Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
143 results
cve-2015-1187-dir820l-firmware-reverse-engineering preview

cve-2015-1187-dir820l-firmware-reverse-engineering

GitHubchristopher-leese/cve-2015-1187-dir820l-firmware-reverse-engineering

Static firmware reverse engineering of CVE-2015-1187: unauthenticated command injection in D-Link DIR-820L. MIPS root filesystem extraction with…

embedded-systems-securityexploitationfirmware-analysis+5
1 month ago
CVE-2022-20607 preview

CVE-2022-20607

GitHubsumeetit/cve-2022-20607

In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with…

android-securityembedded-systems-securityexploitation+3
3 years ago
CVE-2026-76071 preview

CVE-2026-76071

GitHubozcanpng/cve-2026-76071

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

binary-analysisexploitationfirmware-analysis+3
124 days ago
the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt preview

the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

GitHubhunt-benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

authenticationcryptographyexploitation+4
1 month ago
BootHole preview

BootHole

GitHubeclypsium/boothole

Detection scripts and mitigation resources for the BootHole vulnerability (CVE-2020-10713), including PowerShell and Bash tools to audit EFI System…

configuration-auditingcurated-resourceseducation+3
696 years ago
emuko preview

emuko

GitHubwkoszek/emuko

RISC-V emulator in Rust that boots Linux with JIT on ARM64/x86_64 and Sv39 virtual memory

debuggerseducationembedded-systems-security+5
1036 months ago
IoT-Pentest-devices-and-purpose preview

IoT-Pentest-devices-and-purpose

GitHubiotsrg/iot-pentest-devices-and-purpose

Curated guide to IoT penetration testing hardware and software tools for 2025, covering Bluetooth, Zigbee, Z-Wave, WiFi, RFID, automotive, and…

bluetooth-securitycurated-resourceseducation+8
731 year ago
CVE-2022-22063 preview

CVE-2022-22063

GitHubmsm8916-mainline/cve-2022-22063

Security issue in the hypervisor firmware of some older Qualcomm chipsets

binary-exploitationeducationembedded-systems-security+6
463 years ago
cve-2021-21735-zte-zxhn-h168n-admin-compromise preview

cve-2021-21735-zte-zxhn-h168n-admin-compromise

GitHubminanagehsalalma/cve-2021-21735-zte-zxhn-h168n-admin-compromise

CVE-2021-21735 write-up: ZTE ZXHN H168N V3.5 wizard-page information leak, firmware routing flaw, and the path from exposed PPPoE/WLAN data to full…

embedded-systems-securityexploitationfirmware-analysis+3
44 months ago
CVE-2026-21009-ECDSA-Nonce-Reuse-in-IoT-Firmware-Signing preview

CVE-2026-21009-ECDSA-Nonce-Reuse-in-IoT-Firmware-Signing

GitHubgeorge0papasotiriou/cve-2026-21009-ecdsa-nonce-reuse-in-iot-firmware-signing

Educational Python simulation demonstrating ECDSA nonce reuse in IoT firmware signing, showing how an attacker can recover private keys from two…

cryptographyeducationexploitation+3
2 months ago
CVE-2025-65855 preview

CVE-2025-65855

GitHubluismirandaacebedo/cve-2025-65855

Security advisory for CVE-2025-65855 - Multiple vulnerabilities in HelpFlash IoT OTA update mechanism

embedded-systems-securityexploitationfirmware-analysis+3
9 months ago
CVE-2020-12124 preview

CVE-2020-12124

GitHubscorpion-security-labs/cve-2020-12124

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

binary-analysiscommand-and-controleducation+8
7 months ago
rp2350_hacking_challenge preview

rp2350_hacking_challenge

GitHubraspberrypi/rp2350_hacking_challenge

Raspberry Pi RP2350 hacking challenge: extract a 128-bit OTP secret protected by secure boot and OTP lock, with setup scripts and firmware for Pico 2…

cryptographyctfeducation+5
2051 year ago
ShadeBIOS preview

ShadeBIOS

GitHubffri/shadebios

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

binary-analysiseducationembedded-systems-security+5
681 year ago
sonos preview

sonos

GitHubblasty/sonos

Exploit and tooling for Amlogic-based Sonos devices: dumps OTP/eFUSE via an EL3 exploit, extracts LUKS decryption keys, and fetches/decrypts OTA…

embedded-systems-securityencryption-decryption-toolsexploitation+5
643 years ago
mousejack preview

mousejack

GitHubbastilleresearch/mousejack

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

exploitationfirmware-analysishardware-iot-security+3
1.4k8 years ago
Firmware_Slap preview

Firmware_Slap

GitHubchristhecoolhut/firmware_slap

Discovering vulnerabilities in firmware through concolic analysis and function clustering.

binary-analysisexploitationfirmware-analysis+1
4766 years ago
fnprint preview

fnprint

GitHub1rhino2/fnprint

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

binary-analysisdynamic-code-analysisfirmware-analysis+3
5418 days ago
Previous1…345…8Next