Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
clusterfuzz preview

clusterfuzz

GitHubgoogle/clusterfuzz

Scalable fuzzing infrastructure with coverage-guided engines (libFuzzer, AFL, Honggfuzz), automated crash deduplication, bug filing, and regression…

devsecopsdynamic-analysis-sandboxingfuzzing+1
5.6k
1 day ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
61 month ago
windbg-mcp preview

windbg-mcp

GitHubgengstah/windbg-mcp

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

binary-analysisdebuggersdynamic-analysis-sandboxing+7
914 months ago
markdown-exfil-tester preview

markdown-exfil-tester

GitHubtrerb/markdown-exfil-tester

Black-box test whether an LLM chatbot is vulnerable to markdown/HTML exfil (CVE-2025-32711 class). Spins up a sink, sends payloads, renders in…

ai-securityctfdynamic-analysis-sandboxing+6
4 months ago
GDA-android-reversing-Tool preview

GDA-android-reversing-Tool

GitHubcharles2gan/gda-android-reversing-tool

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

android-securityctfdynamic-analysis-sandboxing+9
4.8k4 months ago
PHP-Fuzzer preview

PHP-Fuzzer

GitHubnikic/php-fuzzer

Edge-coverage-guided fuzzer for PHP libraries that detects bugs via crashes, timeouts, and warnings. Supports corpus management, crash minimization,…

code-analysisdynamic-analysis-sandboxingfuzzing+1
4417 months ago
efi_fuzz preview
Archived

efi_fuzz

GitHubsentinel-one/efi_fuzz

Coverage-guided fuzzer for UEFI NVRAM variables using Qiling emulation and AFL++ to discover firmware vulnerabilities through automated input…

binary-analysisdynamic-analysis-sandboxingembedded-systems-security+3
1541 year ago
CVE-2024-54916 preview

CVE-2024-54916

GitHubsahalll/cve-2024-54916

Frida-based proof-of-concept demonstrating authentication bypass in Telegram Android by hooking SharedConfig.checkPasscode to always return true,…

android-securityauthenticationbinary-analysis+4
1 year ago
CVE-2024-1441 preview

CVE-2024-1441

GitHubalmkuznetsov/cve-2024-1441

Reproduces fuzzing and crash analysis for CVE-2024-1441 using AFL++ and CASR, with detailed setup and commands for libvirt.

binary-analysisdynamic-analysis-sandboxingexploitation+2
2 years ago
icicle preview

icicle

GitHubicicle-emu/icicle

Emulation-based fuzzer for MSP430 firmware that finds and analyzes memory-corruption bugs with detailed crash reports and reproducible inputs.

binary-analysisdynamic-analysis-sandboxingembedded-systems-security+3
1922 years ago
PyJFuzz preview

PyJFuzz

GitHubmseclab/pyjfuzz

PyJFuzz - Python JSON Fuzzer

api-security-testingdynamic-analysis-sandboxingfuzzing+2
3773 years ago
ReClass.NET preview

ReClass.NET

GitHubreclassnet/reclass.net

More than a ReClass port to the .NET platform.

binary-analysiscode-analysisdebuggers+4
2.2k3 years ago
toothpicker preview

toothpicker

GitHubseemoo-lab/toothpicker

Coverage-guided in-process fuzzer for iOS Bluetooth daemon (bluetoothd) using FRIDA, with over-the-air fuzzing for MagicPairing protocol and crash…

bluetooth-securitydynamic-analysis-sandboxingfuzzing+3
2464 years ago
flashmingo preview
Archived

flashmingo

GitHubmandiant/flashmingo

Automatic analysis of SWF files based on some heuristics. Extensible via plugins.

binary-analysisdynamic-analysis-sandboxingeducation+6
1207 years ago