Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Malware Analysis

Tools for dissecting, understanding, and reverse engineering malicious software behavior.

Kitploit recommended

Top tools

10 selected
yara-x preview#1

yara-x

GitHubvirustotal/yara-x
1.2k23 days ago
capa preview#3

capa

GitHubmandiant/capa
6.1k12 days ago
flare-floss preview#4

flare-floss

GitHubmandiant/flare-floss
4.1k12 days ago
x64dbg preview#5

x64dbg

GitHubx64dbg/x64dbg
49.1k1 day ago
radare2 preview#6

radare2

GitHubradareorg/radare2
24.5k1 day ago
ghidra preview#7

ghidra

GitHubnationalsecurityagency/ghidra
71.1k2 days ago
Detect-It-Easy preview#8

Detect-It-Easy

GitHubhorsicq/detect-it-easy
11.3k4h 34m ago
theZoo preview#9

theZoo

GitHubytisf/thezoo
13.3k7 days ago
flare-vm preview#10

flare-vm

GitHubmandiant/flare-vm
8.9k3 months ago
IntelOwl preview#11

IntelOwl

GitHubintelowlproject/intelowl
4.7k19 days ago
NewestRelevanceMost popularRecently updated
3548 results
ecapture preview

ecapture

GitHubgojue/ecapture

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

android-securitypacket-sniffing-analysisdynamic-analysis-sandboxing+3
15.4k3 days ago
Sighthound preview

Sighthound

GitHubcorgea/sighthound

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

static-analysisvulnerability-scannersstatic-code-analysis+4
2753 days ago
threat-research preview

threat-research

GitHubthreatray/threat-research

IoCs and YARA rules from Threatray's Threat Research

ioc-managementforensicsmalware-analysis+2
203 days ago
ll-34 preview

ll-34

GitHubdbrll/ll-34

Circuit-level PDP-11/34 emulator

embedded-systems-securityreverse-engineeringdebuggers+4
693 days ago
Project-Onyx preview

Project-Onyx

GitHubx-3306/project-onyx

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

reverse-engineeringshellcodesteganography+6
1153 days ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityphishing-toolsvulnerability-scanners+15
15.6k3 days ago
MISP preview

MISP

GitHubmisp/misp

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

defensive-toolsioc-managementthreat-feeds-aggregators+10
6.5k3 days ago
upx preview

upx

GitHubupx/upx

UPX - the Ultimate Packer for eXecutables

general-purpose-utilitiesreverse-engineeringbinary-analysis
17.8k3 days ago
mwemu preview

mwemu

GitHubmwemuorg/mwemu

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

exploit-frameworksreverse-engineeringshellcode+2
3133 days ago
Veridiff preview

Veridiff

GitHubveridiff/veridiff

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

dynamic-analysis-sandboxingcode-analysisdynamic-code-analysis+7
13 days ago
protections-artifacts preview

protections-artifacts

GitHubelastic/protections-artifacts

Elastic Security detection content for Endpoint

vulnerability-analysismalware-analysisthreat-intelligence+1
1.5k3 days ago
safe-chain preview

safe-chain

GitHubaikidosec/safe-chain

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

defensive-toolsvulnerability-scannersmalware-analysis+3
1.7k3 days ago
objection preview

objection

GitHubsensepost/objection

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

android-securitypenetration-testing-frameworksdynamic-analysis-sandboxing+9
9.3k4 days ago
packj preview

packj

GitHubossillate-inc/packj

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+3
6914 days ago
cve-2026-59827-metabase-cyber-range preview

cve-2026-59827-metabase-cyber-range

GitHubshivammittal2403/cve-2026-59827-metabase-cyber-range

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking…

dynamic-analysis-sandboxingvulnerability-analysisexploitation+6
4 days ago
CVE-2025-55182-scanner preview

CVE-2025-55182-scanner

GitHubmayank729/cve-2025-55182-scanner

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

static-analysisvulnerability-scannersvulnerability-analysis+3
4 days ago
ghostlock-app preview

ghostlock-app

GitHubyukonga/ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

android-securityprivilege-escalationexploit-frameworks+4
9234 days ago
frida-ssl-bypass preview

frida-ssl-bypass

GitHubdanieldev23/frida-ssl-bypass

Frida toolkit that bypasses SSL/TLS certificate pinning on Android apps, hooking Java TrustManager, OkHttp, Conscrypt, and native OpenSSL/BoringSSL…

android-securitydynamic-analysis-sandboxingweb-proxies-interception+6
154 days ago
Previous1…91011…100Next