Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
CVE-2023-41425-WonderCMS-Authenticated-RCE preview

CVE-2023-41425-WonderCMS-Authenticated-RCE

GitHubdiegomjx/cve-2023-41425-wondercms-authenticated-rce

Xss injection, WonderCMS 3.2.0 -3.4.2

educationexploitationpayload-generation+4
1
1 year ago
CVE-2020-25498 preview

CVE-2020-25498

GitHubthe-girl-who-lived/cve-2020-25498

Stored XSS via CSRF in Beetel 777VR1 Router

exploitationpenetration-testingphishing-tools+2
35 years ago
CVE-2024-37383-exploit preview

CVE-2024-37383-exploit

GitHubamirzargham/cve-2024-37383-exploit

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

data-exfiltrationemail-securityexploitation+3
1 year ago
noapi-google-search-mcp preview

noapi-google-search-mcp

GitHubvincentkaufmann/noapi-google-search-mcp

MCP server for Google search and page fetching using headless Chromium

anti-botcaptcha-bypasscrawler+8
1224 days ago
Malicious-MCP preview

Malicious-MCP

GitHubquinnbast/malicious-mcp

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

ai-securitycommand-and-controldata-exfiltration+8
84 months ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
95716 days ago
phishery preview

phishery

GitHubryhanson/phishery

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

phishingphishing-toolssocial-engineering+1
1.0k9 years ago
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
3058 years ago
fb-phisher-python preview

fb-phisher-python

GitHubarjunindia/fb-phisher-python

A python server tool based on flask , this tool can phish some Facebook credentials!

phishingphishing-toolssocial-engineering+1
177 years ago
TurkoRat preview

TurkoRat

GitHubcryst4linqq/turkorat

Fully undetected grabber (grabs wallets, passwords, cookies, modifies discord client etc.)

anti-botdata-exfiltrationinformation-gathering+5
1763 years ago
SnitchDNS preview

SnitchDNS

GitHubctxis/snitchdns

Database Driven DNS Server with a Web UI

command-and-controldata-exfiltrationdns-analysis+7
2442 years ago
Responder preview
Archived

Responder

GitHubspiderlabs/responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

authenticationdns-analysisexploitation+8
4.9k6 years ago