Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
304
8 years ago
Moniker-Link--CVE-2024-21413- preview

Moniker-Link--CVE-2024-21413-

GitHubbhatbhupendra/moniker-link--cve-2024-21413-

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

educationemail-securityexploitation+7
5 months ago
ditto preview

ditto

GitHubevilsocket/ditto

A tool for IDN homograph attacks and detection.

dns-subdomain-enumerationinformation-gatheringosint+2
7395 years ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.8k12h 14m ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
3.9k2 days ago
Awesome-BEC preview

Awesome-BEC

GitHubrandomaccess3/awesome-bec

Repository of attack and defensive information for Business Email Compromise investigations

cloud-securitycurated-resourcesdigital-forensics+7
2813 months ago
ThePhish preview

ThePhish

GitHubemalderson/thephish

ThePhish: an automated phishing email analysis tool

digital-forensicsemail-securityincident-response+5
1.4k2 years ago
NtlmRelayToEWS preview

NtlmRelayToEWS

GitHubarno0x/ntlmrelaytoews

ntlm relay attack to Exchange Web Services

email-securityexploitationinformation-gathering+4
3328 years ago
PRISM-AP preview

PRISM-AP

GitHub1n3/prism-ap

An automated Wireless RogueAP MITM attack framework.

dns-analysisinformation-gatheringpacket-sniffing-analysis+6
1917 years ago
Microsoft365_devicePhish preview

Microsoft365_devicePhish

GitHuboptiv/microsoft365_devicephish

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

authenticationemail-securitypenetration-testing+4
1075 years ago
https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubfathanahhidayati/https-github.com-xaitax-cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

email-securityexploitationpassword-cracking+4
2 years ago
fracture preview

fracture

GitHubelvira-alec/fracture

FragAttacks WiFi penetration framework — CVE-2020-24586/87/88

dns-analysisexploitationinformation-gathering+7
322h 32m ago
RTI-Toolkit preview

RTI-Toolkit

GitHubnickvourd/rti-toolkit

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

penetration-testingphishingphishing-tools+1
553 months ago
evilginx preview

evilginx

GitHubkgretzky/evilginx

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

authenticationpenetration-testingphishing+4
1.2k8 years ago
evilqr preview

evilqr

GitHubkgretzky/evilqr

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

authenticationpenetration-testingphishing+4
4343 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
tirith preview

tirith

GitHubsheeki03/tirith

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

curated-resourcesdata-exfiltrationdevsecops+8
2.7k18h 8m ago
hideNsneak preview

hideNsneak

GitHubrmikehodges/hidensneak

a CLI for ephemeral penetration testing

cloud-securitycommand-and-controlpayload-generation+5
186 years ago
Previous12Next