Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
131 results
ReArk preview

ReArk

GitHublkimuk/reark

An intelligent reverse engineering analysis tool designed for multiple target platforms, currently supporting HarmonyOS (HAP/APP/ABC) and Android…

ai-assisted-reversingandroid-securitybinary-analysis+6
3154 days ago
super-trouper preview

super-trouper

GitHubcrissyfield/super-trouper

MCP server exposing Frida instrumentation as tools for coding agents to connect to devices, inspect processes, manage sessions, and load JavaScript…

android-securitybinary-analysisdebuggers+5
41 day ago
kunglao-agent preview

kunglao-agent

GitHubamd2g2zz/kunglao-agent

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

ai-assisted-reversingandroid-securitybinary-analysis+8
262 days ago
the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss preview

the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

GitHubhunt-benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

android-securitydynamic-analysis-sandboxingexploitation+6
3 days ago
slythestx preview

slythestx

GitHubstuxctf/slythestx

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

android-securitydynamic-analysis-sandboxingios-security+6
141 month ago
rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android preview

rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android

GitHubhunt-benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android

Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…

android-securitybinary-analysisdefensive-tools+3
HydraDragonAV-Mobile preview

HydraDragonAV-Mobile

GitHubhydradragonantivirus/hydradragonav-mobile

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

android-securitydefensive-toolsdynamic-analysis-sandboxing+6
1616 days ago
Fermion preview

Fermion

GitHubfuzzysecurity/fermion

Fermion, an electron wrapper for Frida & Monaco.

android-securitybinary-analysisdebuggers+4
7021 year ago
unidbg preview

unidbg

GitHubzhkl0228/unidbg

Allows you to emulate an Android native library, and an experimental iOS emulation

ai-assisted-reversingandroid-securitybinary-analysis+5
5.2k7 days ago
binder-trace preview

binder-trace

GitHubfoundryzero/binder-trace

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".

android-securitybinary-analysisdynamic-analysis-sandboxing+3
7691 year ago
AMFDSer-ngng preview

AMFDSer-ngng

GitHubnccgroup/amfdser-ngng

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
2711 years ago
assethook preview

assethook

GitHubnccgroup/assethook

LD_PRELOAD magic for Android's AssetManager

android-securitydynamic-analysis-sandboxingmobile-app-pentesting+3
829 years ago
LazyDroid preview

LazyDroid

GitHubnccgroup/lazydroid

bash script to facilitate some aspects of an Android application assessment

android-securitydynamic-analysis-sandboxinginformation-gathering+3
1605 years ago
AWE preview

AWE

GitHubstuxlabs/awe

adaptive agents for dynamic web penetration testing

dynamic-analysis-sandboxingeducationpapers-research+4
216 months ago
Vega preview

Vega

GitHubsubgraph/vega

Subgraph Vega

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
36210 years ago
collaborator preview

collaborator

GitHubprojectdiscovery/collaborator

BurpSuite Standard/Private Collaborator Library

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
254 years ago
burp-radamsa preview

burp-radamsa

GitHubraz0r/burp-radamsa

Radamsa fuzzer extension for Burp Suite

api-security-testingdynamic-analysis-sandboxingfuzzing+3
2313 years ago
SILENTCHAIN preview

SILENTCHAIN

GitHubsilentchainai/silentchain

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

ai-securityapi-security-testingcode-analysis+8
4592 months ago
Previous12…8Next
1
24 days ago