Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
71 results
androguard preview

androguard

GitHubandroguard/androguard

Reverse engineering and pentesting for Android applications

android-securitydynamic-analysis-sandboxingmalware-analysis+6
6.3k2 days ago
APatch preview

APatch

GitHubbmax121/apatch

The patching of Android kernel and Android system

android-securitymobile-securitypayload-development+4
8.0k7 days ago
Lenovo-TB365FC-GhostLock-CVE-2026-43499 preview

Lenovo-TB365FC-GhostLock-CVE-2026-43499

GitHubwonjj6768/lenovo-tb365fc-ghostlock-cve-2026-43499

GhostLock (CVE-2026-43499) root + KernelSU LKM for the Lenovo TB365FC (ZUXOS / Android 16, kernel 5.15.170)

android-securitybinary-exploitationexploitation+6
11 days ago
apk-medit preview

apk-medit

GitHubsterrasec/apk-medit

memory search and patch tool on debuggable apk without root & ndk

android-securitybinary-analysismemory-forensics+2
43415 days ago
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day preview

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

android-securityeducationexploitation+7
318 days ago
objection preview

objection

GitHubsensepost/objection

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

android-securitydynamic-analysis-sandboxingexploitation+9
9.4k18 days ago
ghost-hoock preview

ghost-hoock

GitHubdeaurity/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
120 days ago
ghost-hoock preview

ghost-hoock

GitHubgenksome/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
421 days ago
CVE-2026-28576-poc preview

CVE-2026-28576-poc

GitHubmobilehackinglab/cve-2026-28576-poc

Educational proof-of-concept demonstrating a SQL injection vulnerability in Android 17's Contacts Provider, allowing a zero-permission app to…

android-securityeducationexploitation+4
4228 days ago
vivo_iqoo_neo_9_root_research_on_CVE-2025-21479 preview

vivo_iqoo_neo_9_root_research_on_CVE-2025-21479

GitHubreaizuguo/vivo_iqoo_neo_9_root_research_on_cve-2025-21479

iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** — 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案

android-securitybinary-exploitationexploitation+4
31 month ago
CVE-2026-64560-Analysis preview

CVE-2026-64560-Analysis

GitHubvillager1314/cve-2026-64560-analysis

Linux kernel UAF analysis for CVE-2026-64560 with race-triggering PoC, patch review, affected LTS/Android version matrix, and self-check for patched…

android-securitybinary-exploitationeducation+3
692 months ago
renef-skills preview

renef-skills

GitHubvichhka-git/renef-skills

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

android-securitybinary-analysisctf+9
153 months ago
blueshrimp preview

blueshrimp

GitHubzhuowei/blueshrimp

Proof-of-concept for CVE-2025-48593

android-securitybluetooth-securityembedded-systems-security+3
5610 months ago
UnrestrictedUserCreator preview

UnrestrictedUserCreator

GitHubrifting/unrestrictedusercreator

Simple script to add a new, unrestricted user on devices with Family Link by abusing CVE-2025-32324 (pre September patch)

android-securityexploitationmobile-security+2
411 months ago
ResourcePoison preview

ResourcePoison

GitHubmichalbednarski/resourcepoison

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

android-securityexploitationmobile-security+3
1080 years ago
ThisSeemsWrong preview

ThisSeemsWrong

GitHubmichalbednarski/thisseemswrong

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

android-securitybinary-exploitationexploit-frameworks+3
470 years ago
AbxOverflow preview

AbxOverflow

GitHubmichalbednarski/abxoverflow

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

android-securitybinary-exploitationcode-analysis+5
790 years ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubcanyie/cve-2024-0044

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

android-securitybinary-exploitationeducation+5
1802 years ago
Previous1234Next