Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
298 results
Fix-Apple-Mail-CVE-2020-9922 preview

Fix-Apple-Mail-CVE-2020-9922

GitHubwowfunhappy/fix-apple-mail-cve-2020-9922

Patches the zero-click Apple Mail vulnerability (CVE-2020-9922) on macOS, preventing remote code execution without user interaction.

binary-exploitationexploitationforensics+3
3
11 months ago
APKLab preview

APKLab

GitHubapklab/apklab

Android Reverse-Engineering Workbench for VS Code

android-securitybinary-analysisdynamic-analysis-sandboxing+4
4k2 months ago
simplify preview

simplify

GitHubcalebfenton/simplify

Android virtual machine and deobfuscator

android-securitybinary-analysisdynamic-analysis-sandboxing+2
4.7k5 years ago
androwarn preview

androwarn

GitHubmaaaaz/androwarn

Yet another static code analyzer for malicious Android applications

android-securitymalware-analysismobile-security+2
5347 years ago
DECAF preview

DECAF

GitHubdecaf-project/decaf

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

android-securitybinary-analysisdynamic-analysis-sandboxing+2
8415 years ago
Apkx-Hunter preview

Apkx-Hunter

GitHubsyscallx-18113/apkx-hunter

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

android-securityinformation-gatheringmachine-learning+7
9419 days ago
MalEval preview

MalEval

GitHubzhengxr930/maleval

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

ai-securityandroid-securitycode-analysis+5
52 months ago
USBvalve preview

USBvalve

GitHubcecio/usbvalve

Expose USB activity on the fly

dynamic-analysis-sandboxingembedded-systems-securityforensics+2
1.3k1 month ago
MalwareSourceCode preview

MalwareSourceCode

GitHubvxunderground/malwaresourcecode

Collection of malware source code for a variety of platforms in an array of different programming languages.

curated-resourceseducationmalware-analysis+1
18.8k4 months ago
RedTeamCCode preview

RedTeamCCode

GitHubmr-un1k0d3r/redteamccode

Red Team C code repo

binary-analysisdefensive-toolsmalware-analysis+1
5731 year ago
LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubc-g-creator/letsdefend-soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

ctfeducationemail-security+6
5 months ago
ExportHider preview

ExportHider

GitHubfrkngksl/exporthider

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

binary-analysisdynamic-code-analysisexploitation+4
365 months ago
inspec_cve_2019_15224 preview

inspec_cve_2019_15224

GitHubchef-cft/inspec_cve_2019_15224

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

configuration-auditingincident-responsemalware-analysis+2
17 years ago
ThreatCheck preview

ThreatCheck

GitHubrasta-mouse/threatcheck

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

binary-analysisdefensive-toolsmalware-analysis+1
1.6k6 months ago
OSweep preview

OSweep

GitHubecstatic-nobel/osweep

Don't Just Search OSINT. Sweep It.

dns-subdomain-enumerationinformation-gatheringmalware-analysis+4
3197 years ago
Limon preview

Limon

GitHubmonnappa22/limon

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

dynamic-analysis-sandboxingmalware-analysismemory-forensics+1
40510 years ago
rasputin preview

rasputin

GitHubfrenchyeti/rasputin

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

android-securitybinary-analysiscurated-resources+4
6210 days ago
0xCr0ssCrush preview

0xCr0ssCrush

GitHubdeathshotxd/0xcr0sscrush

Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities.

binary-analysisdefensive-toolsexploitation+4
363 days ago
Previous1…345…17Next