Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
bettercap preview

bettercap

GitHubbettercap/bettercap

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

bluetooth-securitydata-exfiltrationfingerprint-spoofing+16
19.9k
16 days ago
social-engineer-toolkit preview

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

exploitationexploit-frameworksimpersonation-tools+9
15.2k2 months ago
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k3 months ago
thermoptic preview

thermoptic

GitHubmandatoryprogrammer/thermoptic

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

anti-botcaptcha-bypasscrawler+5
1.0k5 months ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
5619 days ago
RIUS preview

RIUS

GitHubzadewg/rius

CVE-2020-20093; 20094; 20095; 20096, 2022-28345 RTLO Injection URI Spoofing

ids-ips-evasionimpersonation-toolsphishing+3
864 years ago
evilginx2 preview

evilginx2

GitHubkgretzky/evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

impersonation-toolspenetration-testingphishing+4
15.5k2 months ago
Modlishka preview

Modlishka

GitHubdrk1wi/modlishka

Modlishka. Reverse Proxy.

authenticationimpersonation-toolspenetration-testing+6
5.4k15 days ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.8k3 months ago
nodriver preview

nodriver

GitHubultrafunkamsterdam/nodriver

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

anti-botcaptcha-bypasscrawler+8
4.7k3 months ago
BITB preview

BITB

GitHubmrd0x/bitb

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

impersonation-toolsphishingphishing-tools+2
2.9k4 years ago
CredSniper preview

CredSniper

GitHubustayready/credsniper

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

authenticationimpersonation-toolsphishing+3
1.4k6 years ago
Prox-Ez preview

Prox-Ez

GitHubsynacktiv/prox-ez

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

authenticationimpersonation-toolslateral-movement+4
1112 months ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
376 years ago
impersonate-proxy preview

impersonate-proxy

GitHubytkoka/impersonate-proxy

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

fingerprint-spoofingimpersonation-toolspenetration-testing+3
378 days ago
CVE-2019-13498 preview

CVE-2019-13498

GitHubfurqankhan1/cve-2019-13498

CVE-2019-13498

exploitationids-ips-evasionimpersonation-tools+3
96 years ago
pocKeycloakCVE-2023-0264 preview

pocKeycloakCVE-2023-0264

GitHubeliangonzi00/pockeycloakcve-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

authenticationdefensive-toolsexploitation+7
1 month ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubx48ps/cve-2026-8181

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

api-securityauthenticationexploitation+3
3 months ago
Previous12Next