Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
408 results
dockerized-android preview

dockerized-android

GitHubcybersecsi/dockerized-android

A container-based framework to enable the integration of mobile components in security training platforms

android-securitycontainer-securityeducation+2
187
4 years ago
mas-crackmes preview

mas-crackmes

GitHubowasp/mas-crackmes

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

android-securitybinary-analysisctf+6
373 years ago
CVE_2019_2215 preview

CVE_2019_2215

GitHub0xbinder/cve_2019_2215

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

android-securitybinary-exploitationeducation+5
325 days ago
android-workprofile-exploit preview

android-workprofile-exploit

GitHubhasan-al-hussein/android-workprofile-exploit

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

android-securitydata-exfiltrationeducation+5
11 month ago
CVE-2021-521-Exploit preview

CVE-2021-521-Exploit

GitHubnagendrapittu/cve-2021-521-exploit

Lab Exploit (CVE-2021-521): App uses Java reflection to access Android system components, retrieving a list of all installed apps. Reflection…

android-securityeducationexploitation+3
3 years ago
Flutter-Reverse-Engineering-Labs preview

Flutter-Reverse-Engineering-Labs

GitHubbrnpl/flutter-reverse-engineering-labs

Hands-on challenges for learning how to reverse engineer Flutter applications.

android-securitybinary-analysisctf+6
585 days ago
CVE-2026-0047-poc preview

CVE-2026-0047-poc

GitHubmobilehackinglab/cve-2026-0047-poc

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

android-securitybinary-exploitationeducation+6
154 months ago
Bootloader_Unlock_Retroid_Pocket_3Plus preview
Archived

Bootloader_Unlock_Retroid_Pocket_3Plus

GitHubseriousattempts/bootloader_unlock_retroid_pocket_3plus

Bootloader unlock using CVE-2022-38694 for Retroid Pocket 3+

android-securityeducationembedded-systems-security+4
21 year ago
CVE-2023-25690-POC preview

CVE-2023-25690-POC

GitHubdhmosfunk/cve-2023-25690-poc

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

educationexploitationlabs-practice+3
2892 years ago
Keycloak_CVE-2026-18963_PoC preview

Keycloak_CVE-2026-18963_PoC

GitHubprot0tw/keycloak_cve-2026-18963_poc

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

authenticationexploitationlabs-practice+3
1524 days ago
CVE-2023-25690-POC preview

CVE-2023-25690-POC

GitHuboocyginxoo/cve-2023-25690-poc

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

educationexploitationlabs-practice+3
21 year ago
ethical-hacking-CVE-2011-2523 preview

ethical-hacking-CVE-2011-2523

GitHubchathura123git/ethical-hacking-cve-2011-2523

Ethical Hacking Assessment | Practical vulnerability testing of vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 using Kali Linux & Metasploit

ctfeducationexploitation+3
3 months ago
thm_steelmountain_CVE-2014-6287 preview

thm_steelmountain_CVE-2014-6287

GitHubmrintern/thm_steelmountain_cve-2014-6287

a python3 version of the exploit written for CVE-2014-6287. Useful for completing the "Steel Mountain" room on TryHackMe.com without the use of…

binary-exploitationctfeducation+3
14 years ago
Awesome-RCE-techniques preview

Awesome-RCE-techniques

GitHubp0dalirius/awesome-rce-techniques

Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

curated-resourceseducationexploitation+3
1.9k2 years ago
sudoinjection preview

sudoinjection

GitHubmikivirus0/sudoinjection

Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)

binary-exploitationctfeducation+5
21 year ago
SUDO_KILLER preview

SUDO_KILLER

GitHubth3xace/sudo_killer

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

ctfeducationexploitation+5
2.5k6 months ago
ludus_crushftp_cve-2025-31161 preview

ludus_crushftp_cve-2025-31161

GitHubrufflabs/ludus_crushftp_cve-2025-31161

Ansible role deploying a vulnerable CrushFTP 10.8.0 instance on Windows for authorized penetration testing of CVE-2025-31161 authentication bypass.

educationexploitationlabs-practice+3
2 months ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
6 months ago
Previous1…678…23Next