Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
radare2 preview

radare2

GitHubradareorg/radare2

UNIX-like reverse engineering framework and command-line toolset

ai-assisted-reversingandroid-securitybinary-analysis+16
24.9k3h 52m ago
B2R2 preview

B2R2

GitHubb2r2-org/b2r2

B2R2 is a fully managed binary analysis framework written in F#. It provides a rich set of algorithms, functions, and tools for reverse engineering,…

binary-analysisdynamic-analysis-sandboxingeducation+4
5527h 56m ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.9k14h 4m ago
Relapse-Exploit preview

Relapse-Exploit

GitHubntfargo/relapse-exploit

PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

binary-exploitationeducationexploitation+5
83221h 34m ago
ironcurtain preview

ironcurtain

GitHubprovos/ironcurtain

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

ai-securitycontainer-securitydynamic-analysis-sandboxing+3
61222h 53m ago
AppArmor.d preview

AppArmor.d

GitLabroddhjav/apparmor.d

Comprehensive set of over 1500 AppArmor profiles to confine Linux system processes, desktops, and services, with support for multiple distributions…

configuration-auditingcurated-resourceseducation+1
71 day ago
gosentry preview

gosentry

GitHubtrailofbits/gosentry

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

binary-analysiscode-analysisdevsecops+5
1228 days ago
weakrng-sweep preview

weakrng-sweep

GitHubbrendonlee20042004-sys/weakrng-sweep

Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership

cryptographycurated-resourceseducation+1
1 month ago
SAFE preview

SAFE

GitHubnanda-rani/safe

A contextual security auditing system for research artifacts

ai-securitycode-analysiseducation+2
1 month ago
gef preview

gef

GitHubhugsy/gef

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

ai-assisted-reversingbinary-analysisbinary-exploitation+10
8.4k1 month ago
CVE-2026-22015-Serverless-Function-Environment-Variable-Injection-via-Event preview

CVE-2026-22015-Serverless-Function-Environment-Variable-Injection-via-Event

GitHubgeorge0papasotiriou/cve-2026-22015-serverless-function-environment-variable-injection-via-event

PoC for CVE-2026-22015: malicious event injects environment variables into serverless functions, overwriting secrets and enabling privilege…

cloud-securityeducationexploitation+3
1 month ago
CVE-2025-7384 preview

CVE-2025-7384

GitHubdungsocool/cve-2025-7384

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

educationexploitationlabs-practice+2
2 months ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
12 months ago
crucible preview

crucible

GitHubcrucible-security/crucible

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

ai-securitydevsecopseducation+3
502 months ago
inside-pegasus preview

inside-pegasus

GitHubamnestytech/inside-pegasus

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

android-securitycurated-resourceseducation+6
582 months ago
exim-rce-cve-2018-6789 preview

exim-rce-cve-2018-6789

GitHubmartinclauss/exim-rce-cve-2018-6789

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

binary-exploitationdebuggerseducation+3
112 months ago
So You Want To Build A Nethunter Kernel preview

So You Want To Build A Nethunter Kernel

GitLabakabulous/so_you_want_to_build_a_nethunter_kernel

Step-by-step guide to building custom Kali NetHunter kernels for Android: source retrieval, toolchain selection, cross-compilation, and flashing.

android-securityeducationembedded-systems-security+3
33 months ago
TCASVS preview

TCASVS

GitHubowasp/tcasvs

OWASP Thick Client Application Security Verification Standard

code-analysisconfiguration-auditingcryptography+5
323 months ago
Previous12345Next