Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
neo preview

neo

GitHub4ier/neo

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

ai-securityapi-securitycrawler+8
7575 months ago
decomp2dbg preview

decomp2dbg

GitHubmahaloz/decomp2dbg

A plugin to introduce interactive symbols into your debugger from your decompiler

binary-analysisbinary-exploitationdebuggers+3
8232 months ago
burpfox preview

burpfox

GitHubhalilkirazkaya/burpfox

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

dynamic-analysis-sandboxingpenetration-testingvulnerability-analysis+3
237 months ago
schrodingers-toctou preview

schrodingers-toctou

GitHubxoreaxeaxeax/schrodingers-toctou

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

binary-analysisdynamic-analysis-sandboxingeducation+3
1401 month ago
firmware-workshop preview

firmware-workshop

GitHubonekey-sec/firmware-workshop

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…

binary-analysisdynamic-analysis-sandboxingeducation+5
673 months ago
windbg-mcp preview

windbg-mcp

GitHubgengstah/windbg-mcp

An MCP (Model Context Protocol) server that turns all pybag Windows debugger functions into native MCP tools. It lets MCP-compatible clients (Claude…

binary-analysisdebuggersdynamic-analysis-sandboxing+7
945 months ago
XboxSeries preview

XboxSeries

GitHubdaniellmcguire/xboxseries

Personal research into the Xbox Series Architecture

binary-analysisdebuggersdynamic-analysis-sandboxing+6
612 months ago
TraceTree preview

TraceTree

GitHubtejasprasad2008-afk/tracetree

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

container-securitydevsecopsdynamic-analysis-sandboxing+6
4217 days ago
MaliciousBrowserExtensions preview

MaliciousBrowserExtensions

GitHubgherardofiori/maliciousbrowserextensions

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

curated-resourcesdynamic-analysis-sandboxingeducation+4
3121 days ago
Sandroid_Dexray-Intercept preview

Sandroid_Dexray-Intercept

GitHubfkie-cad/sandroid_dexray-intercept

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

android-securitycryptographydynamic-analysis-sandboxing+8
1025 days ago
reDOM preview

reDOM

GitHubweirdmachine64/redom

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

api-security-testingdynamic-analysis-sandboxinginformation-gathering+5
154 months ago
-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis- preview

-Remcos-RAT-Fileless-svchost-Injection-Obfuscated-Payload-Analysis-

GitHubkaandemir993/-remcos-rat-fileless-svchost-injection-obfuscated-payload-analysis-

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

api-securitybinary-analysisdynamic-analysis-sandboxing+8
22 months ago
dae preview

dae

GitHubejfkdev/dae

Config-driven Dart AOT snapshot analyzer that exports blutter-compatible symbols and structs for IDA, radare2 and Frida, and decompiles functions…

android-securitybinary-analysisdebuggers+6
65 days ago
HWID-SteamSpywareTerminator preview

HWID-SteamSpywareTerminator

GitHubgmh5225/hwid-steamspywareterminator

Work-in-progress library injected into Steam to block the hidden CFillMachineInfoThread that collects HWID, disk, network adapter, and registry…

anti-botbinary-analysisdefensive-tools+3
14 years ago
bytecode-viewer preview

bytecode-viewer

GitHubkonloch/bytecode-viewer

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

android-securitybinary-analysiscode-analysis+6
15.7k2 months ago
flare-floss preview

flare-floss

GitHubmandiant/flare-floss

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

ai-assisted-reversingbinary-analysisdigital-forensics+8
4.2k1 day ago
Mergen preview

Mergen

GitHubnac-l/mergen

Deobfuscation via optimization with usage of LLVM IR and parsing assembly.

binary-analysisbinary-exploitationdynamic-analysis-sandboxing+2
9064 months ago
jackhammer preview

jackhammer

GitHubolacabs/jackhammer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

code-analysisconfiguration-auditingdevsecops+9
7387 years ago
Previous12Next