Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
CVE-2026-43914-PoC preview

CVE-2026-43914-PoC

GitHubboreas37/cve-2026-43914-poc

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

exploitationpassword-attackspenetration-testing+2
1
25 days ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubsariamubeen/cve-2023-7028

Python exploit for CVE-2023-7028, abusing GitLab password reset poisoning to take over accounts including administrators via crafted email requests.

educationexploitationpassword-attacks+3
31 year ago
CVE-2025-10658 preview

CVE-2025-10658

GitHubjfriedli/cve-2025-10658

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

authenticationexploitationpassword-attacks+3
15 months ago
IMAPLoginTester preview

IMAPLoginTester

GitHubrm1984/imaplogintester

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

email-securityinformation-gatheringpassword-attacks+1
732 years ago
sudo-snooper preview

sudo-snooper

GitHubxorond/sudo-snooper

Python script that acts like the original sudo binary to fool users into entering their passwords

password-attackspenetration-testingphishing-tools+1
706 years ago
LaZagne preview

LaZagne

GitHubalessandroz/lazagne

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

encryption-decryption-toolsforensicshash-analysis+8
11.0k1 year ago
wildlogger preview

wildlogger

GitHubmustafadalga/wildlogger

This is a keylogger that collects all the data and e-mail it in a set time with system information which includes device S/N and hardware specs,…

data-exfiltrationinformation-gatheringpassword-attacks+1
4610 months ago
cve-2023-23397 preview

cve-2023-23397

GitHubbronzebee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

email-securityexploitationpassword-attacks+3
143 years ago
CVE-2025-4796 preview

CVE-2025-4796

GitHubanothersec/cve-2025-4796

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

exploitationpassword-attackspenetration-testing+3
110 months ago
CVE-2023-32243-Detection-and-Mitigation-in-WordPress preview

CVE-2023-32243-Detection-and-Mitigation-in-WordPress

GitHubdev0558/cve-2023-32243-detection-and-mitigation-in-wordpress

Educational lab demonstrating detection and mitigation of CVE-2023-32243 privilege escalation in WordPress Essential Addons for Elementor, using…

educationexploitationlabs-practice+6
1 year ago
Cr3dOv3r preview

Cr3dOv3r

GitHubd4vinci/cr3dov3r

Know the dangers of credential reuse attacks.

information-gatheringosintpassword-attacks+1
2.1k9 months ago
datasploit preview

datasploit

GitHubdatasploit/datasploit

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

dns-subdomain-enumerationemail-harvestinginformation-gathering+6
3.3k10 months ago
Slackor preview

Slackor

GitHubcoalfire-research/slackor

A Golang implant that uses Slack as a command and control server

command-and-controllateral-movementpassword-attacks+8
4606 years ago
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
25 years ago
SprayingToolkit preview
Archived

SprayingToolkit

GitHubbyt3bl33d3r/sprayingtoolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient

email-harvestinginformation-gatheringosint-social-engineering+4
1.6k3 years ago
MailRipV2 preview

MailRipV2

GitHubdrpython3/mailripv2

Improved SMTP Checker / SMTP Cracker with proxy-support, inbox test and many more features.

email-securityinformation-gatheringpassword-attacks+1
2134 years ago
CVE-2023-23397-PoW preview

CVE-2023-23397-PoW

GitHubtheunknownsoul/cve-2023-23397-pow

Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.

email-securityexploitationpassword-attacks+3
12 years ago
iKy preview

iKy

GitHubkennbroorg/iky

OSINT Project. Collect information from a mail. Gather. Profile. Timeline.

data-exfiltrationemail-harvestinginformation-gathering+5
9812 months ago
Previous123Next