Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
allsafe-android preview

allsafe-android

GitHubt0thkr1s/allsafe-android

Intentionally vulnerable Android application.

android-securitydynamic-analysis-sandboxingeducation+7
415
11 months ago
Awesome-Fuzzing preview

Awesome-Fuzzing

GitHubsecfigo/awesome-fuzzing

A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for…

binary-analysiscurated-resourceseducation+6
5.9k3 years ago
Damn_Vulnerable_C_Program preview

Damn_Vulnerable_C_Program

GitHubhardik05/damn_vulnerable_c_program

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

educationfuzzinglabs-practice+1
7271 year ago
regexploit preview

regexploit

GitHubdoyensec/regexploit

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

fuzzingstatic-code-analysisvulnerability-analysis
8482 years ago
optee-qemu preview

optee-qemu

GitHubpjlantz/optee-qemu

Environment with vulnerable kernel for exploitation of the TEE driver (CVE-2021-44733)

binary-exploitationeducationembedded-systems-security+4
764 years ago
navgix preview

navgix

GitHubhakaioffsec/navgix

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

fuzzingmisconfigurationvulnerability-scanners+1
753 years ago
CVE-2024-38473-Nuclei-Template preview

CVE-2024-38473-Nuclei-Template

GitHubjuanschallibaum/cve-2024-38473-nuclei-template

Nuclei template to detect Apache servers vulnerable to CVE-2024-38473

exploitationfuzzingmisconfiguration+3
302 years ago
pyrmax preview

pyrmax

GitHubinfobyte/pyrmax

Decoder/encoder for Ubiquiti AirMAX wireless protocol frames; parse pcap/live captures, discover devices, scan for vulnerable firmware, craft…

fuzzingnetwork-securityreverse-engineering+2
622 days ago
POC_CVE-2024-36420 preview

POC_CVE-2024-36420

GitHubfineman999/poc_cve-2024-36420

Local reproduction lab and Nuclei template for CVE-2024-36420, an arbitrary file read vulnerability in Flowise via unsanitized fileName parameter.…

educationexploitationfuzzing+3
3 months ago
xpdf-docker preview

xpdf-docker

GitHubrishvic/xpdf-docker

Docker images of Xpdf 4.04, vulnerable to CVE-2022-30524

binary-analysiscontainer-securityeducation+3
13 years ago
CVE-2025-5688-FreeRTOS-Plus-TCP-Out-of-Bounds-Write preview

CVE-2025-5688-FreeRTOS-Plus-TCP-Out-of-Bounds-Write

GitHubmbanyamer/cve-2025-5688-freertos-plus-tcp-out-of-bounds-write

PoC exploit for CVE-2025-5688: remote out-of-bounds write in FreeRTOS-Plus-TCP via crafted LLMNR/mDNS queries, causing crash or potential RCE on…

binary-exploitationdns-analysisembedded-systems-security+6
6 months ago
CVE-2020-6308-mass-exploiter preview

CVE-2020-6308-mass-exploiter

GitHubfreefv/cve-2020-6308-mass-exploiter

Mass exploiter for CVE-2020-6308 with multi-worker support, enabling automated exploitation of vulnerable SAP NetWeaver systems.

exploitationfuzzingpenetration-testing+2
5 years ago
CVE-2020-25478--ASUS-RT-AC87U-TFTP-is-vulnerable-to-Denial-of-Service-DoS-attack preview

CVE-2020-25478--ASUS-RT-AC87U-TFTP-is-vulnerable-to-Denial-of-Service-DoS-attack

GitHubsantokum/cve-2020-25478--asus-rt-ac87u-tftp-is-vulnerable-to-denial-of-service-dos-attack

ASUS RT-AC87U TFTP is vulnerable to Denial of Service(DoS) attack

exploitationfuzzinghardware-iot-security+1
3 years ago
cve-2026-23398-poc preview

cve-2026-23398-poc

GitHubzpol/cve-2026-23398-poc

Reproducible lab for CVE-2026-23398, a Linux kernel NULL dereference in icmp_tag_validation() triggered by ICMP Fragmentation Needed packets, causing…

educationexploitationfuzzing+3
14 months ago
peach preview

peach

GitHubcalebstewart/peach

Simple vulnerability scanning framework

code-analysisfuzzingstatic-analysis+1
519 years ago
w1f1t3kAl1 preview

w1f1t3kAl1

GitHubnu11secur1ty/w1f1t3kal1

w1f1t3kAl1

cryptographyfuzzingpassword-attacks+3
4720 days ago
CVE-2025-40634 preview

CVE-2025-40634

GitHubhacefresko/cve-2025-40634

Exploit for stack-based buffer overflow found in the conn-indicator binary in the TP-Link Archer AX50 router

binary-exploitationembedded-systems-securityexploitation+5
3110 months ago
NotEnough preview

NotEnough

GitHubcaoweiquan322/notenough

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

binary-exploitationexploitationfuzzing+3
252 years ago
Previous12Next