Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
frameless-bitb preview

frameless-bitb

GitHubwaelmas/frameless-bitb

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

educationids-ips-evasionphishing+3
455
2 years ago
research preview

research

GitHubalessandrobertoldi/research

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

authenticationcurated-resourcesdns-subdomain-enumeration+5
4 months ago
SMSOTPBOT preview

SMSOTPBOT

GitHubghost-otpbot/smsotpbot

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

impersonation-toolsinformation-gatheringpenetration-testing+3
2164 years ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.7k3 days ago
sherlock preview

sherlock

GitHubsherlock-project/sherlock

Hunt down social media accounts by username across social networks

digital-forensicsemail-harvestingforensics+11
91.0k1 month ago
trape preview

trape

GitHubjofpin/trape

People tracker on the Internet: OSINT analysis and research tool by Jose Pino

educationinformation-gatheringosint+3
9.0k5 years ago
opensquat preview

opensquat

GitHubatenreiro/opensquat

OSINT tool that detects domain squatting, typosquatting, and phishing look-alikes by monitoring newly registered domains against brand keywords with…

dns-analysisinformation-gatheringosint+2
9851 month ago
Umbrella_android preview

Umbrella_android

GitHubsecurityfirst/umbrella_android

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

digital-forensicseducationencryption-decryption-tools+6
2922 years ago
Phishing-Simulation preview

Phishing-Simulation

GitHubjenyraval/phishing-simulation

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

educationpenetration-testingphishing+2
1474 years ago
detections preview

detections

GitHubdelivr-to/detections

A home for detection content developed by the delivr.to team

email-securityintrusion-detectionmalware-analysis+2
751 year ago
Abused-Legitimate-Services preview

Abused-Legitimate-Services

GitHubbushidouk/abused-legitimate-services

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

curated-resourcespapers-researchphishing+2
603 years ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
CVE-2017-5415 preview

CVE-2017-5415

GitHub649/cve-2017-5415

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…

phishingsocial-engineeringweb-application-exploitation+1
79 years ago
EmailXpose preview

EmailXpose

GitLabroxanne_ardary/emailxpose

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

ai-securitydynamic-analysis-sandboxingemail-security+8
9 days ago
CVE-2021-24545 preview

CVE-2021-24545

GitHubv35hr4j/cve-2021-24545

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

exploitationpenetration-testingphishing+3
24 years ago
CVE-2024-34568 preview

CVE-2024-34568

GitHubsanupl/cve-2024-34568

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

exploitationphishingvulnerability-analysis+2
13 months ago
CVE-2025-3568 preview

CVE-2025-3568

GitHubshellkraft/cve-2025-3568

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

exploitationphishingprivilege-escalation+3
1 year ago
CVE-2024-3867 preview

CVE-2024-3867

GitHubc4cnm/cve-2024-3867

This repository shows u some information on this vulnerability, which were found by me.

educationexploitationphishing+3
2 years ago
Previous123Next