Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
388 results
CVE-2017-7921-EXP preview

CVE-2017-7921-EXP

GitHubblacksheepstudio/cve-2017-7921-exp

Python exploit for CVE-2017-7921 in Hikvision IP cameras, performing unauthenticated user enumeration, snapshot capture, and configuration file…

authenticationexploitationinformation-gathering+3
3 years ago
zyxel-p870hn-hardware-hacking preview

zyxel-p870hn-hardware-hacking

GitHubdanyw24/zyxel-p870hn-hardware-hacking

From a bare PCB to root: hardware-hacking a ZyXEL P-870HN (BCM6368) over UART — CVE-2025-0890 + CVE-2024-40891, on my own hardware.

educationembedded-systems-securityexploitation+6
7 days ago
CVE-2026-25938-FUXA-Unauthenticated-RCE preview

CVE-2026-25938-FUXA-Unauthenticated-RCE

GitHubjudgedbykira/cve-2026-25938-fuxa-unauthenticated-rce

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

exploitationiot-securitypayload-development+6
17 days ago
Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC preview

Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC

GitHubdarknesschieftain/injection-vulnerability-in-paradox-security-systems-ipr512-cve-2023-24709-poc

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

exploitationiot-securitypenetration-testing+3
3 years ago
CVE-2026-64824-PoC preview

CVE-2026-64824-PoC

GitHubboreas37/cve-2026-64824-poc

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

exploitationiot-securitypayload-development+2
110 days ago
pocs_slides preview

pocs_slides

GitHubcq674350529/pocs_slides

my advisory, poc, slides and scripts related to IoT/protocol security

binary-analysisexploitationiot-security+4
7111 months ago
FirmAE preview

FirmAE

GitHubpr0v3rbs/firmae

Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis

dynamic-analysis-sandboxingembedded-systems-securityfirmware-analysis+3
9071 month ago
untitledgoosetool preview

untitledgoosetool

GitHubcisagov/untitledgoosetool

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

cloud-securitydefensive-toolsdigital-forensics+4
9626 months ago
EvilCrowRF_Custom_Firmware_CC1101_FlipperZero preview

EvilCrowRF_Custom_Firmware_CC1101_FlipperZero

GitHubh-rat/evilcrowrf_custom_firmware_cc1101_flipperzero

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

embedded-systems-securityhardware-hackinghardware-iot-security+5
5922 years ago
go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset preview

go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset

GitHubhunt-benito/go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset
binary-exploitationdynamic-analysis-sandboxingembedded-systems-security+6
13 days ago
dlink preview

dlink

GitHubnetsecfish/dlink
authenticationexploitationiot-security+3
1002 years ago
BlueSpy preview

BlueSpy

GitHubtarlogicsecurity/bluespy

PoC to record audio from a Bluetooth device

bluetooth-securityexploitationhardware-iot-security+3
1.6k3 months ago
meshtastic-cve-2025-52464-poc preview

meshtastic-cve-2025-52464-poc

GitHubmsdmehdipour/meshtastic-cve-2025-52464-poc

Software-only proof of concept for CVE-2025-52464 in Meshtastic Direct Messages

cryptographyeducationembedded-systems-security+4
114 days ago
CVE-2026-21009-ECDSA-Nonce-Reuse-in-IoT-Firmware-Signing preview

CVE-2026-21009-ECDSA-Nonce-Reuse-in-IoT-Firmware-Signing

GitHubgeorge0papasotiriou/cve-2026-21009-ecdsa-nonce-reuse-in-iot-firmware-signing
cryptographyeducationexploitation+3
17 days ago
firmware-workshop preview

firmware-workshop

GitHubonekey-sec/firmware-workshop

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…

binary-analysisdynamic-analysis-sandboxingeducation+5
591 month ago
CVE-2026-2222-MQTT-Broker-CONNECT-Packet-Heap-Overflow preview

CVE-2026-2222-MQTT-Broker-CONNECT-Packet-Heap-Overflow

GitHubgeorge0papasotiriou/cve-2026-2222-mqtt-broker-connect-packet-heap-overflow
binary-exploitationeducationexploitation+2
18 days ago
CVE-2026-0101-BLE-Address-Spoofing-via-Weak-Resolvable-Private-Address preview

CVE-2026-0101-BLE-Address-Spoofing-via-Weak-Resolvable-Private-Address

GitHubgeorge0papasotiriou/cve-2026-0101-ble-address-spoofing-via-weak-resolvable-private-address
adversarial-attackbluetooth-securityeducation+3
18 days ago
unknownpwn.github.io preview

unknownpwn.github.io

GitHubunknownpwn-zz/unknownpwn.github.io

infosec enthusiast and madman

exploitationhardware-iot-securityiot-security+3
28 years ago
Previous12…22Next