Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
mailinabox preview

mailinabox

GitHubmail-in-a-box/mailinabox

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

configuration-auditingdefensive-toolsemail-security+3
15.4k
1 day ago
paperweight preview

paperweight

GitHubwslyvh/paperweight

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

data-exfiltrationemail-securityincident-response+5
4572 days ago
WhoAmIMailBot preview

WhoAmIMailBot

GitHubmthbernardes/whoamimailbot

Self-hosted email alias masking service using Postfix and Telegram bot to create disposable addresses for signups, with full control over email…

authenticationemail-securityprivacy+1
688 years ago
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
54 days ago
CVE-2020-1349 preview

CVE-2020-1349

GitHub0neb1n/cve-2020-1349

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…

binary-exploitationemail-securityexploitation+2
116 years ago
Evilginx-Phishing-Infra-Setup preview

Evilginx-Phishing-Infra-Setup

GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

command-and-controlcurated-resourceseducation+6
6081 year ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6404 years ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubwyatu/cve-2018-8581

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

email-securityexploitationlateral-movement+4
3307 years ago
Tangled preview

Tangled

GitHubineesdv/tangled

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

command-and-controlemail-securitylateral-movement+5
2769 months ago
BadOutlook preview

BadOutlook

GitHubaahmad097/badoutlook

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

command-and-controlemail-securityexploitation+3
1375 years ago
smtpshell preview

smtpshell

GitHubmachine1337/smtpshell

A simple Reverse Shell that can communicate through Gmail SMTP or any other SMTP to evade network restrictions

command-and-controlemail-securityred-teaming+1
82 years ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubjishino567/cve-2026-73570

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

email-securityexploitationpenetration-testing+3
21 month ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
21 month ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubqiantu88/cve-2018-8581

CVE-2018-8581

email-securityexploitationpenetration-testing+3
57 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubabc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

command-and-controleducationemail-security+9
4 months ago
Shadow-Vault preview

Shadow-Vault

GitHubjenderal92/shadow-vault

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

authentication-authorizationemail-securityidentity-access-management+3
4 months ago
CVE-2025-43920 preview

CVE-2025-43920

GitHub0nyx-my7h/cve-2025-43920

PoC and technical write-up for CVE-2025-43920, a remote command injection in GNU Mailman 2.1.39's external archiver allowing unauthenticated code…

command-and-controlemail-securityexploitation+3
11 year ago