Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
43 results
WuppieFuzz preview

WuppieFuzz

GitHubtno-s3/wuppiefuzz

A coverage-guided REST API fuzzer developed on top of LibAFL

api-securityapi-security-testingfuzzing+3
22310 days ago
RMS-Runtime-Mobile-Security preview

RMS-Runtime-Mobile-Security

GitHubm0bilesecurity/rms-runtime-mobile-security

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

android-securitydebuggersdynamic-analysis-sandboxing+7
3.1k2 months ago
recon preview

recon

GitHubknowledge-wisdom-understanding/recon

Enumerate a target Based off of Nmap Results

ctfdns-analysisdns-subdomain-enumeration+9
762 years ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubjsantos1990/cve-2025-5548

🚀 Complete analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server 1.0 - NOOP Buffer Overflow) Full methodology: manual tool installation,…

binary-exploitationeducationexploitation+6
5 months ago
kanha preview

kanha

GitHubpwnwriter/kanha

🦚 A web-app pentesting suite written in rust .

dns-subdomain-enumerationfuzzinginformation-gathering+5
3251 year ago
aether preview

aether

GitHubl33tdawg/aether

AI Smart Contract Security Analysis and PoC Generation Framework

ai-securitybinary-analysiscryptography+7
654 months ago
angryFuzzer preview

angryFuzzer

GitHubihebski/angryfuzzer

Tools for information gathering

fuzzinginformation-gatheringpenetration-testing+2
3632 years ago
ros2_CVE-2024-28231 preview

ros2_CVE-2024-28231

GitHubgrimmmbo/ros2_cve-2024-28231

Demonstrating the usage of Fastrtps-DDS vulnerability CVE-2024-28231 within Ros2

binary-exploitationeducationexploitation+3
9 months ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubjgs-developer/cve-2025-5548

Stack-based buffer overflow exploit for FreeFloat FTP Server, demonstrating reverse engineering, EIP control, and shellcode execution for educational…

binary-exploitationeducationexploitation+5
5 months ago
umap2 preview

umap2

GitHubnccgroup/umap2

Umap2 is the second revision of NCC Group's python based USB host security assessment tool.

dynamic-analysis-sandboxingembedded-systems-securityfuzzing+4
2834 years ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubgodoy-sec/cve-2017-14980

Study of a classic stack-based buffer overflow vulnerability in a controlled lab environment for educational purposes.

binary-exploitationdebuggerseducation+5
126 days ago
sippts preview

sippts

GitHubpepelux/sippts

Set of tools to audit SIP based VoIP Systems

exploitationfuzzinginformation-gathering+6
5712 months ago
bug-bounty-tools preview

bug-bounty-tools

GitHubrxerium/bug-bounty-tools

A BASH Script to automate the installation of the most popular bug bounty tools

dns-subdomain-enumerationfuzzinginformation-gathering+7
278 months ago
gustave preview

gustave

GitHubairbus-seclab/gustave

GUSTAVE is a fuzzing platform for embedded OS kernels. It is based on QEMU and AFL (and all of its forkserver siblings). It allows to fuzz OS kernels…

binary-analysisembedded-systems-securityfuzzing
2045 years ago
t-reqs preview

t-reqs

GitHubbahruzjabiyev/t-reqs

Grammar-based HTTP/1 fuzzer with mutation ability

fuzzingpapers-researchvulnerability-analysis+1
2631 year ago
fpicker preview

fpicker

GitHubttdennis/fpicker

Frida-based in-process fuzzing suite with AFL++ proxy, standalone active/passive modes, and shared memory communication for high-performance…

binary-analysisdynamic-analysis-sandboxingexploitation+2
2981 year ago
echteeteepee preview

echteeteepee

GitHubperplext/echteeteepee

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

dynamic-analysis-sandboxingeducationfuzzing+3
61 year ago
CVE-2025-54574-Squid-Heap-Buffer-Overflow preview

CVE-2025-54574-Squid-Heap-Buffer-Overflow

GitHubstarrynightsecurity/cve-2025-54574-squid-heap-buffer-overflow

Vulnerability Found on Squid Proxy.

binary-analysisexploitationfuzzing+3
7 months ago
Previous123Next