Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
18 results
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal preview

two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

GitHubhunt-benito/two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

android-securityexploitationmobile-app-pentesting+4
27 days ago
one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow preview

one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow

GitHubhunt-benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

android-securitydynamic-code-analysiseducation+3
1 month ago
MalEval preview

MalEval

GitHubzhengxr930/maleval

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

ai-securityandroid-securitycode-analysis+5
51 month ago
FreeMOCA preview

FreeMOCA

GitHubiqsec-lab/freemoca

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

android-securityeducationmachine-learning+3
2 months ago
CVE-2025-48593 preview

CVE-2025-48593

GitHublogesh-git001/cve-2025-48593

"A single malicious packet can own your device." — Android Security Team, Nov 2025

android-securitybluetooth-securityeducation+7
74 months ago
GDA-android-reversing-Tool preview

GDA-android-reversing-Tool

GitHubcharles2gan/gda-android-reversing-tool

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

android-securityctfdynamic-analysis-sandboxing+9
4.8k5 months ago
ZygoteExploitDemo preview

ZygoteExploitDemo

GitHubgitamans/zygoteexploitdemo

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

android-securitybinary-exploitationeducation+7
26 months ago
permhash preview

permhash

GitHubgoogle/permhash

Framework for hashing declared permissions in Chromium extensions and APKs, enabling clustering, hunting, and pivoting across potentially malicious…

android-securitydigital-forensicshash-analysis+3
459 months ago
EvilDroid preview

EvilDroid

GitHubsridhar-sec/evildroid

EvilDroid automates the exploitation of CVE-2024-0044, installing malicious payloads on a target device and extracting sensitive data. It features…

android-securityeducationexploitation+3
301 year ago
Dirty_Stream-Android-POC preview

Dirty_Stream-Android-POC

GitHubcyb3r-w0lf/dirty_stream-android-poc

Android - Dirty Stream exploit for MI-File Explorer V1-210567 version. CVE-2024-35205

android-securityeducationexploitation+3
131 year ago
CVE-2024-36842-Backdooring-Oncord-Android-Sterio- preview

CVE-2024-36842-Backdooring-Oncord-Android-Sterio-

GitHubabbiy/cve-2024-36842-backdooring-oncord-android-sterio-

CVE-2024-36842, Creating Persistent Backdoor on Oncord+ android/ios car infotaiment using malicious script!

android-securityembedded-systems-securityexploitation+5
51 year ago
Android-Privilege-Escalation-Remote-Access-Vulnerability-CVE-2015-1805 preview

Android-Privilege-Escalation-Remote-Access-Vulnerability-CVE-2015-1805

GitHubireshchaminda1/android-privilege-escalation-remote-access-vulnerability-cve-2015-1805

AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT…

android-securityexploitationexploit-frameworks+5
53 years ago
CVE-2022-3168-adb-unexpected-reverse-forwards preview

CVE-2022-3168-adb-unexpected-reverse-forwards

GitHubirsl/cve-2022-3168-adb-unexpected-reverse-forwards

Proof of concept code to exploit flaw in adb that allowed opening network connections on the host to arbitrary destinations

android-securityexploitationmobile-security+3
33 years ago
pacpoc preview

pacpoc

GitHubaemmitt-ns/pacpoc

A local PoC exploit for CVE-2019-2205

android-securityexploitationmobile-security+2
44 years ago
CVE-2022-0219 preview

CVE-2022-0219

GitHubhaxatron/cve-2022-0219

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

android-securitycode-analysismobile-security+3
4 years ago
HosTaGe preview

HosTaGe

GitHubaau-network-security/hostage

Low Interaction Mobile Honeypot

android-securitydefensive-toolseducation+5
995 years ago
androwarn preview

androwarn

GitHubmaaaaz/androwarn

Yet another static code analyzer for malicious Android applications

android-securitymalware-analysismobile-security+2
5326 years ago
scaredycat preview

scaredycat

GitHubeudemonics/scaredycat

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

android-securityexploitationmobile-security+4
1710 years ago