Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
paperweight preview

paperweight

GitHubwslyvh/paperweight

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

data-exfiltrationemail-securityincident-response+5
435
1 day ago
osquery preview

osquery

GitHubosquery/osquery

SQL powered operating system instrumentation, monitoring, and analytics.

anomaly-detectiondefensive-toolsemail-security+8
23.6k2 days ago
web-check preview

web-check

GitHublissy93/web-check

🕵️‍♂️ All-in-one OSINT tool for analysing any website

dns-analysisemail-harvestinginformation-gathering+10
34.9k5 days ago
MailAccess preview

MailAccess

GitHubkatrielmoses/mailaccess

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

data-exfiltrationemail-harvestingforensics+8
1.4k8 days ago
Hundred OSINT preview

Hundred OSINT

GitLabt-beckett/h-osint

Local-first, keyboard-driven OSINT workbench for the terminal with 28 modules covering username, domain, IP, email, breach, and geolocation lookups…

dns-analysiseducationemail-harvesting+7
9 days ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

exploitationphishingreconnaissance+2
12 days ago
POC-CVE-2026-54121-Certighost preview

POC-CVE-2026-54121-Certighost

GitHubsam00/poc-cve-2026-54121-certighost

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

exploitationimpersonation-toolspenetration-testing+5
1 month ago
CVE-2016-10033 preview

CVE-2016-10033

GitHubblue-chocolates/cve-2016-10033

Exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer, enabling unauthenticated attackers to execute arbitrary code via…

exploitationinformation-gatheringpenetration-testing+2
1 month ago
CVE-2026-54390 preview

CVE-2026-54390

GitHubshinthink/cve-2026-54390

CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1

exploitationpenetration-testingreconnaissance+2
2 months ago
CVE-2026-12400-Exploit preview

CVE-2026-12400-Exploit

GitHub0x00phantom-hat/cve-2026-12400-exploit

Authenticated WordPress IDOR exploit for CVE-2026-12400; enumerates FlowForms REST form IDs and modifies form content or hijacks email notifications.

api-security-testingeducationexploitation+3
12 months ago
CVE-2026-XXXX-atlassian-email-enumeration preview

CVE-2026-XXXX-atlassian-email-enumeration

GitHubwh4l3x/cve-2026-xxxx-atlassian-email-enumeration

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

email-harvestinginformation-gatheringosint+5
12 months ago
quien preview

quien

GitHubretlehs/quien

A better whois and domain intelligence toolkit

dns-analysisemail-securityinformation-gathering+6
1.3k2 months ago
exchange-scanner preview

exchange-scanner

GitHubbishopfox/exchange-scanner

Identify public-facing Microsoft Exchange servers and determine their software versions

email-securityinformation-gatheringreconnaissance+3
23 months ago
CVE-2019-9053-exploit preview

CVE-2019-9053-exploit

GitHubjeanback1/cve-2019-9053-exploit

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

exploitationinformation-gatheringpassword-cracking+3
3 months ago
harpoon preview

harpoon

GitHubte-k/harpoon

CLI tool for open source and threat intelligence

dns-analysisemail-harvestinginformation-gathering+5
1.3k4 months ago
PoC_CVEs preview
Archived

PoC_CVEs

GitHubtg12/poc_cves

PoC_CVEs

curated-resourceseducationexploit-frameworks+5
1714 months ago
BlackWidow preview

BlackWidow

GitHub1n3/blackwidow

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

fuzzinginformation-gatheringosint+3
1.8k5 months ago
pwnedOrNot preview

pwnedOrNot

GitHubthewhiteh4t/pwnedornot

OSINT Tool for Finding Passwords of Compromised Email Addresses

information-gatheringosintpassword-cracking+1
2.6k5 months ago
Previous1234Next