Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
CVE-2022-30190-follina-Office-MSDT-Fixed preview

CVE-2022-30190-follina-Office-MSDT-Fixed

GitHubkomomon/cve-2022-30190-follina-office-msdt-fixed

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

command-and-controlexploitationpayload-generation+3
390
3 years ago
Mystikal preview

Mystikal

GitHubd00mfist/mystikal

macOS Initial Access Payload Generator

adversarial-attackcommand-and-controlpayload-development+4
3262 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtrackflaw/cve-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

email-securityexploitationpassword-attacks+3
1323 years ago
ExifSmugglingPoC preview

ExifSmugglingPoC

GitHubmalwaretech/exifsmugglingpoc

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

data-exfiltrationexploitationpayload-generation+3
6610 months ago
cve-2023-23397 preview

cve-2023-23397

GitHubbronzebee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

email-securityexploitationpassword-attacks+3
143 years ago
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
31 year ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4404 years ago
backdoorppt preview

backdoorppt

GitHubr00t-3xp10it/backdoorppt

transform your payload.exe into one fake word doc (.ppt)

impersonation-toolspayload-generationphishing-tools+2
4696 years ago
FakeImageExploiter preview

FakeImageExploiter

GitHubr00t-3xp10it/fakeimageexploiter

Use a Fake image.jpg to exploit targets (hide known file extensions)

command-and-controlexploitationpayload-development+5
9461 year ago
MaliciousMacroGenerator preview

MaliciousMacroGenerator

GitHubmr-un1k0d3r/maliciousmacrogenerator

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

malware-analysispayload-generationphishing-tools
8317 years ago
JShell preview

JShell

GitHubs0md3v/jshell

JShell - Get a JavaScript shell with XSS.

exploitationpayload-generationphishing-tools+1
5307 years ago
EmbedInHTML preview

EmbedInHTML

GitHubarno0x/embedinhtml

Embed and hide any file in an HTML file

payload-generationphishing-toolssocial-engineering+1
4908 years ago
EXCELntDonut preview

EXCELntDonut

GitHubredsiege/excelntdonut

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

exploitationpayload-generationphishing+4
5185 years ago
MacroShop preview

MacroShop

GitHubkhr0x40sh/macroshop

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

payload-developmentpayload-generationpenetration-testing+2
40810 years ago
boobsnail preview

boobsnail

GitHubstmcyber/boobsnail

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

payload-generationpenetration-testingphishing-tools+2
2561 year ago
SteaLinG preview

SteaLinG

GitHubde3vil/stealing

The SteaLinG is an open-source penetration testing framework designed for social engineering

data-exfiltrationpayload-generationpenetration-testing-frameworks+4
2472 years ago
HtmlSmuggling preview

HtmlSmuggling

GitHubde3vil/htmlsmuggling

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

malware-analysispayload-generationphishing-tools+1
1203 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubthemehackers/cve-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

email-securityexploitationpayload-generation+3
251 year ago
Previous123Next