Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
75 results
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
4.0k
11 days ago
WiFi-Pineapple-MK7_Evil-Portal preview

WiFi-Pineapple-MK7_Evil-Portal

GitHubtw-d/wifi-pineapple-mk7_evil-portal

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

penetration-testingphishingred-teaming+3
112 years ago
AmzWord preview

AmzWord

GitHubjump-wang-111/amzword

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

command-and-controleducationemail-security+6
12 years ago
EmbedInHTML preview

EmbedInHTML

GitHubarno0x/embedinhtml

Embed and hide any file in an HTML file

payload-generationphishing-toolssocial-engineering+1
4899 years ago
poc-CVE-2026-64638- preview

poc-CVE-2026-64638-

GitHubmohwahyudi/poc-cve-2026-64638-

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

exploitationpayload-generationpenetration-testing+5
1 month ago
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
31 year ago
XLL_Phishing preview

XLL_Phishing

GitHuboctoberfest7/xll_phishing

XLL Phishing Tradecraft

defensive-toolsexploitationpayload-development+7
4384 years ago
Fudge preview

Fudge

GitHubdale-ruane/fudge

Hiding implants in HTML files

payload-generationphishingred-teaming+1
646 years ago
WEAPONIZING-CVE-2024-4367 preview

WEAPONIZING-CVE-2024-4367

GitHubexfil0/weaponizing-cve-2024-4367

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

educationexploitationpayload-generation+3
31 year ago
IconJector preview

IconJector

GitHubd419h/iconjector

Inject DLLs into the explorer process using icons

adversarial-attackexploitationpayload-development+3
4151 year ago
terra preview

terra

GitHubxadhrit/terra

OSINT Tool on Twitter and Instagram.

email-harvestinginformation-gatheringosint+2
46811 months ago
AtlasReaper preview

AtlasReaper

GitHubwerdhaihai/atlasreaper

A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.

information-gatheringpenetration-testingreconnaissance+2
2753 years ago
cua-kit preview

cua-kit

GitHubpreludeorg/cua-kit

Tools for attacking Computer Use Agents

ai-securitycommand-and-controlexploitation+7
338 months ago
infernal-twin preview

infernal-twin

GitHubentropy1337/infernal-twin

wireless hacking - This is automated wireless hacking tool

exploitationinformation-gatheringpenetration-testing+4
1.3k7 years ago
poastal preview

poastal

GitHubjakecreps/poastal

Email OSINT tool that resolves names, checks deliverability, detects disposable/spam addresses, and identifies registrations on 10+ social platforms…

email-harvestinginformation-gatheringosint+2
6023 years ago
instaloctrack preview
Archived

instaloctrack

GitHubbernsteining/instaloctrack

An Instagram OSINT tool to collect all the geotagged locations available on an Instagram profile in order to plot them on a map, and dump them in a…

crawlerinformation-gatheringosint+2
3236 years ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

educationexploitationlabs-practice+5
1 year ago
unve1ler preview

unve1ler

GitHubspyboy-productions/unve1ler

A social engineering tool designed to seamlessly locate profiles using usernames while offering convenient reverse image search functionality.

information-gatheringosintreconnaissance+1
1612 years ago
Previous12345Next