Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
beef preview

beef

GitHubbeefproject/beef

The Browser Exploitation Framework Project

command-and-controlexploitationexploit-frameworks+8
11.0k3 days ago
cve-2023-23397-purple-team preview

cve-2023-23397-purple-team

GitHubpraneethnaidu1910-cmd/cve-2023-23397-purple-team

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

educationemail-securityexploitation+3
1 month ago
wordpress-rce-vapt-cve-2020-25213 preview

wordpress-rce-vapt-cve-2020-25213

GitHubcmadhushanka/wordpress-rce-vapt-cve-2020-25213

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

educationexploitationlabs-practice+6
4 months ago
toastfix-demo preview

toastfix-demo

GitHubh4lpy/toastfix-demo

Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with…

educationimpersonation-toolslabs-practice+5
185 months ago
PoC-CVE-2026-20841 preview

PoC-CVE-2026-20841

GitHubelenichristopoulou/poc-cve-2026-20841

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

exploitationphishingsocial-engineering+1
7 months ago
CVE-2025-22381 preview

CVE-2025-22381

GitHubpescada-dev/cve-2025-22381

Discovering CVE-2025-22381: Host Header Injection in the Aggie Open-Source Project

educationexploitationpassword-attacks+3
17 months ago
AdvPhishing preview

AdvPhishing

GitHubignitetch/advphishing

This is Advance Phishing Tool ! OTP PHISHING

educationimpersonation-toolsinformation-gathering+3
3.3k8 months ago
EvilNeko preview

EvilNeko

GitHubcorvralabs/evilneko

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

container-securitypenetration-testingphishing+3
808 months ago
CVE-2025-60378 preview

CVE-2025-60378

GitHubajansha/cve-2025-60378

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

educationexploitationphishing+3
11 months ago
Leantime-POC preview

Leantime-POC

GitHubdead1nfluence/leantime-poc

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

exploitationphishingvulnerability-analysis+2
1 year ago
CVE-2025-50363_BXSS_CVE preview

CVE-2025-50363_BXSS_CVE

GitHub1h3ll/cve-2025-50363_bxss_cve

Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

exploitationpenetration-testingphishing+3
1 year ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

educationexploitationlabs-practice+5
1 year ago
HiddenEyeReborn preview

HiddenEyeReborn

GitHubd4rks3c-group/hiddeneyereborn

HiddenEye Reborn in better shape than ever, rewritten from scratch and adapted to modern world

information-gatheringosint-social-engineeringpenetration-testing+3
7621 year ago
analyzer preview

analyzer

GitHubqeeqbox/analyzer

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

digital-forensicsdynamic-analysis-sandboxingforensics+8
3232 years ago
StalkPhish preview
Archived

StalkPhish

GitHubt4d/stalkphish

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

forensicsincident-responseinformation-gathering+3
6702 years ago
FullscreenBrowserPhishing preview

FullscreenBrowserPhishing

GitHubgmh5225/fullscreenbrowserphishing

PoC of the phishing through setting browser in the fullscreen mode

educationphishingphishing-tools+3
3 years ago
SocialFishMobile preview
Archived

SocialFishMobile

GitHubundeadsec/socialfishmobile

📱 🐟 An app to remote control SocialFish.

educationmobile-securityphishing+2
5853 years ago
Medusa preview

Medusa

GitHubascotbe/medusa

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

dns-analysisexploit-frameworkspayload-generation+4
2.2k3 years ago
Previous12Next