Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
209 results
flyphish preview

flyphish

GitHubvirtualsamuraii/flyphish

Deploy a phishing infrastructure on the fly.

cloud-infrastructure-securityemail-securitypenetration-testing+3
80
1 year ago
ThePhish preview

ThePhish

GitHubemalderson/thephish

ThePhish: an automated phishing email analysis tool

digital-forensicsemail-securityincident-response+5
1.4k2 years ago
training-security-awareness preview

training-security-awareness

GitHubransomleak/training-security-awareness

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

ai-securityeducationemail-security+5
1901 month ago
overlord preview

overlord

GitHubqsecure-labs/overlord

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

cloud-securitycommand-and-controlemail-security+3
6394 years ago
king-phisher preview

king-phisher

GitHubcrimsonforge-io/king-phisher

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

email-securityimpersonation-toolspenetration-testing+4
2.6k4 months ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

anomaly-detectiondigital-forensicsdisk-forensics+11
3.8k7 months ago
Spoofy preview

Spoofy

GitHubmattkeeley/spoofy

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

dns-analysisemail-securitypenetration-testing+1
7719 months ago
msmailprobe preview

msmailprobe

GitHubbusterb/msmailprobe

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…

email-securityinformation-gatheringosint+2
2048 years ago
Tyr preview

Tyr

GitHubjb-selfcompany/tyr

True P2P Email on top of Yggdrasil Network for Android

android-securityauthenticationemail-security+4
3481 month ago
IMAPLoginTester preview

IMAPLoginTester

GitHubrm1984/imaplogintester

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

email-securityinformation-gatheringpassword-attacks+1
732 years ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
224 days ago
tryhackme-moniker-link preview

tryhackme-moniker-link

GitHubyfelipecruvinel/tryhackme-moniker-link

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

educationemail-securityexploitation+3
25 days ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
Moniker-Link--CVE-2024-21413- preview

Moniker-Link--CVE-2024-21413-

GitHubbhatbhupendra/moniker-link--cve-2024-21413-

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

educationemail-securityexploitation+7
4 months ago
LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubc-g-creator/letsdefend-soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

ctfeducationemail-security+6
4 months ago
SOGo_web_mail-vulnerability-CVE-2025-50340 preview

SOGo_web_mail-vulnerability-CVE-2025-50340

GitHubmillad7/sogo_web_mail-vulnerability-cve-2025-50340

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

email-securityimpersonation-toolspenetration-testing+3
1 year ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubth3hellion/cve-2024-21413

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

email-securityexploitationpayload-generation+2
2 years ago
smtp_userenum preview

smtp_userenum

GitHubh3x0v3rl0rd/smtp_userenum

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

email-harvestingemail-securityinformation-gathering+4
1 year ago
Previous12…12Next