Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
upb-any-recursion-audit preview

upb-any-recursion-audit

GitHubvardhan0257/upb-any-recursion-audit

Audit harness testing whether the CVE-2026-0994 Any-unwrapping recursion bug class affects upb's C core in Ruby and PHP protobuf bindings, with…

binary-analysiseducationfuzzing+4
6 days ago
PyMemoryEditor preview

PyMemoryEditor

GitHubjeanextreme002/pymemoryeditor

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

binary-analysisdebuggerseducation+3
21812 days ago
cve-2023-4911-exploit-optimized preview

cve-2023-4911-exploit-optimized

GitHubjarpex/cve-2023-4911-exploit-optimized

Pure C exploit for CVE-2023-4911 (Looney Tunables) — x86_64 & aarch64 implementations. Multi-processing brute-forcing, dynamic calibration,…

binary-exploitationeducationexploitation+5
416 days ago
the-key-ships-with-the-lock-cve-2026-82876-phison-s11-ssd-firmware-signature-bypass preview

the-key-ships-with-the-lock-cve-2026-82876-phison-s11-ssd-firmware-signature-bypass

GitHubhunt-benito/the-key-ships-with-the-lock-cve-2026-82876-phison-s11-ssd-firmware-signature-bypass

Proof-of-concept demonstrating a firmware signature verification bypass in Phison S11 SSDs, allowing attackers to re-sign modified firmware by…

educationembedded-systems-securityexploitation+4
20 days ago
xmloxide preview

xmloxide

GitHubjonwiggins/xmloxide

A pure Rust reimplementation of libxml2

binary-analysiscode-analysiscurated-resources+5
851 month ago
IOSSecuritySuite preview

IOSSecuritySuite

GitHubsecuring/iossecuritysuite

iOS platform security & anti-tampering Swift library

educationios-securitymobile-security+1
2.7k1 month ago
Stegano preview

Stegano

GitHubcedricbonhomme/stegano

A pure Python steganography module.

cryptographyeducationencryption-decryption-tools+2
5942 months ago
Phantom-Evasion-Loader preview

Phantom-Evasion-Loader

GitHubjm00nj/phantom-evasion-loader

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

binary-exploitationcommand-and-controleducation+6
1132 months ago
ruzzy preview

ruzzy

GitHubtrailofbits/ruzzy

A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

binary-analysiscode-analysisdynamic-analysis-sandboxing+3
1203 months ago
http2-security-lab preview

http2-security-lab

GitHubmadhantr0/http2-security-lab

HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python…

defensive-toolseducationlabs-practice+4
3 months ago
pharmacy-sqli-CVE-2026-7392 preview

pharmacy-sqli-CVE-2026-7392

GitHubmicrowaveabi/pharmacy-sqli-cve-2026-7392

SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection

database-securityeducationexploitation+3
3 months ago
kangaroo preview

kangaroo

GitHuboritwoen/kangaroo

GPU-accelerated Pollard's Kangaroo algorithm for solving the Elliptic Curve Discrete Logarithm Problem (ECDLP) on secp256k1, supporting Vulkan,…

binary-analysiscryptographyeducation+3
275 months ago
ejbca-pqc-lab preview

ejbca-pqc-lab

GitHubmokokash/ejbca-pqc-lab

Pure PQC two-tier PKI hierarchy using ML-DSA-65 (NIST FIPS 204) on EJBCA Community Edition — Root CA + Sub CA with CRL and OCSP

cloud-securitycryptographyeducation+2
6 months ago
bigint-buffer-safe preview

bigint-buffer-safe

GitHubloserlab/bigint-buffer-safe

Safe, pure-JS drop-in replacement for bigint-buffer. Fixes CVE-2025-3194 (CVSS 7.5). Zero dependencies, no native bindings.

educationencryption-decryption-toolsgeneral-purpose-utilities+2
16 months ago
CVE-2023-5360-exploit-with-native-libraries preview

CVE-2023-5360-exploit-with-native-libraries

GitHublavirudilshan/cve-2023-5360-exploit-with-native-libraries

CVE-2023-5360 PoC: Unauthenticated arbitrary file upload leading to RCE in Royal Elementor Addons (≤ 1.3.78), written in pure Python.

educationexploitationpayload-generation+3
19 months ago
log4py preview

log4py

GitHubdotpy-hax/log4py

pythonic pure python RCE exploit for CVE-2021-44228 log4shell

educationexploitationpayload-generation+3
24 years ago
InjuredAndroid preview
Archived

InjuredAndroid

GitHubb3nac/injuredandroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

android-securityctfeducation+5
7635 years ago