Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
MemorizingTrustManager preview

MemorizingTrustManager

GitHubge0rg/memorizingtrustmanager

A "plugin" for Android Java to allow asking the user about SSL certificates

android-securityauthenticationcryptography+3
181
3 years ago
kcmd preview

kcmd

Bitbucketaseemjakhar/kcmd

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

cryptographyexploitationhardware-iot-security+4
11 years ago
test_avb_key preview

test_avb_key

GitHubnccgroup/test_avb_key

Python utility to check if Android verified boot images (vbmeta) are signed with publicly known test keys, identifying misconfigurations in release…

android-securitycryptographyfirmware-analysis+3
92 years ago
Pixnapping-Attack-on-Android preview

Pixnapping-Attack-on-Android

GitHubdemining/pixnapping-attack-on-android

Pixnapping Attack: Compromising private keys and seed phrases through vulnerability CVE-2025-48561 represents a new critical threat to the Bitcoin…

android-securitycryptographyexploitation+2
1910 months ago
themis preview

themis

GitHubcossacklabs/themis

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

authenticationcryptographydatabase-security+4
2.0k2 years ago
ESPTouchCatcher preview

ESPTouchCatcher

GitHubsalgio/esptouchcatcher

eWeLinkESPT is a tool that automatically decodes and decrypts the WiFi network credentials transmitted to a supported ESP-based IoT device by the…

cryptographyexploitationhardware-iot-security+4
55 years ago
eWeLink-QR-Code preview

eWeLink-QR-Code

GitHubsalgio/ewelink-qr-code

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

cryptographyexploitationhardware-iot-security+3
15 years ago
libsodium preview

libsodium

GitHubjedisct1/libsodium

A modern, portable, easy to use crypto library.

cryptographyencryption-decryption-toolshash-analysis
14.0k1 day ago
security-study-plan preview

security-study-plan

GitHubjassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

api-securitycloud-securitycryptography+8
5.1k7 days ago
libsignal preview

libsignal

GitHubsignalapp/libsignal

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

cryptographyencryption-decryption-toolshardware-security+2
6.0k2 days ago
wolfssl preview

wolfssl

GitHubwolfssl/wolfssl

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

cloud-securitycryptographyembedded-systems-security+6
2.9k2 days ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1021 year ago
libexif_Android10_r33_CVE-2016-6328 preview

libexif_Android10_r33_CVE-2016-6328

GitHubpazhanivelmani/libexif_android10_r33_cve-2016-6328

C-based library for parsing, editing, and saving EXIF metadata from JPEG images, with a focus on exploiting CVE-2016-6328 for Android 10.

binary-analysiscryptographydigital-forensics+3
1 year ago
zte-smartlife-app-pwned preview

zte-smartlife-app-pwned

GitHubminanagehsalalma/zte-smartlife-app-pwned

ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.

android-securityapi-securitycryptography+7
20h 43m ago
Tools preview

Tools

GitHubcyberguideme/tools

Cyber Security Tools

cryptographycurated-resourceseducation+6
4437 years ago
ultrablue preview

ultrablue

GitHubanssi-fr/ultrablue

User-friendly Lightweight TPM Remote Attestation over Bluetooth

authenticationbluetooth-securitycryptography+2
1743 years ago
zipbrk preview

zipbrk

GitHubkvesel/zipbrk

Zip file format fuzzer and multi-tool.

binary-analysiscryptographyencryption-decryption-tools+4
124 months ago
CVE-2016-6271 preview

CVE-2016-6271

GitHubgteissier/cve-2016-6271

Proof-of-concept exploit for CVE-2016-6271 demonstrating ZRTP man-in-the-middle attack via hash-commitment bypass in libbzrtp, with Docker-based…

cryptographyexploitationnetwork-security+2
59 years ago
Previous123Next