Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
57 days ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubhorkimhab/cve-2026-73570

Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

educationemail-securityexploitation+3
429 days ago
zeek preview

zeek

GitHubzeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

anomaly-detectionanti-botdefensive-tools+14
8.0k1 day ago
FiercePhish preview

FiercePhish

GitHubraikia/fiercephish

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

email-securitypenetration-testingphishing+2
1.4k2 years ago
decode-spam-headers preview

decode-spam-headers

GitHubmgeeky/decode-spam-headers

A script that helps you understand why your E-Mail ended up in Spam

email-securityinformation-gatheringlog-analysis+2
6987 months ago
paperweight preview

paperweight

GitHubwslyvh/paperweight

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

data-exfiltrationemail-securityincident-response+5
45113h 32m ago
SpoofcheckSelfTest preview

SpoofcheckSelfTest

GitHubbishopfox/spoofcheckselftest

Web application that lets you test if your domain is vulnerable to email spoofing

configuration-auditingdns-analysisemail-security+1
439 years ago
PasteMonitor preview

PasteMonitor

GitHubpixelbubble/pastemonitor

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.

email-securityinformation-gatheringosint+1
511 year ago
sigma preview

sigma

GitHubsigmahq/sigma

Main Sigma Rule Repository

anomaly-detectioncurated-resourcesdefensive-tools+9
11.1k1 day ago
IntelOwl preview

IntelOwl

GitHubintelowlproject/intelowl

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

curated-resourcesdigital-forensicsdynamic-analysis-sandboxing+14
4.7k22 days ago
ruler preview

ruler

GitHubsensepost/ruler

A tool to abuse Exchange services

email-securityexploitationinformation-gathering+3
2.3k2 years ago
inboxkitten preview

inboxkitten

GitHubuilicious/inboxkitten

Disposable email inbox powered by serverless mailgun kittens

anti-botemail-securitygeneral-purpose-utilities+1
5722 years ago
RedTeamScripts preview

RedTeamScripts

GitHubmr-un1k0d3r/redteamscripts

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

email-securityexploitationpassword-attacks+4
1485 years ago
Spoof_AnyMail preview

Spoof_AnyMail

GitHubhackerxphantom/spoof_anymail

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

email-securityimpersonation-toolspenetration-testing+3
1874 years ago
Email-Vulnerability-Checker preview

Email-Vulnerability-Checker

GitHubblack-scorp10/email-vulnerability-checker

Automated SPF and DMARC configuration checker that identifies email spoofing vulnerabilities across single or bulk domains using DNS lookups.

dns-analysisemail-securityinformation-gathering+1
982 years ago
HOCig1_2 preview

HOCig1_2

GitHubhackersonlineclub/hocig1_2

HOCig- Automatic HOC Information Gathering Tool V 1.2

dns-analysisemail-securityinformation-gathering+5
115 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdshabani96/cve-2024-21413

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP email delivery, malicious RTF attachment generation, and optional…

email-securityexploitationpayload-development+3
22 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdionissh/cve-2024-21413

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

email-securityexploitationpassword-cracking+3
8 months ago
Previous12Next