Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
SECMON preview
Archived

SECMON

GitHubalb-uss/secmon

Automated infosec watching and vulnerability management tool with CVE polling, CPE-based matching, exploit search, RSS threat feed aggregation, and…

email-securityexploitationinformation-gathering+4
268
4 years ago
NtlmRelayToEWS preview

NtlmRelayToEWS

GitHubarno0x/ntlmrelaytoews

Relays NTLM authentication to Exchange Web Services for mailbox access, email sending, forwarding rule creation, and Outlook command execution via…

email-securityexploitationinformation-gathering+4
3328 years ago
crime-mapper preview

crime-mapper

GitHubmr-r3b00t/crime-mapper

Browser-based OSINT mapper for cyber crime: enriches IPs, domains, and emails via Shodan, Hudson Rock, and IPInfo; analyzes email headers/time deltas…

digital-forensicsemail-securityinformation-gathering+3
2417 months ago
CVE-2021-26855-d preview

CVE-2021-26855-d

GitHubmr-xn/cve-2021-26855-d

Python tool to exploit CVE-2021-26855 (ProxyLogon) for downloading Exchange mailbox emails via EWS, supporting user enumeration and bulk target…

email-securityexploitationinformation-gathering+3
65 years ago
SMTPTester preview

SMTPTester

GitHubxfreed0m/smtptester

small python3 tool to check common vulnerabilities in SMTP servers

email-securityinformation-gatheringpenetration-testing+1
1643 years ago
exchange-scanner preview

exchange-scanner

GitHubbishopfox/exchange-scanner

Identify public-facing Microsoft Exchange servers and determine their software versions

email-securityinformation-gatheringreconnaissance+3
12 months ago
ruler preview

ruler

GitHubsensepost/ruler

Abuse Exchange services via MAPI/HTTP or RPC/HTTP to enumerate users, create malicious mail rules, execute VBScript through Outlook forms/homepage,…

email-securityexploitationinformation-gathering+3
2.3k2 years ago
HOCig1_2 preview

HOCig1_2

GitHubhackersonlineclub/hocig1_2

HOCig- Automatic HOC Information Gathering Tool V 1.2

dns-analysisemail-securityinformation-gathering+5
115 years ago
IP-Biter preview

IP-Biter

GitHubdamianofalcioni/ip-biter

Open-source tracking framework that generates configurable tracking images and links for email, web, and chat systems, with a hacker-friendly…

email-securityinformation-gatheringosint+1
3261 year ago
spfmap preview

spfmap

GitHubbishopfox/spfmap

A program to map out SPF and DKIM records for a large number of domains

dns-analysisemail-securityinformation-gathering+2
4111 years ago
mxmap preview

mxmap

GitHubdavidhuser/mxmap

Automated pipeline that resolves Swiss municipality domains, scrapes websites for email addresses, and classifies email providers via MX, SPF, DKIM,…

dns-analysisemail-securityinformation-gathering+3
1217 days ago
Phishious preview

Phishious

GitHubcaniphish/phishious

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

email-securityinformation-gatheringmisconfiguration+3
5183 years ago
MailRipV2 preview

MailRipV2

GitHubdrpython3/mailripv2

Improved SMTP Checker / SMTP Cracker with proxy-support, inbox test and many more features.

email-securityinformation-gatheringpassword-attacks+1
2144 years ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubxaitax/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413 (MonikerLink) enabling remote code execution and NTLM credential leakage via crafted email links,…

email-securityexploitationinformation-gathering+5
7692 years ago
smtp_userenum preview

smtp_userenum

GitHubh3x0v3rl0rd/smtp_userenum

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

email-harvestingemail-securityinformation-gathering+4
1 year ago
quien preview

quien

GitHubretlehs/quien

A better whois and domain intelligence toolkit

dns-analysisemail-securityinformation-gathering+6
1.3k2 months ago
CVE-2021-26855-PoC preview

CVE-2021-26855-PoC

GitHubsrvaccount/cve-2021-26855-poc

Go-based PoC for CVE-2021-26855 (Exchange Server SSRF) enabling unauthenticated user enumeration, mail reading, and contact extraction via crafted…

email-securityexploitationinformation-gathering+3
175 years ago
TrashEmail preview

TrashEmail

GitHubrosehgal/trashemail

A hosted disposable email telegram bot; Extremely privacy friendly; Proudly hosted for community.

email-securityinformation-gatheringosint+1
5674 years ago
Previous12Next