Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
FACT_core preview

FACT_core

GitHubfkie-cad/fact_core

Automated firmware analysis platform that unpacks, analyzes, and compares embedded device firmware to identify components, vulnerabilities, and…

binary-analysisdynamic-analysis-sandboxingembedded-systems-security+9
1.5k20 days ago
Extracting-User-credentials-For-Web-portal-and-WiFi-AP-For-Hathway-Router-CVE-2024-44815- preview

Extracting-User-credentials-For-Web-portal-and-WiFi-AP-For-Hathway-Router-CVE-2024-44815-

GitHubnitinronge91/extracting-user-credentials-for-web-portal-and-wifi-ap-for-hathway-router-cve-2024-44815-

Proof-of-concept exploit for CVE-2024-44815 demonstrating extraction of plaintext router credentials from SPI flash via hardware teardown, UART…

embedded-systems-securityexploitationfirmware-analysis+5
1 year ago
owasp-istg preview

owasp-istg

GitHubowasp/owasp-istg

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

curated-resourceseducationembedded-systems-security+9
12822 days ago
CVE-2025-65855 preview

CVE-2025-65855

GitHubluismirandaacebedo/cve-2025-65855

Security advisory detailing multiple vulnerabilities in HelpFlash IoT OTA firmware update mechanism, including hard-coded WiFi credentials,…

embedded-systems-securityexploitationfirmware-analysis+3
8 months ago
TagTinker preview

TagTinker

GitHubi12bp8/tagtinker

Flipper Zero app for infrared electronic shelf-label (ESL) protocol research, featuring custom image transmission, NFC tag scanning, and a web-based…

educationembedded-systems-securityfirmware-analysis+5
1.7k3 months ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
91910 months ago
shim-review preview

shim-review

GitHubrhboot/shim-review

Review process for signing UEFI shim bootloaders, providing a structured template for submitting binaries, build logs, and security patch…

code-analysiscurated-resourceseducation+3
8928 days ago
IoTGoat preview

IoTGoat

GitHubscriptingxss/iotgoat

Deliberately insecure OpenWrt firmware with OWASP IoT Top 10 vulnerability challenges for hands-on IoT security testing, firmware analysis, and…

educationfirmware-analysishardware-iot-security+4
1836 years ago
bd-alaris-firmware-analysis preview

bd-alaris-firmware-analysis

GitHubnadafarafat/bd-alaris-firmware-analysis

Firmware security analysis of BD Alaris 8015 infusion pump: extracts plaintext Wi-Fi credentials, identifies 6 compound vulnerabilities (HTTP…

cryptographyeducationembedded-systems-security+5
2 months ago
trommel preview
Archived

trommel

GitHubcertcc/trommel

Static analysis tool that sifts through embedded device firmware to identify vulnerable indicators including SSH/SSL keys, IPs, URLs, shell scripts,…

embedded-systems-securityfirmware-analysishardware-security+6
2136 years ago
wolfssl preview

wolfssl

GitHubwolfssl/wolfssl

Lightweight TLS 1.3/DTLS 1.3 library with FIPS 140-3 validated cryptography, hardware entropy support, and post-quantum cipher suites for embedded,…

cloud-securitycryptographyembedded-systems-security+6
2.9k3 days ago
CVE-2024-48705 preview

CVE-2024-48705

GitHubl41kaa/cve-2024-48705

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

binary-analysiscommand-and-controlembedded-systems-security+7
21 year ago
LIEF preview

LIEF

GitHublief-project/lief

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

ai-assisted-reversingandroid-securitybinary-analysis+12
5.5k3 days ago
ESP32-Bit-Pirate preview

ESP32-Bit-Pirate

GitHubgeo-tp/esp32-bit-pirate

A Hardware Hacking Tool with Web-Based CLI That Speaks Every Protocol

bluetooth-securitydebuggersembedded-systems-security+5
5.6k9 days ago
arduino-pico preview

arduino-pico

GitHubearlephilhower/arduino-pico

Raspberry Pi Pico Arduino core, for all RP2040 and RP2350 boards

bluetooth-securityeducationembedded-systems-security+5
2.9k1 day ago
nexmon preview

nexmon

GitHubseemoo-lab/nexmon

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

embedded-systems-securityfirmware-analysishardware-hacking+6
2.9k1 month ago
efiXplorer preview

efiXplorer

GitHubrehints/efixplorer

IDA plugin and loader for UEFI firmware analysis and reverse engineering automation

binary-analysisembedded-systems-securityfirmware-analysis+5
1.1k5 days ago
firmwalker preview

firmwalker

GitHubcraigz28/firmwalker

Script for searching the extracted firmware file system for goodies!

firmware-analysishardware-securityinformation-gathering+2
1.2k5 years ago
Previous1234Next