Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
141 results
ChameleonMini preview

ChameleonMini

GitHubrfidresearchgroup/chameleonmini

Portable NFC/RFID security tool for emulating and cloning contactless smartcards, reading tags, sniffing RF traffic, and recovering Mifare access…

hardware-hackinginformation-gatheringpenetration-testing+2
4402 years ago
Log4j-CVE-2021-44228 preview

Log4j-CVE-2021-44228

GitHubjustakazh/log4j-cve-2021-44228

Mass scanner for Log4j CVE-2021-44228 vulnerability with Python-based detection and exploit capabilities for automated security testing.

exploitationinformation-gatheringpenetration-testing+2
64 years ago
CVE-2025-29927-Testing preview

CVE-2025-29927-Testing

GitHubtheresafewconors/cve-2025-29927-testing

PowerShell script to test if a web app is vulnerable to CVE-2025-29927

exploitationinformation-gatheringpenetration-testing+3
21 year ago
CVE-2021-41647 preview

CVE-2021-41647

GitHubmobiusbinary/cve-2021-41647

Proof-of-concept exploit for unauthenticated SQL injection in Online-Food-Ordering-Web-App, demonstrating login bypass and error/time-based blind…

educationexploitationinformation-gathering+3
4 years ago
RSC-Infra-Scanner preview

RSC-Infra-Scanner

GitHubvyvivekyadav04/rsc-infra-scanner

This is a fast, asynchronous Python tool that fingerprints domains for likely Next.js App Router / React Server Components (RSC) infrastructure. (I…

educationinformation-gatheringreconnaissance+2
9 months ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
HostileSubBruteforcer preview

HostileSubBruteforcer

GitHubnahamsec/hostilesubbruteforcer

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

cloud-securitydns-subdomain-enumerationinformation-gathering+3
4839 years ago
x8-Burp preview

x8-Burp

GitHubimpact-i/x8-burp

Hidden parameters discovery suite

api-security-testinginformation-gatheringreconnaissance+2
2253 years ago
AdbNet preview

AdbNet

GitHub0x1ca3/adbnet

A tool that allows you to search for vulnerable android devices across the world and exploit them.

android-securityexploitationinformation-gathering+4
4345 years ago
POC-ES-File-Explorer-CVE-2019-6447 preview

POC-ES-File-Explorer-CVE-2019-6447

GitHubjulio-cfa/poc-es-file-explorer-cve-2019-6447

Bash PoC script exploiting CVE-2019-6447 in ES File Explorer to list files, photos, videos, apps, and download files from vulnerable Android devices.

android-securitydata-exfiltrationexploitation+3
4 years ago
CVE-2024-23700-C2-Server preview

CVE-2024-23700-C2-Server

GitHubkaitokidc500/cve-2024-23700-c2-server

Source code minh họa máy chủ c2 demo kịch bản thực thi của CVE-2024-23700

android-securitycommand-and-controldata-exfiltration+9
15 days ago
sniffnet preview

sniffnet

GitHubgyulyvgc/sniffnet

Comfortably monitor your network traffic 🕵️‍♂️

dns-analysisinformation-gatheringpacket-sniffing-analysis+1
41.1k1 day ago
Apepe preview

Apepe

GitHub0xdsm/apepe

Extracts app settings, permissions, deeplinks, and SSL pinning bypass suggestions from Android APK files via static analysis of AndroidManifest.xml,…

android-securityinformation-gatheringmobile-app-pentesting+1
15610 months ago
CVE-2026-0047-poc preview

CVE-2026-0047-poc

GitHubmobilehackinglab/cve-2026-0047-poc

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

android-securitybinary-exploitationeducation+6
154 months ago
Android-Passive-Location-Tracker preview

Android-Passive-Location-Tracker

GitHubchirantar7004/android-passive-location-tracker

Location tracking app without location permissions! Makes use of CVE-2018-15835 which makes use of Android OS information leakage.

android-securityexploitationinformation-gathering+3
26 years ago
phonepe-sensitive-data-exposure-cve-2025-5154 preview

phonepe-sensitive-data-exposure-cve-2025-5154

GitHubhonestcorrupt/phonepe-sensitive-data-exposure-cve-2025-5154

CVE-2025-5154: Proof-of-concept for unencrypted local storage of authentication tokens, PII, and KYC data in the PhonePe Android app, enabling…

android-securityauthenticationdata-exfiltration+6
11 year ago
social-analyzer preview

social-analyzer

GitHubqeeqbox/social-analyzer

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

crawleremail-harvestingimpersonation-tools+7
24.0k7 months ago
ipatool preview

ipatool

GitHubmajd/ipatool

Command-line tool that allows searching and downloading app packages (known as ipa files) for iOS, iPadOS, tvOS, and visionOS from the App Store.

information-gatheringios-securitymobile-app-pentesting+2
11.0k4 days ago
Previous12…8Next