Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
88 results
CVE-2024-0044 preview

CVE-2024-0044

GitHubcanyie/cve-2024-0044

RunAsAnyone: PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation…

android-securitybinary-exploitationeducation+5
180
1 year ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
2568 months ago
Apepe preview

Apepe

GitHub0xdsm/apepe

Extracts app settings, permissions, deeplinks, and SSL pinning bypass suggestions from Android APK files via static analysis of AndroidManifest.xml,…

android-securityinformation-gatheringmobile-app-pentesting+1
15610 months ago
maldrolyzer preview

maldrolyzer

GitHubmaldroid/maldrolyzer

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

android-securitycommand-and-controlinformation-gathering+3
11211 years ago
OpenContacts preview

OpenContacts

GitLabsultanahamer/opencontacts

Android contact manager that stores contacts in an isolated database, preventing other apps from accessing them. Provides call log and caller ID…

android-securityprivacy
992 months ago
AbxOverflow preview

AbxOverflow

GitHubmichalbednarski/abxoverflow

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

android-securitybinary-exploitationcode-analysis+5
6810 months ago
android_autorooter preview

android_autorooter

GitHubscs-labrat/android_autorooter

Exfiltrate sensitive user data from apps on Android 12 and 13 using CVE-2024-0044 vulnerability remotely

android-securitydata-exfiltrationexploitation+5
772 years ago
GeckoDroid preview

GeckoDroid

GitHubblacksnufkin/geckodroid

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

android-securitycommand-and-controlmobile-security+4
385 months ago
Artemis preview

Artemis

GitHubhadesscs/artemis

Extracts and investigates infrastructure (IPs, domains) from APK files, with manifest parsing and WHOIS lookup for mobile application reconnaissance.

android-securityinformation-gatheringmobile-security+2
663 years ago
TransitionPlayer preview

TransitionPlayer

GitHubcanyie/transitionplayer

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

android-securitybinary-exploitationeducation+4
331 month ago
CVE-2021-25374_Samsung-Account-Access preview

CVE-2021-25374_Samsung-Account-Access

GitHubreverseclabs/cve-2021-25374_samsung-account-access

This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung…

android-securityexploitationmobile-security+3
322 years ago
CVE-2026-0047-poc preview

CVE-2026-0047-poc

GitHubmobilehackinglab/cve-2026-0047-poc

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

android-securitybinary-exploitationeducation+6
153 months ago
jadx-magic-strings preview

jadx-magic-strings

GitHub0rshemesh/jadx-magic-strings

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

android-securitybinary-analysiscode-analysis+5
399 months ago
CVE-2023-6241-Pixel7_Adaptation preview

CVE-2023-6241-Pixel7_Adaptation

GitHubilgobbo00/cve-2023-6241-pixel7_adaptation

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241

android-securitybinary-exploitationdebuggers+5
141 year ago
ztewaste preview

ztewaste

GitHubjoshatticus/ztewaste

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

android-securitydata-exfiltrationdigital-forensics+6
32 months ago
ABL_ROP preview

ABL_ROP

GitHubboredpentester/abl_rop

Experimenting with CVE-2022-20120 (Pixel Bootloader / ABL) using Unicorn, derived from eShard's emulator at…

android-securitybinary-exploitationembedded-systems-security+4
71 year ago
CVE-2021-43530-UXSS-On-QRcode-Reader- preview

CVE-2021-43530-UXSS-On-QRcode-Reader-

GitHubhfh86/cve-2021-43530-uxss-on-qrcode-reader-

CVE-2021-43530 A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned…

android-securityexploitationmobile-security+2
22 months ago
DocViewerExploitApp preview

DocViewerExploitApp

GitHubtinopreter/docviewerexploitapp

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

android-securitybinary-exploitationdynamic-code-analysis+6
1 year ago
Previous12345Next