Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
311 results
QRLJacking preview

QRLJacking

GitHubowasp/qrljacking

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

exploit-frameworkspenetration-testingphishing+2
1.6k
1 year ago
king-phisher preview

king-phisher

GitHubcrimsonforge-io/king-phisher

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

email-securityimpersonation-toolspenetration-testing+4
2.6k4 months ago
cyberchef-recipes preview

cyberchef-recipes

GitHubmattnotmax/cyberchef-recipes

A list of cyber-chef recipes and curated links

curated-resourcesdigital-forensicsdisk-forensics+8
2.2k2 years ago
Watcher preview

Watcher

GitHubthalesgroup-cert/watcher

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with…

ai-securitydata-exfiltrationdns-subdomain-enumeration+7
1.4k8 days ago
domainhunter preview

domainhunter

GitHubthreatexpress/domainhunter

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

command-and-controlinformation-gatheringosint+4
1.7k3 years ago
CredSniper preview

CredSniper

GitHubustayready/credsniper

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

authenticationimpersonation-toolsphishing+3
1.4k6 years ago
OffensiveVBA preview

OffensiveVBA

GitHubs3cur3th1ssh1t/offensivevba

This repo covers some code execution and AV Evasion methods for Macros in Office documents

curated-resourceseducationids-ips-evasion+7
1.3k4 years ago
intelmq preview

intelmq

GitHubcerttools/intelmq

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

incident-responseinformation-gatheringintrusion-detection+6
1.1k4 months ago
I-See-You preview

I-See-You

GitHubviralmaniar/i-see-you

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

educationinformation-gatheringosint+5
1.2k7 years ago
skills preview

skills

GitHubspecterops/skills

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

command-and-controleducationexploitation+9
62516 days ago
sublime-rules preview

sublime-rules

GitHubsublime-security/sublime-rules

Sublime rules for email attack detection, prevention, and threat hunting.

defensive-toolsemail-securityphishing+1
37521h 14m ago
FiercePhish preview

FiercePhish

GitHubraikia/fiercephish

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

email-securitypenetration-testingphishing+2
1.4k2 years ago
awesome-soc-analyst preview

awesome-soc-analyst

GitHubletsdefend/awesome-soc-analyst

Useful resources for SOC Analyst and SOC Analyst candidates.

curated-resourcesdigital-forensicseducation+6
1.0k3 years ago
BEAR-C2 preview

BEAR-C2

GitHubs3n4t0r-0x0/bear-c2

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

adversarial-attackcommand-and-controldata-exfiltration+8
6464 days ago
Zeek-Intelligence-Feeds preview

Zeek-Intelligence-Feeds

GitHubcriticalpathsecurity/zeek-intelligence-feeds

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

command-and-controlintrusion-detectionnetwork-security+3
4006 days ago
opensquat preview

opensquat

GitHubatenreiro/opensquat

OSINT tool that detects domain squatting, typosquatting, and phishing look-alikes by monitoring newly registered domains against brand keywords with…

dns-analysisinformation-gatheringosint+2
9851 month ago
Snoopy preview

Snoopy

GitHubsensepost/snoopy

Snoopy: A distributed tracking and data interception framework

malware-analysisnetwork-mappingosint+5
61213 years ago
CyberThreatIntel preview

CyberThreatIntel

GitHubstrangerealintel/cyberthreatintel

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

curated-resourcesdigital-forensicsmalware-analysis+3
7243 years ago
Previous123…18Next