Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
251 results
byd-dolphin-hacking preview

byd-dolphin-hacking

GitHubwheregoes/byd-dolphin-hacking

Reverse engineering the BYD Dolphin head unit — CAN bus, AVAS, NFC keys, OTA, and more. DiLink 3 / Android 10.

android-securitybinary-analysisembedded-systems-security+7
59
2 days ago
disclosure-thinkware-u3000 preview

disclosure-thinkware-u3000

GitHubturretsec/disclosure-thinkware-u3000

Three unauthenticated vulnerabilities in the Thinkware U3000 dashcam's local WiFi control protocol: arbitrary file write, arbitrary file read, and…

cryptographyembedded-systems-securityhardware-iot-security+5
6 days ago
u3000py preview

u3000py

GitHubturretsec/u3000py

Python client for the Thinkware U3000 dashcam's local WiFi control protocol, reverse-engineered from the official Android app. PoC tooling behind…

embedded-systems-securityexploitationhardware-iot-security+7
6 days ago
CVE-2026-100740 preview

CVE-2026-100740

GitHubmurrez/cve-2026-100740

Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and…

embedded-systems-securityexploitationfirmware-analysis+6
18 days ago
ps5-pihost preview

ps5-pihost

GitHubflex36ty/ps5-pihost

PS5 Exploit Web Server on a Raspberry Pi Powered by the PS5's USB Port

dns-analysisembedded-systems-securityexploitation+7
2 days ago
CVE-2026-13249 preview

CVE-2026-13249

GitHubmurrez/cve-2026-13249

Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit…

embedded-systems-securityexploitationhardware-iot-security+6
9 days ago
attezt preview

attezt

GitHubfoxboron/attezt

An open-source TPM device-attest-01 CA server

authenticationcryptographydefensive-tools+6
586 months ago
reyee_decrypt preview

reyee_decrypt

GitHubejfkdev/reyee_decrypt

Decrypt Ruijie ReyeeOS firmware (v1/v2) and encrypted config backups; recover plaintext passwords

cryptographyembedded-systems-securityencryption-decryption-tools+7
1 month ago
moria preview

moria

GitHubnmatt0/moria

IoT firmware identification and extraction

binary-analysisdigital-forensicsembedded-systems-security+7
3881 day ago
badbox-h713-projector preview

badbox-h713-projector

GitHubflorentineprinzessinzusachsen/badbox-h713-projector

Analysis and cleanup guide for BadBox malware on Allwinner H713 Android projectors: ADB access, infection proof, firmware backup, dropper removal,…

android-securitydigital-forensicsembedded-systems-security+8
38 days ago
CVE-2026-67279 preview

CVE-2026-67279

GitHubhackspeak/cve-2026-67279

Python proof-of-concept scripts for the MikroTrick MikroTik RouterOS SSH takeover chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) for…

authenticationembedded-systems-securityexploitation+7
49 days ago
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
498 days ago
CVE-2026-mikrotik-poc preview

CVE-2026-mikrotik-poc

GitHubgagaltotal/cve-2026-mikrotik-poc

CVE-2026-86060 - CVE-2026-67279 - CVE-2026-67276 RouterOS SSH

authenticationeducationembedded-systems-security+5
28 days ago
flipper-mcp preview

flipper-mcp

GitHubroostercoopllc/flipper-mcp

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.

ai-securitybluetooth-securitycommand-and-control+9
277 months ago
netis-cve-2026-36539 preview

netis-cve-2026-36539

GitHubkhaleedbt/netis-cve-2026-36539

Python script that checks Netis routers for CVE-2026-36539, detecting vulnerable devices on a network.

embedded-systems-securityhardware-iot-securityiot-security+4
10 days ago
Dji_ble_vuln preview

Dji_ble_vuln

GitHubfeedbeef/dji_ble_vuln

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

bluetooth-securitycommand-and-controlembedded-systems-security+6
11 days ago
MicroTrick preview

MicroTrick

GitHubdigiprosec/microtrick

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

authenticationembedded-systems-securityexploitation+7
5211 days ago
CVE-2024-29269 preview

CVE-2024-29269

GitHubdkstar11q/cve-2024-29269

Exploit for CVE-2024-29269 enabling unauthenticated OS command execution on TLR-2005KSH routers, with ZoomEye and Leakix dork queries for target…

embedded-systems-securityexploitationinformation-gathering+5
2 years ago
Previous12…14Next