Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
178 results
ogi preview

ogi

GitHubkhashashin/ogi

Open Source Link Analysis & OSINT Framework

crawlerdns-analysiseducation+7
2891 month ago
InfoHound preview

InfoHound

GitHubfundacio-i2cat/infohound

InfoHound is an OSINT to extract a large amount of data given a web domain name.

dns-analysiseducationemail-harvesting+8
1632 years ago
MITMer preview

MITMer

GitHubhusam212/mitmer

Automated man-in-the-middle attack tool.

dns-analysisnetwork-securitypacket-sniffing-analysis+5
5312 years ago
dmi-tcat preview
Archived

dmi-tcat

GitHubdigitalmethodsinitiative/dmi-tcat

Digital Methods Initiative - Twitter Capture and Analysis Toolset

crawlereducationinformation-gathering+3
3711 year ago
All-CEHv13-Module-wise-PDF-Reports preview

All-CEHv13-Module-wise-PDF-Reports

GitHubaniket2912/all-cehv13-module-wise-pdf-reports

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

cloud-securitycryptographyeducation+9
1387 months ago
WiFi-Pineapple-MK7_Evil-Portal preview

WiFi-Pineapple-MK7_Evil-Portal

GitHubtw-d/wifi-pineapple-mk7_evil-portal

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

penetration-testingphishingred-teaming+3
112 years ago
fluxion preview

fluxion

GitHubfluxionnetwork/fluxion

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

penetration-testingphishingred-teaming+3
5.9k1 month ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

cloud-securityctfcurated-resources+10
27.1k1 month ago
RedRoot preview

RedRoot

GitHubagampreet-singh/redroot

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

ctfexploit-frameworksfuzzing+9
174 months ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

educationexploitationlabs-practice+5
1 year ago
CVE-2019-13496 preview

CVE-2019-13496

GitHubfurqankhan1/cve-2019-13496

Proof-of-concept exploit demonstrating OTP bypass in One Identity Cloud Access Manager 8.1.3 via MITM/SSL-strip, SAML response replay, and injected…

authenticationids-ips-evasionpenetration-testing+3
26 years ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.8k3 months ago
SMSOTPBOT preview

SMSOTPBOT

GitHubghost-otpbot/smsotpbot

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

impersonation-toolsinformation-gatheringpenetration-testing+3
2153 years ago
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k3 months ago
Moniker-Link-Lab-Setup preview

Moniker-Link-Lab-Setup

GitHube-m-e-k-a/moniker-link-lab-setup

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

authenticationeducationexploitation+6
5 months ago
CVE-2021-3456 preview

CVE-2021-3456

GitHubmrk336/cve-2021-3456

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

command-and-controleducationexploitation+8
1 year ago
chatter preview
Archived

chatter

GitHubvisualbasic6/chatter

internet monitoring osint telegram bot for windows

crawlereducationinformation-gathering+4
1503 years ago
spiderfoot preview

spiderfoot

GitHubsmicallef/spiderfoot

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

dns-analysisemail-harvestinginformation-gathering+9
21.7k2 years ago
Previous12…10Next