Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
O365-Doppelganger preview

O365-Doppelganger

GitHubparanoidninja/o365-doppelganger

A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

phishingred-teamingsocial-engineering
254
4 years ago
wifipumpkin3 preview

wifipumpkin3

GitHubp0cl4bs/wifipumpkin3

Powerful framework for rogue access point attack.

captcha-bypassdns-analysisphishing+5
2.5k2 years ago
fluxion preview

fluxion

GitHubfluxionnetwork/fluxion

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

penetration-testingphishingred-teaming+3
5.9k21h 33m ago
phishing-frenzy preview

phishing-frenzy

GitHubpentestgeek/phishing-frenzy

Ruby on Rails Phishing Framework

penetration-testingphishingred-teaming+2
8932 years ago
ClickOnceBlobber preview

ClickOnceBlobber

GitHubdazzyddos/clickonceblobber

Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

command-and-controlpayload-developmentred-teaming+1
1696 months ago
GitBackdorizer preview

GitBackdorizer

GitHubunkl4b/gitbackdorizer

GitBackdorizer (bad name, I know!) Is a proof of concept from Ulisses Castro's talk - 50 ton of backdoors…

payload-developmentpenetration-testingred-teaming+1
518 years ago
WiFi-Pineapple-MK7_Evil-Portal preview

WiFi-Pineapple-MK7_Evil-Portal

GitHubtw-d/wifi-pineapple-mk7_evil-portal

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

penetration-testingphishingred-teaming+3
112 years ago
DiscoRape preview

DiscoRape

GitHubdaddy-bit/discorape

A selfbot for discord made using Discord.py. It comes with 70+ commands and server nuking features

command-and-controlexploitationpenetration-testing+2
16 years ago
FakeAuth preview

FakeAuth

GitHubatn1ght/fakeauth

Creates Fake Auth prompt to capture users plaintext passwords

password-attacksphishingred-teaming+1
35 years ago
CVE-2018-13257 preview

CVE-2018-13257

GitHubgluxon/cve-2018-13257

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

authenticationpenetration-testingphishing+3
17 years ago
sleepall preview

sleepall

GitHuboditynet/sleepall

trojan CVE-2024-28085 CVE 28085

command-and-controlexploitationpassword-attacks+2
21 year ago
Invoke-LinkSpray preview

Invoke-LinkSpray

GitLabkevinjclark/invoke-linkspray

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

authenticationpenetration-testingphishing+2
6 years ago
fluxion preview

fluxion

GitHubjas502n/fluxion

fluxion

password-attackspenetration-testingphishing+4
8 years ago
MAL-008 preview

MAL-008

GitHubmbadanoiu/mal-008

Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN

exploitationpenetration-testingred-teaming+3
2 years ago
dot preview

dot

GitHubsensity-ai/dot

Real-time deepfake toolkit for penetration testing of identity verification and video conferencing systems. Supports face swap, image animation, and…

adversarial-attackai-securityimpersonation-tools+3
4.6k2 years ago
wifiphisher preview

wifiphisher

GitHubwifiphisher/wifiphisher

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

impersonation-toolsmalware-analysisphishing+6
14.8k3 months ago
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k3 months ago
OSINT-Cheat-sheet preview

OSINT-Cheat-sheet

GitHubjieyab89/osint-cheat-sheet

Curated OSINT cheat sheet with tools, datasets, wiki, and tips for reconnaissance, social media intelligence, and red team operations. Includes…

curated-resourceseducationinformation-gathering+3
2.2k7 days ago
Previous123Next