Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
muraena preview

muraena

GitHubmuraenateam/muraena

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

impersonation-toolsphishingphishing-tools+3
1.1k
1 year ago
Mimic preview

Mimic

GitHub0x4meliorate/mimic

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

impersonation-toolspenetration-testingphishing+4
4618 days ago
Flash-player preview

Flash-player

GitHubianxtianxt/flash-player

flash钓鱼源码 中文+英文

impersonation-toolsinformation-gatheringphishing+2
336 years ago
SMSOTPBOT preview

SMSOTPBOT

GitHubghost-otpbot/smsotpbot

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

impersonation-toolsinformation-gatheringpenetration-testing+3
2164 years ago
SOGo_web_mail-vulnerability-CVE-2025-50340 preview

SOGo_web_mail-vulnerability-CVE-2025-50340

GitHubmillad7/sogo_web_mail-vulnerability-cve-2025-50340

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

email-securityimpersonation-toolspenetration-testing+3
1 year ago
CVE-2025-33053-Proof-Of-Concept preview

CVE-2025-33053-Proof-Of-Concept

GitHubdevbuihieu/cve-2025-33053-proof-of-concept

CVE-2025-33053 Proof Of Concept (PoC)

command-and-controlexploitationlateral-movement+6
631 year ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubdhananjayasj/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413, a critical Outlook RCE vulnerability that leaks NetNTLMv2 hashes via crafted file:// links, enabling…

exploitationlateral-movementpassword-cracking+3
3 months ago
CVE-2022-0165-EXPLOIT preview

CVE-2022-0165-EXPLOIT

GitHubk3ystr0k3r/cve-2022-0165-exploit

A PoC exploit for CVE-2022-0165 - Page Builder KingComposer WordPress Plugin - ID Parameter Validation Bypass

exploitationpenetration-testingphishing+3
13 years ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
1 year ago
TokenFlare preview

TokenFlare

GitHubjumpseclabs/tokenflare

Serverless AITM Simulation Framework for Entra ID and M365

authenticationcloud-securitycommand-and-control+6
2438 months ago
Tangled preview

Tangled

GitHubineesdv/tangled

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

command-and-controlemail-securitylateral-movement+5
2748 months ago
CVE-2024-34328 preview

CVE-2024-34328

GitHub0xsu3ks/cve-2024-34328

Proof-of-concept for open redirection via Host header manipulation in Sielox AnyWare 2.1.2 (CVE-2024-34328), with exploit steps, impact, and…

educationpapers-researchphishing+2
1 year ago
CVE-2025-33053_PoC preview

CVE-2025-33053_PoC

GitHub4n4s4zi/cve-2025-33053_poc

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

command-and-controlexploitationlateral-movement+3
11 year ago
CredSpy preview

CredSpy

GitHubredbyte1337/credspy

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

authenticationcloud-securityidentity-access-management+5
1701 month ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.8k3 months ago
eaphammer preview

eaphammer

GitHubs0lst1c3/eaphammer

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

lateral-movementpenetration-testingphishing+4
2.6k1 year ago
CredSniper preview

CredSniper

GitHubustayready/credsniper

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

authenticationimpersonation-toolsphishing+3
1.4k6 years ago
king-phisher preview

king-phisher

GitHubcrimsonforge-io/king-phisher

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

email-securityimpersonation-toolspenetration-testing+4
2.6k4 months ago
Previous12Next