Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
210 results
Bypass-Sandbox-Evasion preview

Bypass-Sandbox-Evasion

GitHubzeromemoryex/bypass-sandbox-evasion

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

anti-botbinary-analysisids-ips-evasion+1
1413 years ago
Evasor preview

Evasor

GitHubcyberark/evasor

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

binary-analysisdefensive-toolspenetration-testing+3
3266 years ago
redexer preview

redexer

GitHubplum-umd/redexer

The Redexer binary instrumentation framework for Dalvik bytecode

android-securitybinary-analysisdynamic-analysis-sandboxing+4
1745 years ago
ApkAnalyser preview
Archived

ApkAnalyser

GitHubsonyxperiadev/apkanalyser

Static analysis tool for Android APKs that inspects Dalvik bytecode, decodes XML resources, and detects potential issues. Supports binary…

android-securitybinary-analysiscode-analysis+3
1.0k3 years ago
protobuf-inspector preview

protobuf-inspector

GitHubmildsunrise/protobuf-inspector

🕵️ Tool to reverse-engineer Protocol Buffers with unknown definition

binary-analysisreverse-engineeringutilities-frameworks
1.1k5 years ago
jadx preview

jadx

GitHubskylot/jadx

Command-line and GUI tool for decompiling Android Dex and APK files into readable Java source code, with resource decoding, deobfuscation, and Smali…

android-securitybinary-analysisdebuggers+5
50.3k1 day ago
rematch preview

rematch

GitHubnirizr/rematch

REmatch, a complete binary diffing framework that is free and strives to be open source and community driven.

binary-analysisreverse-engineeringutilities-frameworks
1567 years ago
path-auditor preview
Archived

path-auditor

GitHubgoogle/path-auditor

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

binary-analysisdynamic-code-analysisexploitation+3
2505 years ago
LID preview

LID

GitHubazqzazq1/lid

LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux…

binary-analysiseducationexploitation+6
203 months ago
Windows-SignedBinary preview

Windows-SignedBinary

GitHubmr-un1k0d3r/windows-signedbinary

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

adversarial-attackbinary-analysishash-analysis+4
2607 years ago
-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis- preview

-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis-

GitHubkaandemir993/-remcos-rat-fileless-svchost-injection-obfuscated-payload-analysis-

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

api-securitybinary-analysisdynamic-analysis-sandboxing+8
31 month ago
renef-skills preview

renef-skills

GitHubvichhka-git/renef-skills

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

android-securitybinary-analysisctf+9
142 months ago
TheLastBundleMismatch preview

TheLastBundleMismatch

GitHubmichalbednarski/thelastbundlemismatch

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

android-securitybinary-analysisexploitation+2
1012 years ago
ret-sync preview

ret-sync

GitHubbootleg/ret-sync

ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja…

binary-analysisdebuggersdynamic-analysis-sandboxing+2
2.4k6 months ago
CVE-2026-25250 preview

CVE-2026-25250

GitHubthemalwareguardian/cve-2026-25250

Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without…

binary-analysiseducationexploitation+3
117 days ago
LIEF preview

LIEF

GitHublief-project/lief

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

ai-assisted-reversingandroid-securitybinary-analysis+12
5.6k3 days ago
Apktool preview

Apktool

GitHubibotpeaches/apktool

A tool for reverse engineering Android apk files

android-securitybinary-analysisdebuggers+4
25.4k1 day ago
blutter preview

blutter

GitHubworawit/blutter

Flutter Mobile Application Reverse Engineering Tool

android-securitybinary-analysismobile-security+1
2.6k14 days ago
Previous12…12Next