Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
FullscreenBrowserPhishing preview

FullscreenBrowserPhishing

GitHubgmh5225/fullscreenbrowserphishing

PoC of the phishing through setting browser in the fullscreen mode

educationphishingphishing-tools+3
3 years ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubbardlaudian/cve-2025-24071

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

exploitationinformation-gatheringlateral-movement+5
6 days ago
JQueryingU preview

JQueryingU

GitHubsamsayen/jqueryingu

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

information-gatheringosint-social-engineeringphishing-tools+2
7 years ago
flyphish preview

flyphish

GitHubvirtualsamuraii/flyphish

Deploy a phishing infrastructure on the fly.

cloud-infrastructure-securityemail-securitypenetration-testing+3
791 year ago
CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration preview

CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration

GitHubmbanyamer/cve-2026-27579-collabplatform-appwrite-cors-misconfiguration

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

exploitationphishing-toolsred-teaming+3
7 months ago
WEAPONIZING-CVE-2024-4367 preview

WEAPONIZING-CVE-2024-4367

GitHubexfil0/weaponizing-cve-2024-4367

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

educationexploitationpayload-generation+3
31 year ago
CVE-2026-32201-exploit preview

CVE-2026-32201-exploit

GitHubb1tbit/cve-2026-32201-exploit

Python exploit for CVE-2026-32201, a reflected XSS in Microsoft SharePoint Server, enabling unauthenticated spoofing and data modification via…

exploitationpenetration-testingphishing-tools+3
15 months ago
tryhackme-moniker-link preview

tryhackme-moniker-link

GitHubyfelipecruvinel/tryhackme-moniker-link

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

educationemail-securityexploitation+3
1 month ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubdungsocool/cve-2026-64638

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

code-analysisexploitationpayload-development+4
1 month ago
decode-spam-headers preview

decode-spam-headers

GitHubmgeeky/decode-spam-headers

A script that helps you understand why your E-Mail ended up in Spam

email-securityinformation-gatheringlog-analysis+2
6987 months ago
SpamChannel preview

SpamChannel

GitHubbyt3bl33d3r/spamchannel

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

email-securityimpersonation-toolsphishing-tools+1
3493 years ago
recaptcha-phish preview

recaptcha-phish

GitHubjohnhammond/recaptcha-phish

Phishing with a fake reCAPTCHA

impersonation-toolspayload-generationphishing-tools+1
6582 years ago
DroppedConnection preview

DroppedConnection

GitHubnccgroup/droppedconnection

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

impersonation-toolspenetration-testingphishing-tools+2
1293 years ago
OutlookLeakTest preview

OutlookLeakTest

GitHubnccgroup/outlookleaktest

The Outlook HTML Leak Test Project

data-exfiltrationemail-securityinformation-gathering+5
1298 years ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
366 years ago
camjacking preview

camjacking

GitHubcappricio-securities/camjacking

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

educationimpersonation-toolsinformation-gathering+5
707 months ago
LetterPress-1.2.1-Open-Redirection-Via-Html-Injection-Vulnerability preview

LetterPress-1.2.1-Open-Redirection-Via-Html-Injection-Vulnerability

GitHubsanupl/letterpress-1.2.1-open-redirection-via-html-injection-vulnerability

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

penetration-testingphishing-toolsweb-application-exploitation
4 months ago
CVE-2026-13156 preview

CVE-2026-13156

GitHubminhhk68/cve-2026-13156

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

educationexploitationpapers-research+3
2 months ago
Previous1234567Next