Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
wifi-agent preview

wifi-agent

GitHubmakdosx/wifi-agent

Rogue access point tool for creating captive portals, phishing credentials via cloned login pages, and injecting malware downloads for educational…

educationphishingphishing-tools+3
56
4 years ago
Embedded-PDF preview

Embedded-PDF

GitHubjasmoon99/embedded-pdf

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

command-and-controleducationexploitation+6
715 years ago
AllPhish preview

AllPhish

GitHubitsmehacker/allphish

A Complete Phishing Tool

educationphishingphishing-tools+1
406 years ago
WhatsPayloadRCE preview

WhatsPayloadRCE

GitHuberr0r-ica/whatspayloadrce

Whatsapp Automatic Payload Generator [CVE-2019-11932]

educationexploitationpayload-generation+3
354 years ago
pmotadeee preview

pmotadeee

GitHubpmotadeee/pmotadeee

Bora Jogar?

ctfeducationlabs-practice+3
152 days ago
CVE-2019-18426 preview

CVE-2019-18426

GitHubhumansecurity/cve-2019-18426

CVE-2019-18426 disclosure repository detailing Open Redirect, CSP Bypass, Persistent XSS, and FS read permissions in WhatsApp, with technical…

educationexploitationphishing+3
116 years ago
CVE-2024-21378 preview

CVE-2024-21378

GitHubd0rb/cve-2024-21378

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

educationemail-securityexploitation+4
92 years ago
osint-suspicious-recruitment-case preview

osint-suspicious-recruitment-case

GitHub0ggp4r1s/osint-suspicious-recruitment-case

OSINT investigation into a suspicious recruitment scheme involving miramedesdecasa

educationinformation-gatheringosint+3
75 months ago
ai-email-threat-research preview

ai-email-threat-research

GitHubscottalt/ai-email-threat-research

A cybersecurity research game measuring how humans detect AI-generated phishing emails. Built as a retro terminal experience.

ai-securityctfeducation+4
83 months ago
telegram-phish-simulator preview

telegram-phish-simulator

GitHubmaty156/telegram-phish-simulator

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

educationinformation-gatheringlabs-practice+6
25 days ago
NetCrackPi preview

NetCrackPi

GitHubcisc0-gif/netcrackpi

RPi3+ Network Cracker Setup Tool

educationintrusion-detectionnetwork-security+5
45 years ago
interrogation-game preview

interrogation-game

GitHubjpoindexter/interrogation-game

Voice-based detective interrogation game. Mistral Large 3 + Voxtral STT + ElevenLabs TTS. Built for the Mistral Worldwide Hackathon 2026.

adversarial-attackai-securityctf+6
53 months ago
SPY-MASKER preview

SPY-MASKER

GitHubanupam2808/spy-masker

It is a simple Python Script to hide phishing URL under a normal looking URL (google.com or facebook.com). It can be integrated into Phishing tools…

educationphishingphishing-tools+1
42 years ago
web-mitm-lab preview

web-mitm-lab

GitHubdereeqw/web-mitm-lab

Web traffic interception simulation tool for cybersecurity research and defensive learning in isolated lab environments.

educationinformation-gatheringnetwork-security+5
35 months ago
xz-backdoor-research preview

xz-backdoor-research

GitHubnnatsopoulos/xz-backdoor-research

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

educationforensicsincident-response+5
12 months ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
CVE-2025-69606-GSVoIP-XSS preview

CVE-2025-69606-GSVoIP-XSS

GitHubrazielx64/cve-2025-69606-gsvoip-xss

Proof-of-concept for a reflected XSS vulnerability (CVE-2025-69606) in GSVoIP Web Panel v2.0.90, demonstrating unauthenticated arbitrary JavaScript…

educationphishingsocial-engineering+3
4 months ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubshndnth/cve-2022-30190

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

command-and-controleducationexploitation+8
4 months ago
Previous123456Next