Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
phishurl-list preview

phishurl-list

GitHubjpcertcc/phishurl-list

Curated dataset of confirmed phishing URLs from JPCERT/CC, including confirmation date, full URL, and spoofed brand for threat intelligence and…

curated-resourcesphishingthreat-feeds-aggregators+1
210
1 month ago
Zeek-Intelligence-Feeds preview

Zeek-Intelligence-Feeds

GitHubcriticalpathsecurity/zeek-intelligence-feeds

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

command-and-controlintrusion-detectionnetwork-security+3
39920 hours ago
MITMer preview

MITMer

GitHubhusam212/mitmer

Automated man-in-the-middle attack tool.

dns-analysisnetwork-securitypacket-sniffing-analysis+5
5311 years ago
TrickBot-Toolkit preview

TrickBot-Toolkit

GitHubmalwaretech/trickbot-toolkit

A collection of tools for dealing with TrickBot

command-and-controldata-exfiltrationinformation-gathering+3
2018 years ago
SMSOTPBOT preview

SMSOTPBOT

GitHubghost-otpbot/smsotpbot

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

impersonation-toolsinformation-gatheringpenetration-testing+3
2123 years ago
Email-exploit-Moniker-Link-CVE-2024-21413- preview

Email-exploit-Moniker-Link-CVE-2024-21413-

GitHubyass2400012/email-exploit-moniker-link-cve-2024-21413-
educationemail-securityexploitation+6
11 months ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubshndnth/cve-2022-30190

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

command-and-controleducationexploitation+8
4 months ago
huntglyph preview

huntglyph

GitHubgregory-chatelier/huntglyph

Detect visually similar characters (homoglyphs) and hidden data in text to protect against deceptive attacks

dns-analysisinformation-gatheringosint+3
18 months ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdshabani96/cve-2024-21413
email-securityexploitationpayload-development+3
22 years ago
ms-photos_NTLM_Leak preview

ms-photos_NTLM_Leak

GitHubrubenformation/ms-photos_ntlm_leak

New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click

educationexploitationlateral-movement+4
2099 months ago
CVE-2024-57428 preview

CVE-2024-57428

GitHubahrixia/cve-2024-57428

CVE-2024-57428: PHPJabbers Cinema Booking System v2.0 suffers from stored XSS, enabling persistent JavaScript injection for phishing and malware…

exploitationpenetration-testingphishing+2
1 year ago
CVE-2021-24563 preview

CVE-2021-24563

GitHubv35hr4j/cve-2021-24563

The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing…

exploitationpenetration-testingphishing+2
14 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdionissh/cve-2024-21413
email-securityexploitationpassword-cracking+3
6 months ago
Tangled preview

Tangled

GitHubineesdv/tangled

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

command-and-controlemail-securitylateral-movement+5
2758 months ago
irgc-whatsapp-phishkit preview

irgc-whatsapp-phishkit

GitHubnarimangharib/irgc-whatsapp-phishkit

Analysis of state-sponsored WhatsApp phishing infrastructure with real-time QR hijacking and device surveillance

mobile-securityosintphishing+3
107 months ago
class_struggle preview

class_struggle

GitHubartur-augustyniak/class_struggle
anomaly-detectiondns-analysiseducation+4
29 months ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks…

educationexploitationlabs-practice+5
1 year ago
Previous123Next