Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
CVE-2020-16947 preview

CVE-2020-16947

GitHub0neb1n/cve-2020-16947

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

binary-exploitationemail-securityexploitation+3
122
5 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
CVE-2020-1493 preview

CVE-2020-1493

GitHub0neb1n/cve-2020-1493

Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

binary-exploitationemail-securityexploitation+3
256 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubth3hellion/cve-2024-21413

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

email-securityexploitationpayload-generation+2
2 years ago
BadOutlook preview

BadOutlook

GitHubaahmad097/badoutlook

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

command-and-controlemail-securityexploitation+3
1375 years ago
LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubc-g-creator/letsdefend-soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

ctfeducationemail-security+6
5 months ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6384 years ago
Spoofy preview

Spoofy

GitHubmattkeeley/spoofy

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

dns-analysisemail-securitypenetration-testing+1
7726 days ago
msmailprobe preview

msmailprobe

GitHubbusterb/msmailprobe

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…

email-securityinformation-gatheringosint+2
2048 years ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
21 month ago
Moniker-Link-CVE-2024-21413- preview

Moniker-Link-CVE-2024-21413-

GitHubhau2212/moniker-link-cve-2024-21413-

Educational exploit for CVE-2024-21413 (Moniker Link) demonstrating Outlook RCE and NTLM credential leak via crafted hyperlinks, with detection and…

educationemail-securityexploitation+3
10 months ago
ThePhish preview

ThePhish

GitHubemalderson/thephish

ThePhish: an automated phishing email analysis tool

digital-forensicsemail-securityincident-response+5
1.4k2 years ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

anomaly-detectiondigital-forensicsdisk-forensics+11
3.8k8 months ago
Tyr preview

Tyr

GitHubjb-selfcompany/tyr

True P2P Email on top of Yggdrasil Network for Android

android-securityauthenticationemail-security+4
3492 months ago
CVE-2019-10149 preview

CVE-2019-10149

GitHubdarsigovrustam/cve-2019-10149

Instructions for installing a vulnerable version of Exim and its expluatation

educationemail-securityexploitation+3
56 years ago
CVE-2023-51764-POC preview

CVE-2023-51764-POC

GitHubd4op/cve-2023-51764-poc

Python 3 proof-of-concept for CVE-2023-51764 SMTP smuggling vulnerability, enabling email spoofing via crafted SMTP sessions.

email-securityexploitationpayload-development+2
12 years ago
king-phisher preview

king-phisher

GitHubcrimsonforge-io/king-phisher

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

email-securityimpersonation-toolspenetration-testing+4
2.6k5 months ago
SOC-Analyst-Portfolio preview

SOC-Analyst-Portfolio

GitHub0x0allenace/soc-analyst-portfolio

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

anomaly-detectioncurated-resourcesdigital-forensics+8
21 month ago
Previous123Next