Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
367 results
HPE-Aruba-AOS8-Vulnerabilities preview

HPE-Aruba-AOS8-Vulnerabilities

GitHubjm00nj/hpe-aruba-aos8-vulnerabilities

ArubaOS 8.13.2.0 pre-auth attack surface research. XXE+SSRF, ICMP reflection, buffer over-read, hardcoded credentials — all submitted to HPE…

binary-analysisexploitationfirmware-analysis+3
3
2 months ago
grandstream-cve-2026-2329-analysis preview

grandstream-cve-2026-2329-analysis

GitHubvivianuba/grandstream-cve-2026-2329-analysis

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…

binary-analysiseducationfirmware-analysis+4
6 days ago
CVE-2026-76070 preview

CVE-2026-76070

GitHubozcanpng/cve-2026-76070

Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi

binary-exploitationembedded-systems-securityexploitation+4
16 days ago
CVE-2026-76071 preview

CVE-2026-76071

GitHubozcanpng/cve-2026-76071

Original research and non-destructive PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

binary-analysisexploitationfirmware-analysis+3
16 days ago
Bus_Pirate preview

Bus_Pirate

GitHubelderlypirate/bus_pirate

Multi-protocol firmware for a hardware hacking tool supporting SPI, I2C, JTAG, UART, 1-Wire, bus sniffing, logic analysis, and microcontroller…

debuggersembedded-systems-securityfirmware-analysis+5
6918 months ago
chipwhisperer preview

chipwhisperer

GitHubnewaetech/chipwhisperer

Open-source hardware security toolchain for power trace capture, side-channel analysis, and glitching/fault-injection attacks on embedded devices and…

cryptographyembedded-systems-securityfirmware-analysis+5
1.6k4 days ago
ipsw preview

ipsw

GitHubblacktop/ipsw

iOS/macOS Research Swiss Army Knife

ai-assisted-reversingbinary-analysisdebuggers+9
3.7k3 days ago
libsigrok preview

libsigrok

GitHubsigrokproject/libsigrok

C library providing a portable API for acquiring signals from logic analyzers, oscilloscopes, multimeters, and other test instruments, with…

embedded-systems-securityfirmware-analysisgeneral-purpose-utilities+4
4339 months ago
bluffs preview

bluffs

GitHubfrancozappa/bluffs

Toolkit for testing Bluetooth session establishment against forward and future secrecy attacks, using firmware patching, PCAP analysis, and automated…

bluetooth-securityexploitationfirmware-analysis+4
5232 years ago
the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt preview

the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

GitHubhunt-benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

authenticationcryptographyexploitation+4
5 days ago
fnprint preview

fnprint

GitHub1rhino2/fnprint

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

binary-analysisdynamic-code-analysisfirmware-analysis+3
206 days ago
lg-webos-kexec preview

lg-webos-kexec

GitHubggfuchsi-oss/lg-webos-kexec

Boots a custom Linux kernel on rooted LG webOS TVs via kexec, with reverse-engineered SoC watchdog support, framebuffer payloads, and an initramfs…

embedded-systems-securityfirmware-analysishardware-hacking+2
67 days ago
SpringPeace preview

SpringPeace

GitHubvirtualesp/springpeace

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

android-securitybinary-analysisexploitation+4
1 month ago
spd_dump-macos preview

spd_dump-macos

GitHubxun404/spd_dump-macos

UNISOC BootROM/FDL flasher for macOS: patched spd_dump with CVE-2022-38694 exec_addr2, protocol reference, partition rules, backup verification…

android-securityembedded-systems-securityexploitation+3
8 days ago
CVE-2026-6837-zyxel-export-cgi-command-injection preview

CVE-2026-6837-zyxel-export-cgi-command-injection

GitHubminanagehsalalma/cve-2026-6837-zyxel-export-cgi-command-injection

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

embedded-systems-securityexploitationfirmware-analysis+3
39 days ago
CVE-2026-43499-ZFOLD4 preview

CVE-2026-43499-ZFOLD4

GitHubfusiondrive/cve-2026-43499-zfold4

CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)

android-securitybinary-exploitationexploitation+4
11 days ago
cve-2020-9373-netgear-r6400 preview

cve-2020-9373-netgear-r6400

GitHublimingxi6/cve-2020-9373-netgear-r6400

解决网络安全漏洞

binary-analysisbinary-exploitationembedded-systems-security+6
12 days ago
CVE-2026-73673 preview

CVE-2026-73673

GitHubozcanpng/cve-2026-73673

Non-destructive PoC and technical write-up for CVE-2026-73673, an unauthenticated firmware-update flaw in Netis NC63 router, with reproduction and…

authentication-authorizationembedded-systems-securityexploitation+3
212 days ago
Previous12…21Next