Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
Phishious preview

Phishious

GitHubcaniphish/phishious

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

email-securityinformation-gatheringmisconfiguration+3
515
3 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdshabani96/cve-2024-21413

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP email delivery, malicious RTF attachment generation, and optional…

email-securityexploitationpayload-development+3
22 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdionissh/cve-2024-21413

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

email-securityexploitationpassword-cracking+3
7 months ago
Mailphish preview

Mailphish

GitHubmcracker2002/mailphish

Creates professional phishing emails with 20+ templates for credential harvesting, including HTML generation and direct email delivery to targets.

email-securityphishingphishing-tools+1
5 years ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
6463 days ago
spamscanner preview

spamscanner

GitHubspamscanner/spamscanner

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

anti-botdynamic-analysis-sandboxingemail-security+6
3748 months ago
Cartero preview

Cartero

GitHubmrbrutti/cartero

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

osint-social-engineeringpayload-generationphishing+2
496 months ago
CVE-2024-21378 preview

CVE-2024-21378

GitHubd0rb/cve-2024-21378

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

educationemail-securityexploitation+4
92 years ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

exploitationphishingreconnaissance+2
11 days ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
1 year ago
CVE-2024-50964 preview

CVE-2024-50964

GitHubfdzdev/cve-2024-50964

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

educationemail-securitymisconfiguration+2
11 year ago
CVE-2023-48104 preview

CVE-2023-48104

GitHube1tex/cve-2023-48104

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

exploitationphishingvulnerability-analysis+2
2 years ago
goCabrito preview

goCabrito

GitHubkingsabri/gocabrito

Super organized and flexible script for sending phishing campaigns

email-harvestingpenetration-testingphishing+3
554 years ago
Phishing-Simulation preview

Phishing-Simulation

GitHubjenyraval/phishing-simulation

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

educationpenetration-testingphishing+2
1484 years ago
CredSpy preview

CredSpy

GitHubredbyte1337/credspy

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

authenticationcloud-securityidentity-access-management+5
1721 month ago
CVE-2023-51764 preview

CVE-2023-51764

GitHubduy-31/cve-2023-51764

Postfix SMTP Smuggling - Expect Script POC

educationemail-securityexploitation+3
232 years ago
Blind-Trust-CVE-2024-21413-Research preview

Blind-Trust-CVE-2024-21413-Research

GitHubh1ssbl1tz/blind-trust-cve-2024-21413-research

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

educationemail-securityexploitation+7
2 months ago
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubabc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

command-and-controleducationemail-security+9
3 months ago
Previous1234Next