Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
exr-imageio-poc preview

exr-imageio-poc

GitHubbilly-ellis/exr-imageio-poc

PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5

binary-exploitationexploitationfuzzing+3
46
3 months ago
CVE-2026-62958 preview

CVE-2026-62958

GitHub0linear/cve-2026-62958

Proof-of-concept for CVE-2026-62958: crafts a malformed ELF to trigger an out-of-bounds read in Libriscv and crash the sandbox with SIGSEGV.

binary-exploitationexploitationfuzzing+2
3 months ago
gdcm-security-poc preview

gdcm-security-poc

GitHubabhinavagarwal07/gdcm-security-poc

Private end-to-end sanitizer reproduction package for six GDCM findings

binary-analysisdynamic-analysis-sandboxingeducation+6
18 days ago
HyperOS-Directory-Traversal-Analysis preview

HyperOS-Directory-Traversal-Analysis

GitHubkkaanozturk/hyperos-directory-traversal-analysis

Xiaomi HyperOS AVCodec Medya Framework'ündeki Use-After-Free (CVE-2025-21082) Zafiyetinin Derinlemesine Analizi, Rust Simülasyonu ve İnteraktif Web…

binary-exploitationctfdynamic-analysis-sandboxing+8
12 months ago
google-poc preview

google-poc

GitHub0xxa/google-poc

This repo contains instructions to reproduce CVE-2025-13425: Null Pointer dereference / Array over-indexing vulnerability that I found in Google's…

binary-analysisexploitationfirmware-analysis+3
10 months ago
angr preview

angr

GitHubangr/angr

A powerful and user-friendly binary analysis platform!

ai-assisted-reversingbinary-analysisbinary-exploitation+12
9.1k3 days ago
cve-2026-86547-mrubyc-op-enter preview

cve-2026-86547-mrubyc-op-enter

GitHubharshrajsinghania/cve-2026-86547-mrubyc-op-enter

Standalone proof of concept for CVE-2026-86547, a NULL pointer dereference in mrubyc op_enter() through 4.0.0.

embedded-systems-securityexploitationfuzzing+3
16 days ago
splinter preview

splinter

GitHubawrped/splinter

Runtime JVM analysis toolkit for inspecting classes, methods, fields, constant pool, and bytecode

binary-analysisdebuggersdynamic-analysis-sandboxing+4
911 month ago
CVE-2026-28609-matroska-pcm-oob preview

CVE-2026-28609-matroska-pcm-oob

GitHubdevrodt2/cve-2026-28609-matroska-pcm-oob

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

android-securitybinary-exploitationexploitation+5
66 days ago
Platbox preview

Platbox

GitHubioactive/platbox

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

binary-analysisfirmware-analysisfuzzing+3
2221 year ago
dezlock-dump preview

dezlock-dump

GitHubdougwithseismic/dezlock-dump

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

binary-analysisdebuggersdynamic-code-analysis+6
916 months ago
mnemosyne preview

mnemosyne

GitHubnccgroup/mnemosyne

A Generic Windows Memory Scraping Tool

dynamic-analysis-sandboxingfuzzinginformation-gathering+2
699 years ago
uafuzz preview

uafuzz

GitHubstrongcourage/uafuzz

Binary-level directed fuzzer specialized in detecting Use-After-Free vulnerabilities via ordering-aware input metrics and static analysis, enabling…

binary-analysisexploitationfuzzing+2
3534 years ago
windbg_js_scripts preview

windbg_js_scripts

GitHubhugsy/windbg_js_scripts

Toy scripts for playing with WinDbg JS API

binary-analysisdebuggersdynamic-code-analysis+3
2442 years ago
memscan preview

memscan

GitHubnccgroup/memscan

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

data-exfiltrationfuzzinginformation-gathering+5
1285 years ago
MemITM preview

MemITM

GitHubamossys/memitm

Tool to make in memory man in the middle

binary-analysisdebuggersdynamic-analysis-sandboxing+4
1267 years ago
CVE-2026-90781-alsa-lib-oob preview

CVE-2026-90781-alsa-lib-oob

GitHubharshrajsinghania/cve-2026-90781-alsa-lib-oob

Standalone reproducer for CVE-2026-90781: 1-byte OOB write in alsa-lib __snd_ctl_ascii_elem_id_parse() name= parsing (quoted and unquoted)

educationexploitationfuzzing+4
14 days ago
CVE-2026-90782-s2opc-status-clobber preview

CVE-2026-90782-s2opc-status-clobber

GitHubharshrajsinghania/cve-2026-90782-s2opc-status-clobber

Standalone PoC for CVE-2026-90782: status-clobbering NULL dereference in S2OPC alloc_notification_message_items() (DataChange fails, Event succeeds)

binary-analysisexploitationfuzzing+2
14 days ago
Previous1234Next