Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
CVE-2026-78306 preview

CVE-2026-78306

GitHubwh02m1/cve-2026-78306

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and…

bluetooth-securityembedded-systems-securityexploitation+6
91 day ago
Dji_ble_vuln preview

Dji_ble_vuln

GitHubfeedbeef/dji_ble_vuln

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

bluetooth-securitycommand-and-controlembedded-systems-security+6
4 days ago
Evil-M5Project preview

Evil-M5Project

GitHub7h30th3r0n3/evil-m5project

Multi-purpose WiFi penetration testing toolkit for M5Stack devices. Performs network scanning, evil-twin attacks, deauthentication, captive portal…

bluetooth-securitycommand-and-controleducation+9
2.7k10 days ago
poseidon preview

poseidon

GitHubgeneraldussduss/poseidon

80+ feature pentesting firmware for M5Stack Cardputer-Adv. WiFi, BLE, sub-GHz (CC1101), 2.4GHz (nRF24), LoRa (SX1262), IR, BadUSB, DHCP attacks,…

bluetooth-securitycommand-and-controlexploitation+9
1932 months ago
-BuL preview

-BuL

GitHubhegaz0y/-bul

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over…

bluetooth-securityexploitationexploit-frameworks+3
13 months ago
CVE-2026-31280-Insecure-Bluetooth-RFCOMM-Leading-to-Device-Crash-in-Parani-M10-Intercom preview

CVE-2026-31280-Insecure-Bluetooth-RFCOMM-Leading-to-Device-Crash-in-Parani-M10-Intercom

GitHubcipherx1802/cve-2026-31280-insecure-bluetooth-rfcomm-leading-to-device-crash-in-parani-m10-intercom

Proof-of-concept demonstrating an unauthenticated Bluetooth RFCOMM service in Parani M10 Intercom that allows arbitrary payload delivery, leading to…

bluetooth-securityexploitationhardware-iot-security+1
5 months ago
CVE-2025-69821-Beat-XP-Vega-Smartwatch-Security-Assessment preview

CVE-2025-69821-Beat-XP-Vega-Smartwatch-Security-Assessment

GitHubcipherx1802/cve-2025-69821-beat-xp-vega-smartwatch-security-assessment

A security assessment of the Beat XP VEGA Smartwatch (Firmware RB303ATV006229) focused on Bluetooth Low Energy (BLE) connectivity revealed a design…

bluetooth-securityembedded-systems-securityexploitation+6
5 months ago
flipper-mcp preview

flipper-mcp

GitHubroostercoopllc/flipper-mcp

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.

ai-securitybluetooth-securitycommand-and-control+9
226 months ago
DLPwn preview

DLPwn

GitHubgryfman/dlpwn

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

bluetooth-securitycommand-and-controldata-exfiltration+5
246 months ago
CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass preview

CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass

GitHubniranjangaire1995/cve-2025-46018-csc-pay-mobile-app-payment-authentication-bypass

Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4"

authentication-authorizationbluetooth-securityexploitation+3
1 year ago
CVE-2023-45866_WIP preview

CVE-2023-45866_WIP

GitHubv3ilsm1th/cve-2023-45866_wip

Simulates a Bluetooth keyboard to exploit CVE-2023-45866, injecting keystrokes via DuckyScript on vulnerable Android, iOS, macOS, and Linux devices…

bluetooth-securityexploitationhardware-iot-security+4
1 year ago
CVE-2025-27840-WIP preview

CVE-2025-27840-WIP

GitHubv3ilsm1th/cve-2025-27840-wip

Work-in-progress PoC for CVE-2025-27840, an ESP32 Bluetooth vulnerability involving undocumented HCI commands enabling memory access and device…

bluetooth-securityexploitationhardware-iot-security+1
1 year ago
BlueBunny preview

BlueBunny

GitHub90n45-d3v/bluebunny

BLE-based C2 server for Hak5 Bash Bunny enabling wireless command injection, payload delivery, and remote control over Bluetooth Low Energy.

bluetooth-securitycommand-and-controlhardware-iot-security+2
202 years ago
blue-pigeon preview

blue-pigeon

GitHubbluepigeonproject/blue-pigeon

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

android-securitybluetooth-securitycommand-and-control+4
565 years ago
CVE-2020-11539 preview

CVE-2020-11539

GitHubthe-girl-who-lived/cve-2020-11539

Improper Access Control in Tata Sonata Smartband

bluetooth-securityexploitationhardware-iot-security+3
16 years ago
POC-CVE-2018-4327-and-CVE-2018-4330 preview

POC-CVE-2018-4327-and-CVE-2018-4330

GitHubharryanon/poc-cve-2018-4327-and-cve-2018-4330

Proof-of-concept exploit for iOS Bluetooth stack vulnerabilities CVE-2018-4327 and CVE-2018-4330, enabling ARM PC register control on iPhone 6S via…

binary-exploitationbluetooth-securityexploitation+4
18 years ago
snoopy-ng preview

snoopy-ng

GitHubsensepost/snoopy-ng

Snoopy v2.0 - modular digital terrestrial tracking framework

bluetooth-securitycommand-and-controlcrawler+9
44211 years ago