Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
132 results
kunglao-agent preview

kunglao-agent

GitHubamd2g2zz/kunglao-agent

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

ai-assisted-reversingandroid-securitybinary-analysis+8
26
2 days ago
CVE-2026-20516 preview

CVE-2026-20516

GitHubdingo97/cve-2026-20516

Write-up and ADB proof of concept for CVE-2026-20516, a confused deputy flaw in MediaTek Android TV MiracastService allowing local Wi-Fi Direct state…

android-securityeducationexploitation+5
4 days ago
ghostlock-kit preview

ghostlock-kit

GitHubzhubaohe123/ghostlock-kit

One-click root kit for vivo iQOO Neo9S Pro (MT6989) exploiting CVE-2026-43499 futex PI UAF via MCAST transport, with scripts and analysis docs.

android-securitybinary-exploitationexploitation+7
2 days ago
the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss preview

the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

GitHubhunt-benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

android-securitydynamic-analysis-sandboxingexploitation+6
4 days ago
AuroraStore preview

AuroraStore

GitLabauroraoss/aurorastore

Open-source Android client for browsing and downloading apps from Google Play with anonymous login, device/locale spoofing, and tracker detection.

android-securitygeneral-purpose-utilitiesmobile-app-pentesting+1
2.3k22 days ago
ghostlock-x200-app preview

ghostlock-x200-app

GitHubxiaohj233/ghostlock-x200-app

vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)

android-securityexploitationexploit-frameworks+4
215 days ago
OrganizerTransaction preview

OrganizerTransaction

GitHubmichalbednarski/organizertransaction

PoC for CVE-2021-39749, allowing starting arbitrary Activity on Android 12L Beta

android-securityexploitationmobile-app-pentesting+2
374 years ago
slythestx preview

slythestx

GitHubstuxctf/slythestx

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

android-securitydynamic-analysis-sandboxingios-security+6
141 month ago
ssl-kill-switch2 preview

ssl-kill-switch2

GitHubnabla-c0d3/ssl-kill-switch2

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

ios-securitymobile-app-pentestingmobile-security+3
3.3k3 years ago
frida-ios-dump-modern preview

frida-ios-dump-modern

GitHubjwalker/frida-ios-dump-modern

An updated Frida iOS dump tool supporting the latest Frida 17.5.2 APIs

binary-analysisios-securitymalware-analysis+3
97 months ago
grapefruit preview

grapefruit

GitHubchichou/grapefruit

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

android-securitybinary-analysisdynamic-code-analysis+5
1.4k1 month ago
ipatool preview

ipatool

GitHubmajd/ipatool

Command-line tool that allows you to search for iOS, iPadOS, tvOS, visionOS, and macOS apps on the App Store, and download .ipa or macOS .pkg app…

information-gatheringios-securitymobile-app-pentesting+2
11.2k1 day ago
frida-interception-and-unpinning preview

frida-interception-and-unpinning

GitHubhttptoolkit/frida-interception-and-unpinning

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

android-securityios-securitymobile-app-pentesting+4
2.3k5 days ago
mitmproxy_rs preview

mitmproxy_rs

GitHubmitmproxy/mitmproxy_rs

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

api-security-testingmobile-app-pentestingnetwork-security+2
44525 days ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubhackerronin/cve-2024-0044

a vulnerability affecting Android version 12 & 13

android-securityexploitationmobile-app-pentesting+3
62 years ago
CVE-2020-0096-strandhogg-exploit-p0c preview

CVE-2020-0096-strandhogg-exploit-p0c

GitHubhackerronin/cve-2020-0096-strandhogg-exploit-p0c

Android Application Task Hijacking Aka Strandhogg Attack Exploit

android-securityexploitationmobile-app-pentesting+1
12 years ago
android-hardware-attestation-demo preview

android-hardware-attestation-demo

GitHubquarkslab/android-hardware-attestation-demo

An Android HW Attestation demo

android-securityauthentication-authorizationeducation+3
511 month ago
aotopsy preview

aotopsy

GitHubbronils/aotopsy

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

binary-analysismobile-app-pentestingmobile-security+2
276 days ago
Previous12…8Next