Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
69 results
wifi-agent preview

wifi-agent

GitHubmakdosx/wifi-agent

Rogue access point tool for creating captive portals, phishing credentials via cloned login pages, and injecting malware downloads for educational…

educationphishingphishing-tools+3
56
4 years ago
CiclopeClic preview

CiclopeClic

GitHubpericena/ciclopeclic

Security awareness training tool for authorized phishing simulations and internal IT audits

ai-securityeducationpenetration-testing+4
153 months ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.8k3 months ago
fakelogonscreen preview

fakelogonscreen

GitHubbitsadmin/fakelogonscreen

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

password-attacksphishing-toolspost-exploitation+2
1.4k6 years ago
morpheus preview

morpheus

GitHubr00t-3xp10it/morpheus

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

exploitationids-ips-evasioninformation-gathering+7
8827 years ago
CredsLeaker preview

CredsLeaker

GitHubdviros/credsleaker

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

penetration-testingphishing-toolsred-teaming+1
3175 years ago
otp-bot preview

otp-bot

GitHuboriyomi12/otp-bot

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

authenticationimpersonation-toolspenetration-testing+3
3782 years ago
CVE-2022-30190-follina-Office-MSDT-Fixed preview

CVE-2022-30190-follina-Office-MSDT-Fixed

GitHubkomomon/cve-2022-30190-follina-office-msdt-fixed

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

command-and-controlexploitationpayload-generation+3
3913 years ago
URLCADIZ preview

URLCADIZ

GitHubperezmascato/urlcadiz

A simple script to generate a hidden url for social engineering.

osint-social-engineeringphishing-toolssocial-engineering
1236 years ago
xepor preview

xepor

GitHubxepor/xepor

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

penetration-testingphishing-toolsred-teaming+3
2151 year ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
366 years ago
SMBRat preview

SMBRat

GitHuboperatorequals/smbrat

A Windows Remote Administration Tool in Visual Basic with UNC paths

command-and-controlexploitationlateral-movement+8
227 years ago
CVE-2021-46067 preview

CVE-2021-46067

GitHubsanupl/cve-2021-46067

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

authenticationexploitationimpersonation-tools+3
13 months ago
LetterPress-1.2.1-Open-Redirection-Via-Html-Injection-Vulnerability preview

LetterPress-1.2.1-Open-Redirection-Via-Html-Injection-Vulnerability

GitHubsanupl/letterpress-1.2.1-open-redirection-via-html-injection-vulnerability

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

penetration-testingphishing-toolsweb-application-exploitation
3 months ago
CVE-2024-30956 preview

CVE-2024-30956

GitHubleocottret/cve-2024-30956

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

exploitationphishing-toolssocial-engineering+2
2 years ago
CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager preview

CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager

GitHubsromanhu/cve-2023-43872-cmsmadesimple-arbitrary-file-upload--xss---file-manager

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2023-43871-WBCE-Arbitrary-File-Upload--XSS---Media preview

CVE-2023-43871-WBCE-Arbitrary-File-Upload--XSS---Media

GitHubsromanhu/cve-2023-43871-wbce-arbitrary-file-upload--xss---media

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
evilginx2 preview

evilginx2

GitHubkgretzky/evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

impersonation-toolspenetration-testingphishing+4
15.6k2 months ago
Previous1234Next