Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
Facad1ng preview

Facad1ng

GitHubspyboy-productions/facad1ng

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

defensive-toolseducationphishing+3
529
9 months ago
maskphish preview

maskphish

GitHubjaykali/maskphish

Introducing "URL Making Technology" to the world for the very FIRST TIME. Give a Mask to Phishing URL like a PRO.. A MUST have tool for Phishing.

educationphishingsocial-engineering
3.2k1 year ago
URL_CHECKER preview

URL_CHECKER

GitHubmannansainicyber/url_checker

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

api-security-testingeducationmachine-learning+3
16 months ago
lxancephisher preview

lxancephisher

GitHublxance-hacker/lxancephisher

Automated phishing simulation tool with 30+ login page templates, URL masking, and multiple tunneling options (Ngrok, Cloudflared, Serveo) for…

educationphishingphishing-tools+1
291 year ago
urlcrazy preview

urlcrazy

GitHuburbanadventurer/urlcrazy

Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.

dns-analysisinformation-gatheringosint+2
6971 year ago
phishery preview

phishery

GitHubryhanson/phishery

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

phishingphishing-toolssocial-engineering+1
1.0k9 years ago
CVE-2022-25257 preview

CVE-2022-25257

GitHubpolling-repo-continua/cve-2022-25257

Proof-of-concept exploit for CVE-2022-25257: CSRF parameter injection in SAS Logon 9.4 enabling warning-message spoofing for phishing attacks.

exploitationphishingsocial-engineering+2
4 years ago
CVE-2025-33053-Proof-Of-Concept preview

CVE-2025-33053-Proof-Of-Concept

GitHubdevbuihieu/cve-2025-33053-proof-of-concept

CVE-2025-33053 Proof Of Concept (PoC)

command-and-controlexploitationlateral-movement+6
621 year ago
ip-obfuscation preview

ip-obfuscation

GitHubhackinglz/ip-obfuscation

Generates obfuscated IP addresses and URLs using DWORD, octal, hex, IPv6-mapped, and fake-domain @ tricks for penetration testing, phishing…

educationimpersonation-toolspenetration-testing+6
4710 months ago
CVE-2025-59382-QNAP-Password-Reset-Account-Takeover preview

CVE-2025-59382-QNAP-Password-Reset-Account-Takeover

GitHubrat5ak/cve-2025-59382-qnap-password-reset-account-takeover

Proof-of-concept and technical writeup for CVE-2025-59382, an unauthenticated password reset URL injection in QNAP NAS that enables a…

educationexploitationpenetration-testing+3
23 months ago
phishcollector preview

phishcollector

GitHubolizimmermann/phishcollector

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

crawlereducationinformation-gathering+8
237 months ago
CVE-2025-33053_PoC preview

CVE-2025-33053_PoC

GitHub4n4s4zi/cve-2025-33053_poc

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

command-and-controlexploitationlateral-movement+3
11 year ago
mip22 preview

mip22

GitHubmakdosx/mip22

Advanced phishing framework with 83 pre-built cloned websites, manual site cloning, URL masking, and real-time credential capture with audio…

educationphishingphishing-tools+1
6934 years ago
BlueBox preview

BlueBox

GitHubsvdwi/bluebox

Open-source threat intelligence platform for malware and observable analysis. Enriches IPs, domains, URLs, and hashes with external sources, performs…

ioc-managementmachine-learningmalware-analysis+4
504 years ago
CVE-2025-50363_BXSS_CVE preview

CVE-2025-50363_BXSS_CVE

GitHub1h3ll/cve-2025-50363_bxss_cve

Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

exploitationpenetration-testingphishing+3
1 year ago
DATA preview

DATA

GitHubhadojae/data

Credential Phish Analysis and Automation

information-gatheringosintphishing+2
998 years ago
TeamsNTLMLeak preview

TeamsNTLMLeak

GitHubsoufianetahiri/teamsntlmleak

Leak NTLM via Website tab in teams via MS Office

adversarial-attackexploitationinformation-gathering+4
792 years ago
CVE-2017-5415 preview

CVE-2017-5415

GitHub649/cve-2017-5415

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…

phishingsocial-engineeringweb-application-exploitation+1
79 years ago
Previous12Next