Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
266 results
spamscanner preview

spamscanner

GitHubspamscanner/spamscanner

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

anti-botdynamic-analysis-sandboxingemail-security+6
375
8 months ago
TrickBot-Toolkit preview

TrickBot-Toolkit

GitHubmalwaretech/trickbot-toolkit

A collection of tools for dealing with TrickBot

command-and-controldata-exfiltrationinformation-gathering+3
2008 years ago
toastnotify-bof preview

toastnotify-bof

GitHubbrmkit/toastnotify-bof

abusing windows toast notifications for fun and user manipulation

information-gatheringpayload-developmentphishing+3
1041 month ago
EvilSlackbot preview

EvilSlackbot

GitHubdrew-sec/evilslackbot

A Slack bot phishing framework for Red Teaming exercises

data-exfiltrationinformation-gatheringpenetration-testing+4
1672 years ago
oauthseeker preview

oauthseeker

GitHubpraetorian-inc/oauthseeker

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

authenticationcloud-securityidentity-access-management+6
1791 year ago
Cooper preview

Cooper

GitHubchrismaddalena/cooper

A Python tool for ingesting HTML and producing HTML source suitable for phishing campaigns.

information-gatheringphishingphishing-tools+2
602 months ago
certstreamcatcher preview

certstreamcatcher

GitHubjimywork/certstreamcatcher

This tool is based on regex with effective standards for detecting phishing sites in real time using certstream and can also detect punycode (IDNA)…

information-gatheringosintphishing+2
807 years ago
Cartero preview

Cartero

GitHubmrbrutti/cartero

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

osint-social-engineeringpayload-generationphishing+2
499 years ago
Johnny-You-Are-Fired preview

Johnny-You-Are-Fired

GitHubrub-nds/johnny-you-are-fired

Artifacts for the USENIX publication.

cryptographyemail-securitypapers-research+3
566 years ago
goCabrito preview

goCabrito

GitHubkingsabri/gocabrito

Super organized and flexible script for sending phishing campaigns

email-harvestingpenetration-testingphishing+3
564 years ago
svg_phishing_tools preview

svg_phishing_tools

GitHubhackinglz/svg_phishing_tools

SVG Analysis and generation tools for commonly seen SVG attachment phishing

dynamic-analysis-sandboxinginformation-gatheringmalware-analysis+5
5711 months ago
detections preview

detections

GitHubdelivr-to/detections

A home for detection content developed by the delivr.to team

email-securityintrusion-detectionmalware-analysis+2
751 year ago
RTI-Toolkit preview

RTI-Toolkit

GitHubnickvourd/rti-toolkit

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

penetration-testingphishingphishing-tools+1
563 months ago
phishcollector preview

phishcollector

GitHubolizimmermann/phishcollector

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

crawlereducationinformation-gathering+8
236 months ago
OutlookNTLM_CVE-2023-23397 preview

OutlookNTLM_CVE-2023-23397

GitHubmuhammad-ali007/outlookntlm_cve-2023-23397

Exploit for CVE-2023-23397 Outlook NTLM hash leak via malicious calendar invitations. Includes PowerShell weaponization, Responder integration, and…

exploitationids-ips-evasionincident-response+4
223 years ago
WiFi-Pineapple-MK7_Evil-Portal preview

WiFi-Pineapple-MK7_Evil-Portal

GitHubtw-d/wifi-pineapple-mk7_evil-portal

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

penetration-testingphishingred-teaming+3
112 years ago
CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval- preview

CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval-

GitHubgeorge0papasotiriou/cve-2026-22005-oauth-2.0-device-code-phishing-short-interval-

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

authentication-authorizationeducationexploitation+4
27 days ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubkaleth4/cve-2022-30190

Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

command-and-controlexploitationpayload-generation+3
2 months ago
Previous1…456…15Next