Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
234 results
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
3
1 year ago
CVE-2021-46067 preview

CVE-2021-46067

GitHubsanupl/cve-2021-46067

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

authenticationexploitationimpersonation-tools+3
13 months ago
CVE-2021-24884 preview

CVE-2021-24884

GitHubs1lkys/cve-2021-24884

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

exploitationpayload-developmentphishing-tools+3
14 years ago
CVE-2025-3568 preview

CVE-2025-3568

GitHubshellkraft/cve-2025-3568

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

exploitationphishingprivilege-escalation+3
1 year ago
CVE-2022-46087 preview

CVE-2022-46087

GitHubg37sys73m/cve-2022-46087

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

phishingsocial-engineeringvulnerability-analysis+2
3 years ago
CVE-2024-30956 preview

CVE-2024-30956

GitHubleocottret/cve-2024-30956

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

exploitationphishing-toolssocial-engineering+2
2 years ago
SimpleEmailSpoofer preview
Archived

SimpleEmailSpoofer

GitHublunarca/simpleemailspoofer

A simple Python CLI to spoof emails.

email-securityosint-social-engineeringpenetration-testing+3
5624 years ago
Firework preview
Archived

Firework

GitHubspiderlabs/firework

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

authenticationcommand-and-controlosint-social-engineering+5
436 years ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

malware-analysisphishingred-teaming+4
14.8k3 months ago
Osintgram preview

Osintgram

GitHubdatalux/osintgram

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

educationinformation-gatheringosint+2
14.1k0 years ago
blackbird preview

blackbird

GitHubp1ngul1n0/blackbird

An OSINT tool to search for accounts by username and email in social networks.

email-harvestinginformation-gatheringosint+2
7.8k1 year ago
toutatis preview

toutatis

GitHubmegadose/toutatis

Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails, phone numbers and more

email-harvestinginformation-gatheringosint+1
4.2k1 year ago
Ultimate-Social-Scrapers preview

Ultimate-Social-Scrapers

GitHubharismuneer/ultimate-social-scrapers

🤖 Top-rated tools to scrape all major public sections from Facebook, Instagram, and Twitter (X) including posts (likes/comments), photos/videos,…

crawlerinformation-gatheringosint+2
3.2k1 year ago
Keylogger preview

Keylogger

GitHubaydinnyunus/keylogger

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

data-exfiltrationinformation-gatheringmalware-analysis+5
2.8k2 years ago
fluxion preview

fluxion

GitHubfluxionnetwork/fluxion

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

penetration-testingphishingred-teaming+2
5.9k1 month ago
ALHacking preview

ALHacking

GitHub4lbh4cker/alhacking

Albanian Hacking Tool!! Tools to help you with ethical hacking, Social media hack, phone info, Gmail attack, phone number attack, user discovery,…

information-gatheringosintpassword-attacks+2
1.6k1 year ago
OSIF preview

OSIF

GitHub0xlousie/osif

Facebook account information gathering tool that extracts sensitive personal data (residence, DOB, phone, email) even when target privacy is set to…

information-gatheringosintreconnaissance+1
1.2k7 years ago
tweets_analyzer preview

tweets_analyzer

GitHubx0rz/tweets_analyzer

OSINT tool that scrapes Twitter profile metadata to analyze activity patterns, timezone, language, geolocation, hashtags, and social connections for…

information-gatheringosintreconnaissance+1
3.0k6 years ago
Previous123…13Next