Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
70 results
dexcalibur preview

dexcalibur

GitHubreversenseorg/dexcalibur

[Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it…

android-securitybinary-analysisdebuggers+5
1.2k
13h 48m ago
Penetration_Testing_POC preview

Penetration_Testing_POC

GitHubmr-xn/penetration_testing_poc

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

curated-resourceseducationexploitation+6
7.5k3 days ago
lamda preview

lamda

GitHubfirerpa/lamda

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

android-securitydynamic-analysis-sandboxingeducation+8
8.3k3 days ago
CVE-2026-27280 preview

CVE-2026-27280

GitHubr3n3r0/cve-2026-27280

In-depth analysis and proof-of-concept for CVE-2026-27280, an out-of-bounds write in Adobe DNG SDK's dng_render_task::ProcessArea, reachable via…

android-securitybinary-exploitationexploitation+5
15 days ago
pbtk preview

pbtk

GitHubmarin-m/pbtk

A toolset for reverse engineering and fuzzing Protobuf-based apps

android-securitybinary-analysisdynamic-analysis-sandboxing+5
1.7k7 days ago
cve-2021-21994_POC preview

cve-2021-21994_POC

GitHubmreza-en/cve-2021-21994_poc

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

authenticationexploitationfuzzing+3
18 days ago
medusa preview

medusa

GitHubch0pin/medusa

Mobile Edge-Dynamic Unified Security Analysis

android-securitydynamic-analysis-sandboxingexploitation+8
2.3k21 days ago
WAFNinja preview

WAFNinja

GitHubkhalilbijjou/wafninja

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

fuzzingpenetration-testingwaf-bypass+1
83321 days ago
cve-2026-69243-poc-aiohttp-smuggling preview

cve-2026-69243-poc-aiohttp-smuggling

GitHubjvbotelho/cve-2026-69243-poc-aiohttp-smuggling

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…

exploitationfuzzingpayload-generation+3
128 days ago
cargo-fuzz preview

cargo-fuzz

GitHubrust-fuzz/cargo-fuzz

Cargo subcommand for coverage-guided Rust fuzzing with libFuzzer: create and run fuzz targets, minimize failures and corpora, and report coverage.

dynamic-code-analysisfuzzingvulnerability-analysis
1.9k1 month ago
PulseAPK-Core preview

PulseAPK-Core

GitHubdeemoun/pulseapk-core

PulseAPK Core: Cross-Platform tool for working with APK files: Decompilation, Analysis, Building

android-securitybinary-analysisdynamic-analysis-sandboxing+8
1172 months ago
RMS-Runtime-Mobile-Security preview

RMS-Runtime-Mobile-Security

GitHubm0bilesecurity/rms-runtime-mobile-security

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

android-securitydebuggersdynamic-analysis-sandboxing+7
3.1k2 months ago
honggfuzz preview

honggfuzz

GitHubgoogle/honggfuzz

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

dns-fuzzingdynamic-code-analysisfuzzing+1
3.4k2 months ago
apatchy preview

apatchy

GitHub0xbigshaq/apatchy

Fuzzing Framework for Modules in Apache HTTPD Server

code-analysisdynamic-code-analysisfuzzing+2
222 months ago
polytracker preview

polytracker

GitHubtrailofbits/polytracker

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

binary-analysisdynamic-code-analysiseducation+4
5982 months ago
Popcorn-TJNULL-OSCP- preview

Popcorn-TJNULL-OSCP-

GitHubr3fr4kt/popcorn-tjnull-oscp-

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

ctfeducationexploitation+7
2 months ago
exr-imageio-poc preview

exr-imageio-poc

GitHubbilly-ellis/exr-imageio-poc

PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5

binary-exploitationexploitationfuzzing+3
463 months ago
mdk4 preview

mdk4

GitHubaircrack-ng/mdk4

IEEE 802.11 Wi-Fi testing tool for protocol weakness exploitation, including beacon flooding, deauthentication, packet fuzzing, and IDS evasion.…

exploitationfuzzingids-ips-evasion+5
8033 months ago
Previous1234Next