTA integration.

defensive-toolsemail-securityphishing+1
2.5k17h 27m ago
mailchecker preview

mailchecker

GitHubfgribreau/mailchecker

:mailbox: Cross-language temporary (disposable/throwaway) email detection library. Covers 55 734+ fake email providers.

anti-botemail-security
1.9k8 days ago
o365-attack-toolkit preview

o365-attack-toolkit

GitHubmdsecactivebreach/o365-attack-toolkit

A toolkit to attack Office365

cloud-securitydata-exfiltrationemail-security+5
1.1k5 years ago
Previous12Next