Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
969 results
rcekit preview

rcekit

GitHubkabiri-labs/rcekit

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

command-and-controlexploitationfuzzing+8
14
22h 27m ago
cve-2021-44790-lab preview

cve-2021-44790-lab

GitHubmohammadalimehri/cve-2021-44790-lab

Dockerized Apache mod_lua lab with a Python PoC reproducing the CVE-2021-44790 multipart boundary buffer overflow for local defensive testing and…

educationexploitationfuzzing+5
3 days ago
CVE-2026-28609-matroska-pcm-oob preview

CVE-2026-28609-matroska-pcm-oob

GitHubdevrodt2/cve-2026-28609-matroska-pcm-oob

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

android-securitybinary-exploitationexploitation+5
2 days ago
discord-crasher preview

discord-crasher

GitHubaftermathlabs/discord-crasher

Some bugs found via binary instrumentation and fuzzing

binary-analysisdynamic-analysis-sandboxingexploitation+5
217 days ago
red-teaming-auto-mode preview

red-teaming-auto-mode

GitHubsafety-research/red-teaming-auto-mode

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

ai-securityeducationfuzzing+3
15 days ago
Veridiff preview

Veridiff

GitHubveridiff/veridiff

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

binary-analysisbinary-exploitationcode-analysis+7
15 days ago
CVE-2026-85048-the-gpu-died preview

CVE-2026-85048-the-gpu-died

GitHubsneakynachos/cve-2026-85048-the-gpu-died

Reproducer and technical analysis for CVE-2026-85048, a Chrome viz surface use-after-free in the GPU process, with ASAN unit tests and browser…

binary-exploitationdebuggersexploitation+4
15 days ago
OmniSec-Hex preview

OmniSec-Hex

GitHubvighnesh91/omnisec-hex

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

ai-securitybinary-analysisfuzzing+9
12 days ago
Aresius preview

Aresius

GitHub0xmarik/aresius

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

api-security-testingfuzzinginformation-gathering+6
29 days ago
upb-any-recursion-audit preview

upb-any-recursion-audit

GitHubvardhan0257/upb-any-recursion-audit

Audit harness testing whether the CVE-2026-0994 Any-unwrapping recursion bug class affects upb's C core in Ruby and PHP protobuf bindings, with…

binary-analysiseducationfuzzing+4
5 days ago
FLAWED preview

FLAWED

GitHuboff-by-1-labs/flawed

Fix-Like Artifacts With Embedded Defects

ai-securitycode-analysisdefensive-tools+8
241 month ago
cve-2026-52910-poc preview

cve-2026-52910-poc

GitHubyolkfull/cve-2026-52910-poc

Race reproducer and stress toolkit for CVE-2026-52910, a Linux kernel use-after-free in reuseport cBPF selector programs, with dmesg and leak checks.

binary-exploitationdefensive-toolsexploitation+3
18 days ago
CVE-2025-5548-FreeFloat-FTP-Lab preview

CVE-2025-5548-FreeFloat-FTP-Lab

GitHubm4rc0s-s3c/cve-2025-5548-freefloat-ftp-lab

Laboratorio académico de análisis y explotación de CVE-2025-5548 en FreeFloat FTP Server 1.0.

binary-exploitationctfdebuggers+6
7 days ago
CVE-2026-90782-s2opc-status-clobber preview

CVE-2026-90782-s2opc-status-clobber

GitHubharshrajsinghania/cve-2026-90782-s2opc-status-clobber

Standalone PoC for CVE-2026-90782: status-clobbering NULL dereference in S2OPC alloc_notification_message_items() (DataChange fails, Event succeeds)

binary-analysisexploitationfuzzing+2
9 days ago
CVE-2026-90781-alsa-lib-oob preview

CVE-2026-90781-alsa-lib-oob

GitHubharshrajsinghania/cve-2026-90781-alsa-lib-oob

Standalone reproducer for CVE-2026-90781: 1-byte OOB write in alsa-lib __snd_ctl_ascii_elem_id_parse() name= parsing (quoted and unquoted)

educationexploitationfuzzing+4
9 days ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
1004 days ago
cve-2026-86547-mrubyc-op-enter preview

cve-2026-86547-mrubyc-op-enter

GitHubharshrajsinghania/cve-2026-86547-mrubyc-op-enter

Standalone proof of concept for CVE-2026-86547, a NULL pointer dereference in mrubyc op_enter() through 4.0.0.

embedded-systems-securityexploitationfuzzing+3
11 days ago
silica preview

silica

GitHubnathan-luevano/silica

Exhaustive differential validation of all 4.3B AArch64 instruction encodings.

binary-analysisdynamic-analysis-sandboxingfuzzing+5
411 days ago
Previous12…54Next