Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
hackingtool preview

hackingtool

GitHubz4nzu/hackingtool

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

cloud-securityexploitationforensics+9
79.3k
12 days ago
browser-identity-attacks-matrix preview

browser-identity-attacks-matrix

GitHubpushsecurity/browser-identity-attacks-matrix

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they…

curated-resourceseducationidentity-access-management+6
1.4k4 months ago
EmailXpose preview

EmailXpose

GitLabroxanne_ardary/emailxpose

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

ai-securitydynamic-analysis-sandboxingemail-security+8
8 days ago
ThePhish preview

ThePhish

GitHubemalderson/thephish

ThePhish: an automated phishing email analysis tool

digital-forensicsemail-securityincident-response+5
1.4k2 years ago
EvilOSX preview

EvilOSX

GitHubmarten4n6/evilosx

An evil RAT (Remote Administration Tool) for macOS / OS X.

command-and-controlinformation-gatheringpassword-cracking+6
2.4k5 years ago
CVE-2024-50964 preview

CVE-2024-50964

GitHubfdzdev/cve-2024-50964

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

educationemail-securitymisconfiguration+2
11 year ago
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubabc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

command-and-controleducationemail-security+9
3 months ago
cyberchef-recipes preview

cyberchef-recipes

GitHubmattnotmax/cyberchef-recipes

A list of cyber-chef recipes and curated links

curated-resourcesdigital-forensicsdisk-forensics+8
2.2k2 years ago
CyberThreatIntel preview

CyberThreatIntel

GitHubstrangerealintel/cyberthreatintel

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

curated-resourcesdigital-forensicsmalware-analysis+3
7253 years ago
analyzer preview

analyzer

GitHubqeeqbox/analyzer

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

digital-forensicsdynamic-analysis-sandboxingforensics+8
3212 years ago
svg_phishing_tools preview

svg_phishing_tools

GitHubhackinglz/svg_phishing_tools

SVG Analysis and generation tools for commonly seen SVG attachment phishing

dynamic-analysis-sandboxinginformation-gatheringmalware-analysis+5
5711 months ago
intelmq preview

intelmq

GitHubcerttools/intelmq

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

incident-responseinformation-gatheringintrusion-detection+6
1.1k4 months ago
opensquat preview

opensquat

GitHubatenreiro/opensquat

OSINT tool that detects domain squatting, typosquatting, and phishing look-alikes by monitoring newly registered domains against brand keywords with…

dns-analysisinformation-gatheringosint+2
9851 month ago
Phishious preview

Phishious

GitHubcaniphish/phishious

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

email-securityinformation-gatheringmisconfiguration+3
5183 years ago
malware-ioc preview

malware-ioc

GitHubprodaft/malware-ioc

This repository contains indicators of compromise (IOCs) of our various investigations.

curated-resourcesioc-managementmalware-analysis+2
32010 months ago
WebView2-Cookie-Stealer preview

WebView2-Cookie-Stealer

GitHubmrd0x/webview2-cookie-stealer

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

data-exfiltrationinformation-gatheringpassword-attacks+2
2654 years ago
claude-code-backdoor preview

claude-code-backdoor

GitHubs0ld13rr/claude-code-backdoor

Backdooring Claude Code via hooks in settings.json. Authorized use only!

educationmalware-analysispenetration-testing+4
864 months ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubshndnth/cve-2022-30190

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

command-and-controleducationexploitation+8
4 months ago
Previous12Next