Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
114 results
otp-bot preview

otp-bot

GitHuboriyomi12/otp-bot

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

authenticationimpersonation-toolspenetration-testing+3
378
2 years ago
SpamChannel preview

SpamChannel

GitHubbyt3bl33d3r/spamchannel

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

email-securityimpersonation-toolsphishing-tools+1
3482 years ago
xepor preview

xepor

GitHubxepor/xepor

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

penetration-testingphishing-toolsred-teaming+3
2151 year ago
PasteZort preview

PasteZort

GitHubzettahack/pastezort

Pastejacking - PasteZort

impersonation-toolsphishing-toolssocial-engineering+1
8410 years ago
Phisher-man preview

Phisher-man

GitHubfdx100/phisher-man

Samples Phishing tools made for Linux it contains 30 different type of Phishing Pages made with flask

phishing-toolssocial-engineeringweb-security
1084 years ago
DroppedConnection preview

DroppedConnection

GitHubnccgroup/droppedconnection

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

impersonation-toolspenetration-testingphishing-tools+2
1293 years ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
376 years ago
yappy preview

yappy

GitHubjienweng/yappy

AI-powered LinkedIn engagement assistant

impersonation-toolsinformation-gatheringosint+2
105 months ago
CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval- preview

CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval-

GitHubgeorge0papasotiriou/cve-2026-22005-oauth-2.0-device-code-phishing-short-interval-

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

authentication-authorizationeducationexploitation+4
24 days ago
CVE-2021-46067 preview

CVE-2021-46067

GitHubsanupl/cve-2021-46067

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

authenticationexploitationimpersonation-tools+3
13 months ago
SocialEngineering preview

SocialEngineering

GitHubcappricio-securities/socialengineering

SEt framework

impersonation-toolspassword-attacksphishing-tools+2
15 months ago
CVE-2025-51863 preview

CVE-2025-51863

GitHubsecsys-fdu/cve-2025-51863

Proof-of-concept for a Self-XSS vulnerability in ChatGPTUtil, demonstrating cookie theft and account hijacking via crafted SVG payloads pasted into…

exploitationphishing-toolsvulnerability-analysis+2
1 year ago
LetterPress-1.2.1-Open-Redirection-Via-Html-Injection-Vulnerability preview

LetterPress-1.2.1-Open-Redirection-Via-Html-Injection-Vulnerability

GitHubsanupl/letterpress-1.2.1-open-redirection-via-html-injection-vulnerability

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

penetration-testingphishing-toolsweb-application-exploitation
3 months ago
POC-CVE-2018-25031 preview

POC-CVE-2018-25031

GitHubgeozin/poc-cve-2018-25031

Proof-of-concept exploit for CVE-2018-25031 (Swagger UI XSS) that exfiltrates authorization codes via crafted configUrl/url parameters.

exploitationphishing-toolssocial-engineering+2
2 years ago
CVE-2020-13965 preview

CVE-2020-13965

GitHubmbadanoiu/cve-2020-13965

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2023-33977 preview

CVE-2023-33977

GitHubmnqazi/cve-2023-33977

Read more at Medium

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager preview

CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager

GitHubsromanhu/cve-2023-43872-cmsmadesimple-arbitrary-file-upload--xss---file-manager

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2024-30956 preview

CVE-2024-30956

GitHubleocottret/cve-2024-30956

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

exploitationphishing-toolssocial-engineering+2
2 years ago
Previous1234567Next