Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
311 results
Awesome-BEC preview

Awesome-BEC

GitHubrandomaccess3/awesome-bec

Repository of attack and defensive information for Business Email Compromise investigations

cloud-securitycurated-resourcesdigital-forensics+7
279
2 months ago
Tangled preview

Tangled

GitHubineesdv/tangled

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

command-and-controlemail-securitylateral-movement+5
2758 months ago
crime-mapper preview

crime-mapper

GitHubmr-r3b00t/crime-mapper

A tool for mapping cyber crime

digital-forensicsemail-securityinformation-gathering+3
2417 months ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
Zphisher-GUI-Back_office preview

Zphisher-GUI-Back_office

GitHubmicro-joan/zphisher-gui-back_office

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

information-gatheringosintpassword-attacks+2
2353 years ago
EvilSelenium preview

EvilSelenium

GitHubmrd0x/evilselenium

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

data-exfiltrationinformation-gatheringphishing-tools+3
6084 years ago
M365Pwned preview

M365Pwned

GitHubotterhacker/m365pwned

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

data-exfiltrationexploitationimpersonation-tools+5
2266 months ago
sage preview

sage

GitHubgendigitalinc/sage

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

ai-securitycode-analysisdefensive-tools+6
27019 days ago
Bella preview

Bella

GitHub00xglitch/bella

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

command-and-controldata-exfiltrationids-ips-evasion+8
2053 years ago
CVE-2022-30190-follina-Office-MSDT-Fixed preview

CVE-2022-30190-follina-Office-MSDT-Fixed

GitHubkomomon/cve-2022-30190-follina-office-msdt-fixed

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

command-and-controlexploitationpayload-generation+3
3913 years ago
EmBomber preview

EmBomber

GitHubmazenelzanaty/embomber

Python Script for Email Bombing which supports Gmail, Yahoo, Hotmail/Outlook

email-harvestingpenetration-testingphishing-tools+1
1368 years ago
mail-security-tester preview

mail-security-tester

GitHubtkcert/mail-security-tester

A testing framework for mail security and filtering solutions.

email-securityids-ips-evasionpenetration-testing+2
2447 years ago
cromos preview

cromos

GitHubjimywork/cromos

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

command-and-controldata-exfiltrationlateral-movement+5
1248 years ago
CVE-2022-44666 preview

CVE-2022-44666

GitHubj00sean/cve-2022-44666

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

exploitationpayload-developmentphishing-tools+2
1543 years ago
AzureRedOps preview

AzureRedOps

GitHubmr-un1k0d3r/azureredops

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

authenticationcloud-securityexploitation+8
1801 month ago
URLCADIZ preview

URLCADIZ

GitHubperezmascato/urlcadiz

A simple script to generate a hidden url for social engineering.

osint-social-engineeringphishing-toolssocial-engineering
1236 years ago
noapi-google-search-mcp preview

noapi-google-search-mcp

GitHubvincentkaufmann/noapi-google-search-mcp

MCP server for Google search and page fetching using headless Chromium

anti-botcaptcha-bypasscrawler+8
12415 days ago
xepor preview

xepor

GitHubxepor/xepor

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

penetration-testingphishing-toolsred-teaming+3
2151 year ago
Previous1…456…18Next