Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
reFlutter preview

reFlutter

GitHubimpact-i/reflutter

Patches Flutter engine libraries to enable runtime reverse engineering, traffic interception, and SSL pinning bypass for Android and iOS apps without…

android-securitydynamic-analysis-sandboxingios-security+3
2.8k
7h 48m ago
Magisk preview

Magisk

GitHubtopjohnwu/magisk

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

android-securitymobile-securityprivilege-escalation
62.9k2 days ago
frida-interception-and-unpinning preview

frida-interception-and-unpinning

GitHubhttptoolkit/frida-interception-and-unpinning

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

android-securityios-securitymobile-app-pentesting+4
2.3k6 days ago
objection preview

objection

GitHubsensepost/objection

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

android-securitydynamic-analysis-sandboxingexploitation+9
9.4k7 days ago
meizu21-ghostlock-root preview

meizu21-ghostlock-root

GitHubymh001/meizu21-ghostlock-root

MEIZU 21 locked-bootloader runtime root via CVE-2026-43499 and KernelSU late-load

android-securityexploitationmobile-app-pentesting+4
19 days ago
blutter preview

blutter

GitHubworawit/blutter

Flutter Mobile Application Reverse Engineering Tool

android-securitybinary-analysismobile-security+1
2.7k1 month ago
grapefruit preview

grapefruit

GitHubchichou/grapefruit

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

android-securitybinary-analysisdynamic-code-analysis+5
1.4k1 month ago
phantom-frida preview

phantom-frida

GitHubtheqmaks/phantom-frida

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

android-securitybinary-analysisdynamic-analysis-sandboxing+7
3812 months ago
Arti Mobile - Tor in Rust for Android and iOS preview

Arti Mobile - Tor in Rust for Android and iOS

GitLabguardianproject/tormobile/arti-mobile

Rust-based Tor library for Android and iOS, providing a standard API to integrate the Arti Tor runtime into mobile apps for private,…

android-securityios-securitymobile-security+2
12 months ago
RMS-Runtime-Mobile-Security preview

RMS-Runtime-Mobile-Security

GitHubm0bilesecurity/rms-runtime-mobile-security

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

android-securitydebuggersdynamic-analysis-sandboxing+7
3.1k2 months ago
cve-2025-59489 preview

cve-2025-59489

GitHubtaptap/cve-2025-59489

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

android-securitydevsecopsmobile-security+2
1511 months ago
PAPIMonitor preview

PAPIMonitor

GitHub0xdad0/papimonitor

Frida-based runtime API monitor for Android apps that logs invoked APIs, parameters, return values, and call origins across predefined or custom…

android-securityapi-securitydynamic-analysis-sandboxing+1
882 years ago
ARTful preview

ARTful

GitHublauriewired/artful

The ARTful library for dynamically modifying the Android Runtime

android-securitydynamic-code-analysismobile-app-pentesting+2
3562 years ago
frameworks_native_AOSP-10_r33_CVE-2023-21094 preview

frameworks_native_AOSP-10_r33_CVE-2023-21094

GitHubtrinadh465/frameworks_native_aosp-10_r33_cve-2023-21094

Exploit or patch for CVE-2023-21094 in Android 10 frameworks/native, targeting a specific vulnerability in the Android runtime.

android-securitybinary-exploitationexploitation+2
2 years ago
platform_art_CVE-2021-0394 preview

platform_art_CVE-2021-0394

GitHubtrinadh465/platform_art_cve-2021-0394

Analyzes and demonstrates the Android Runtime vulnerability CVE-2021-0394, providing code-level insights for security researchers and developers.

android-securitybinary-exploitationcode-analysis+3
3 years ago
Frida-VMProtect-Bypass preview

Frida-VMProtect-Bypass

GitHubgmh5225/frida-vmprotect-bypass

Frida script that bypasses VMProtect runtime protections on mobile platforms, enabling dynamic instrumentation and analysis of protected binaries.

android-securitybinary-exploitationdynamic-analysis-sandboxing+3
23 years ago
frida-il2cpp-datacollector preview

frida-il2cpp-datacollector

GitHubgmh5225/frida-il2cpp-datacollector

Frida-based tool that ports Cheat Engine's MonoDataCollector to Android and iOS, enabling runtime Mono/IL2CPP data collection and memory inspection…

android-securitybinary-analysisdebuggers+5
133 years ago
ShaikUsaf-frameworks_base_AOSP10_r33_CVE-2022-20138 preview

ShaikUsaf-frameworks_base_AOSP10_r33_CVE-2022-20138

GitHubshaikusaf/shaikusaf-frameworks_base_aosp10_r33_cve-2022-20138

Proof-of-concept exploit for CVE-2022-20138 targeting Android 10 (AOSP r33) framework base, demonstrating a privilege escalation vulnerability in the…

android-securitybinary-exploitationexploitation+2
4 years ago
Previous12Next