Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
Neton preview

Neton

GitHubaetsu/neton

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

educationinformation-gatheringmalware-analysis+1
99
3 years ago
CAPEv2 preview

CAPEv2

GitHubkevoreilly/capev2

Malware Configuration And Payload Extraction

debuggersdynamic-analysis-sandboxingeducation+6
3.6k16h 47m ago
CVE-2025-10230 preview

CVE-2025-10230

GitHubnehkark/cve-2025-10230

CVE-2025-10230 PoC - Samba WINS Hook Command Injection

command-and-controleducationexploitation+3
110 months ago
CVE-2026-3227-TP-Link-authenticated-RCE preview

CVE-2026-3227-TP-Link-authenticated-RCE

GitHubdo4choo/cve-2026-3227-tp-link-authenticated-rce

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

binary-exploitationeducationexploitation+6
433 months ago
renef-skills preview

renef-skills

GitHubvichhka-git/renef-skills

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

android-securitybinary-analysisctf+9
153 months ago
vibegate preview

vibegate

GitHubthemiddleblue/vibegate

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

ai-securitycode-analysisdevsecops+5
83 months ago
CVE-2026-45321-Tanstack preview

CVE-2026-45321-Tanstack

GitHubrenewablehacking/cve-2026-45321-tanstack

Educational lab simulating npm supply chain attacks, CI/CD abuse, and install-time code execution via CVE-2026-45321. Hands-on defensive security…

educationlabs-practicemalware-analysis+2
4 months ago
cve-2026-29204-whmcs-clientarea-addonid preview

cve-2026-29204-whmcs-clientarea-addonid

GitHubbogdanrotariu/cve-2026-29204-whmcs-clientarea-addonid

Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with…

authentication-authorizationcurated-resourceseducation+3
4 months ago
HyperDbg preview

HyperDbg

GitHubhyperdbg/hyperdbg

State-of-the-art native debugging tools

binary-analysisdebuggerseducation+4
4.1k16 days ago
CVE-2025-48384-submodule preview

CVE-2025-48384-submodule

GitHubvignesh21-git/cve-2025-48384-submodule

Test

educationexploitationmalware-analysis+2
9 months ago
hook preview

hook

GitHubamalmurali47/hook

Hook for the PoC for exploiting CVE-2024-32002

educationexploitationpayload-development+2
182 years ago
hook preview

hook

GitHubeqstlab/hook

submodule for git_rce

educationexploitationpenetration-testing+2
2 years ago
one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow preview

one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow

GitHubhunt-benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

android-securitydynamic-code-analysiseducation+3
2 months ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
2 months ago
CVE-2026-54088-poc preview

CVE-2026-54088-poc

GitHubsaku0512/cve-2026-54088-poc

Proof-of-concept exploit for CVE-2026-54088, a pre-authentication OS command injection in File Browser <=2.63.5. Demonstrates shell injection via…

command-and-controleducationexploitation+4
13 months ago
CVE-2026-54686-poc preview

CVE-2026-54686-poc

GitHubsaku0512/cve-2026-54686-poc

Local PoC for CVE-2026-54686 demonstrating DCS lifecycle hook spoofing in Warp terminal. Simulates spoofed CWD and SSH metadata acceptance in…

ctfeducationexploitation+3
3 months ago
Gitea-Git-Hooks-RCE-CVE-2020-14144- preview

Gitea-Git-Hooks-RCE-CVE-2020-14144-

GitHubmohnad-al-saif/gitea-git-hooks-rce-cve-2020-14144-

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

educationexploitationpayload-development+3
7 months ago
cve-2025-48384-poc preview

cve-2025-48384-poc

GitHubnguyentranbaotran/cve-2025-48384-poc

Proof-of-concept demonstrating Git CR-path submodule misparsing vulnerability leading to arbitrary hook execution during recursive clone operations.

binary-exploitationeducationexploitation+2
1 year ago
Previous12Next