Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
69 results
apiscope preview

apiscope

GitHubkaisonox/apiscope

An API hooking framework for intercepting and monitoring Windows applications

api-security-testingbinary-analysisdebuggers+4
203 months ago
sandsifter preview

sandsifter

GitHubxoreaxeaxeax/sandsifter

The x86 processor fuzzer

binary-analysisfuzzinghardware-security+2
5.1k9 years ago
sandsifter preview

sandsifter

GitHubbattelle/sandsifter

The x86 processor fuzzer

binary-analysiseducationfuzzing+4
5329 years ago
appmon preview
Archived

appmon

GitHubdpnishant/appmon

Documentation:

android-securitybinary-analysisdebuggers+6
1.6k3 years ago
netzob preview

netzob

GitHubnetzob/netzob

Open-source toolkit for reverse engineering, modeling, and fuzzing communication protocols. Infers message formats and state machines from network…

binary-analysisfuzzingnetwork-security+1
8363 years ago
Cisco-ASA-vulnerability-research preview

Cisco-ASA-vulnerability-research

GitHubcobbbex/cisco-asa-vulnerability-research

Systematic reverse engineering of Cisco ASA's lina binary to discover and analyze memory corruption vulnerabilities, including CVE-2025-20333 and…

binary-analysisexploitationfuzzing+4
1 month ago
cve-2020-35498-flag preview

cve-2020-35498-flag

GitHubfreddierice/cve-2020-35498-flag

C-based exploit tool to detect and trigger CVE-2020-35498 via raw socket injection with BPF filter, targeting wireless interfaces for vulnerability…

binary-analysisexploitationnetwork-security+2
5 years ago
zeek-elf preview

zeek-elf

GitHubcorelight/zeek-elf

A Zeek ELF File Analyzer

binary-analysisintrusion-detectionmalware-analysis+2
92 years ago
doona preview

doona

GitHubwireghoul/doona

Network based protocol fuzzer

binary-analysisexploitationfuzzing+3
774 years ago
HPE-Aruba-AOS8-Vulnerabilities preview

HPE-Aruba-AOS8-Vulnerabilities

GitHubjm00nj/hpe-aruba-aos8-vulnerabilities

ArubaOS 8.13.2.0 pre-auth attack surface research. XXE+SSRF, ICMP reflection, buffer over-read, hardcoded credentials — all submitted to HPE…

binary-analysisexploitationfirmware-analysis+3
43 months ago
CVE-2026-34159-Vulnerability-Research-Analysis-Detection preview

CVE-2026-34159-Vulnerability-Research-Analysis-Detection

GitHubrohithronanki/cve-2026-34159-vulnerability-research-analysis-detection

Critical buffer validation bypass in deserialize_tensor() (llama.cpp < b8492). Null tensor buffer skips bounds check, enabling unauthenticated…

binary-analysisexploitationintrusion-detection+2
4 months ago
windows_tcpip_fuzz preview

windows_tcpip_fuzz

GitHubpersonnumber3377/windows_tcpip_fuzz

This is my attempt at fuzzing the tcpip.sys driver in windows via using scapy. This is inspired by this vulnerability here:…

binary-analysisexploitationfuzzing+2
1 year ago
CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed preview

CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed

GitHubwildfootw/cve-2014-0160_openssl_1.0.1f_heartbleed

Exploit for the Heartbleed vulnerability (CVE-2014-0160) in OpenSSL 1.0.1f, allowing memory disclosure from vulnerable servers.

binary-analysisexploitationnetwork-security+2
5 years ago
CVE-2021-24086 preview
Archived

CVE-2021-24086

GitHub0vercl0k/cve-2021-24086

Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.

binary-analysisexploitationfuzzing+2
2365 years ago
CVE-2026-2005 preview

CVE-2026-2005

GitHubopen-flaw/cve-2026-2005

PostgreSQL pgcrypto heap buffer overflow PoC demonstrating CVE-2026-2005: low-privileged RCE and privilege escalation to superuser via crafted…

binary-analysisbinary-exploitationdatabase-security+4
1 month ago
CVE-2024-1346 preview

CVE-2024-1346

GitHubpetergabaldon/cve-2024-1346

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

binary-analysisdatabase-securityexploitation+3
22 years ago
-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis- preview

-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis-

GitHubkaandemir993/-remcos-rat-fileless-svchost-injection-obfuscated-payload-analysis-

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

api-securitybinary-analysisdynamic-analysis-sandboxing+8
22 months ago
FalconEye preview

FalconEye

GitHubrajiv2790/falconeye

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

binary-analysisdefensive-toolsintrusion-detection+1
3105 years ago
Previous1234Next