Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
Forbidden-Buster preview

Forbidden-Buster

GitHubsn1r/forbidden-buster

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

fuzzingids-ips-evasionpenetration-testing+2
252
1 year ago
yakit preview

yakit

GitHubyaklang/yakit

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

command-and-controlexploit-frameworksfuzzing+9
7.7k4 days ago
aixcc-afc-atlantis preview

aixcc-afc-atlantis

GitHubteam-atlanta/aixcc-afc-atlantis

Automated cyber reasoning system that discovers and analyzes software vulnerabilities through fuzzing, binary analysis, and program reasoning for…

binary-analysisfuzzingvulnerability-analysis
6409 months ago
RESim preview

RESim

GitHubmfthomps/resim

Reverse engineering software using a full system simulator

binary-analysisdebuggersdynamic-analysis-sandboxing+3
19418 days ago
VMPacker preview

VMPacker

GitHubleochen-coremind/vmpacker

ARM64 ELF Virtual Machine Protection System

anti-botbinary-analysisembedded-systems-security+8
4865 months ago
TriforceLinuxSyscallFuzzer preview

TriforceLinuxSyscallFuzzer

GitHubnccgroup/triforcelinuxsyscallfuzzer

Linux x86_64 kernel system call fuzzer using AFL and QEMU to find crashes and vulnerabilities via dynamic analysis and instrumentation.

dynamic-analysis-sandboxingfuzzingvulnerability-analysis
1792 years ago
gustave preview

gustave

GitHubairbus-seclab/gustave

QEMU/AFL-based fuzzing platform for embedded OS kernels with binary instrumentation, system call translation, and memory access monitoring to detect…

binary-analysisembedded-systems-securityfuzzing
2035 years ago
fisy-fuzz preview

fisy-fuzz

GitHub0xricksanchez/fisy-fuzz

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.

exploitationfuzzingvulnerability-analysis
1503 years ago
DraculaOS preview

DraculaOS

GitHubemrekybs/draculaos

Dracula OS is a Linux operating system meticulously designed for OSINT (Open Source Intelligence) and Cyber ​​Intelligence missions.

curated-resourceseducationemail-harvesting+9
949 months ago
TriforceOpenBSDFuzzer preview

TriforceOpenBSDFuzzer

GitHubnccgroup/triforceopenbsdfuzzer

System call fuzzing of OpenBSD amd64 using TriforceAFL (i.e. AFL and QEMU)

dynamic-analysis-sandboxingfuzzingvulnerability-analysis
478 years ago
CVE-2023-20052 preview

CVE-2023-20052

GitHubnokn0wthing/cve-2023-20052

Proof-of-concept exploit for CVE-2023-20052, an information leak vulnerability in ClamAV's DMG file parser. Generates a malicious DMG file to trigger…

exploitationfuzzinginformation-gathering+2
283 years ago
CVE-2019-12594 preview

CVE-2019-12594

GitHubalexandre-bartel/cve-2019-12594

Proof-of-concept exploit for CVE-2019-12594, a vulnerability in DOSBox 0.74-2 that allows arbitrary code execution on the host system.

binary-exploitationembedded-systems-securityexploitation+2
137 years ago
OmniScan preview

OmniScan

GitHubd3ckx1/omniscan

Multi-engine vulnerability scanner with built-in Nuclei Lite, Afrog, and XRay engines. Features asset discovery via FOFA/Shodan, OOB interaction…

dynamic-analysis-sandboxingexploit-frameworksfuzzing+6
97 months ago
cve-2026-24688 preview

cve-2026-24688

GitHubfomovet/cve-2026-24688

Proof-of-concept exploit for CVE-2026-24688, a critical DoS vulnerability in pypdf's circular outline parsing causing infinite memory allocation and…

code-analysiseducationexploitation+2
2 months ago
CVE-2026-31024 preview

CVE-2026-31024

GitHuberikdervishi03/cve-2026-31024

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

binary-exploitationeducationexploitation+5
23 months ago
SCADAShutdownTool preview

SCADAShutdownTool

GitHubpentdebra/scadashutdowntool

Industrial control system security testing tool that enumerates and rewrites SCADA controller registers (coils, inputs, holding registers) in safe,…

fuzzingpenetration-testingscada-ics-security+1
10 years ago
CVE-2023-38545 preview

CVE-2023-38545

GitHubyang-shun-yu/cve-2023-38545

Proof-of-concept exploit for CVE-2023-38545, a curl heap buffer overflow. Includes SOCKS5 proxy and HTTP server to trigger the vulnerability and…

exploitationfuzzingnetwork-security+3
2 years ago
expat_CVE-2024-28757 preview

expat_CVE-2024-28757

GitHubrenukaselvar/expat_cve-2024-28757

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

code-analysisdynamic-analysis-sandboxingexploitation+3
2 years ago
Previous123Next