Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
153 results
HyperOS-Directory-Traversal-Analysis preview

HyperOS-Directory-Traversal-Analysis

GitHubkkaanozturk/hyperos-directory-traversal-analysis

Xiaomi HyperOS AVCodec Medya Framework'ündeki Use-After-Free (CVE-2025-21082) Zafiyetinin Derinlemesine Analizi, Rust Simülasyonu ve İnteraktif Web…

binary-exploitationctfdynamic-analysis-sandboxing+8
1
2 months ago
CVE-2026-32945 preview

CVE-2026-32945

GitHubjohanneslks/cve-2026-32945

PJSIP DNS Compression Pointer Heap OOB Read (Remote DoS)

binary-analysisdynamic-analysis-sandboxingexploitation+2
5 months ago
Kaspersky_CVE-2024-3094 preview

Kaspersky_CVE-2024-3094

GitHubvesjolyjd/kaspersky_cve-2024-3094

Security review of CVE-2024-3094 (XZ Utils backdoor) including threat modeling, static/dynamic code analysis, fuzzing with AFL++, and a…

code-analysisdynamic-analysis-sandboxingeducation+7
5 months ago
CVE-2026-42945-nginx-rift-poc preview

CVE-2026-42945-nginx-rift-poc

GitHubf2u0a0d3/cve-2026-42945-nginx-rift-poc

PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab,…

binary-exploitationdynamic-analysis-sandboxingeducation+6
14 months ago
nginx-cve-2026-42945-poc preview

nginx-cve-2026-42945-poc

GitHubforxiucn/nginx-cve-2026-42945-poc

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via…

binary-exploitationcontainer-securitydynamic-analysis-sandboxing+5
14 months ago
CVE-2023-4863- preview

CVE-2023-4863-

GitHubcrackercat/cve-2023-4863-

Triggering the famous libweb 0day vuln with libfuzzer

binary-analysisdynamic-analysis-sandboxingexploitation+2
12 years ago
reproducer-poc-CVE-2022-0847 preview

reproducer-poc-CVE-2022-0847

GitHubstfnw/reproducer-poc-cve-2022-0847

Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.

binary-exploitationdynamic-analysis-sandboxingexploitation+3
8 months ago
extract75-cve-2020-13995 preview

extract75-cve-2020-13995

GitHubdbrumley/extract75-cve-2020-13995

Control flow hijack exploit for CVE-2020-13995 with Docker-based deployment and Mayhem fuzzing integration for automated vulnerability testing.

binary-exploitationdynamic-analysis-sandboxingexploitation+2
3 years ago
bunch-of-fuzzers-developed-using-libfuzzer-and-asan preview

bunch-of-fuzzers-developed-using-libfuzzer-and-asan

GitHubspiralbl0ck/bunch-of-fuzzers-developed-using-libfuzzer-and-asan

Collection of fuzzers built with libFuzzer and AddressSanitizer for automated bug detection in C/C++ code.

binary-analysisdynamic-analysis-sandboxingfuzzing+1
5 years ago
rhuss__jolokia_CVE-2018-1000129_1-4-0 preview

rhuss__jolokia_CVE-2018-1000129_1-4-0

GitHubshoucheng3/rhuss__jolokia_cve-2018-1000129_1-4-0

Agent-based JMX access via JSON/HTTP with bulk requests, fine-grained security policies, and proxy mode for remote MBeanServer monitoring and…

api-securityconfiguration-auditingdynamic-analysis-sandboxing+2
10 months ago
expat_CVE-2024-28757 preview

expat_CVE-2024-28757

GitHubrenukaselvar/expat_cve-2024-28757

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

code-analysisdynamic-analysis-sandboxingexploitation+3
2 years ago
CVE-2024-1441 preview

CVE-2024-1441

GitHubalmkuznetsov/cve-2024-1441

Reproduces fuzzing and crash analysis for CVE-2024-1441 using AFL++ and CASR, with detailed setup and commands for libvirt.

binary-analysisdynamic-analysis-sandboxingexploitation+2
2 years ago
platform_external_libvpx_v1.8.0_CVE-2023-5217 preview

platform_external_libvpx_v1.8.0_CVE-2023-5217

GitHubtrinadh465/platform_external_libvpx_v1.8.0_cve-2023-5217

Patched libvpx codebase addressing CVE-2023-5217 with sanitizer support and cross-platform build configurations for secure VP8/VP9 encoding.

binary-analysiscode-analysisdynamic-analysis-sandboxing+3
2 years ago
REx-skill preview

REx-skill

GitHubtihanyin/rex-skill

REx@Skill - Agentic Reverse Engineering eXecution Skill for binary vulnerability discovery

ai-assisted-reversingbinary-analysisbinary-exploitation+8
444 days ago
Sandroid_Dexray-Intercept preview

Sandroid_Dexray-Intercept

GitHubfkie-cad/sandroid_dexray-intercept

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

android-securitycryptographydynamic-analysis-sandboxing+8
920 days ago
seclab-taskflows-fuzzing preview

seclab-taskflows-fuzzing

GitHubgithubsecuritylab/seclab-taskflows-fuzzing

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

ai-securitycode-analysisdynamic-analysis-sandboxing+7
17 days ago
reverse-engineering-browser preview

reverse-engineering-browser

GitHubsunghoojung/reverse-engineering-browser

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

code-analysisdebuggersdynamic-analysis-sandboxing+9
52 days ago
unicorn_pe preview
Archived

unicorn_pe

GitHubhzqst/unicorn_pe

Emulates Windows PE execution using Unicorn engine for malware analysis, unpacking packed binaries, and decrypting VMProtect strings and imports.

binary-analysisdynamic-analysis-sandboxingexploitation+3
9249 months ago
Previous1…789Next