Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
Evil-Droid preview

Evil-Droid

GitHubm4sc3r4n0/evil-droid
android-securityeducationexploit-frameworks+4
1.1k8 years ago
ReverseAPK preview

ReverseAPK

GitHub1n3/reverseapk

Quickly analyze and reverse engineer Android packages

android-securitymobile-app-pentestingreverse-engineering+2
8683 years ago
idb preview

idb

GitHubdmayer/idb

idb is a tool to simplify some common tasks for iOS pentesting and research

ios-securitymobile-app-pentestingmobile-security+1
9568 years ago
blackboxprotobuf preview

blackboxprotobuf

GitHubnccgroup/blackboxprotobuf

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

binary-analysisdigital-forensicsmobile-app-pentesting+3
7314 months ago
WDBFontOverwrite preview

WDBFontOverwrite

GitHubginsudev/wdbfontoverwrite

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

exploitationios-securitymobile-app-pentesting+2
8893 years ago
vscode-frida preview

vscode-frida

GitHubchichou/vscode-frida

VSCode extension for Frida-based mobile reverse engineering: runtime class/module inspection, Java/ObjC/native hook generation, autocomplete, and…

android-securitybinary-analysisdebuggers+5
5951 month ago
binder-trace preview

binder-trace

GitHubfoundryzero/binder-trace

Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".

android-securitybinary-analysisdynamic-analysis-sandboxing+3
76811 months ago
ssl-kill-switch3 preview

ssl-kill-switch3

GitHubnyamisty/ssl-kill-switch3

Next Generation SSLKillSwitch with much more support!

ios-securitymobile-app-pentestingmobile-security+3
7422 years ago
iGoat-Swift preview

iGoat-Swift

GitHubowasp/igoat-swift

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

ctfeducationios-security+6
4517 months ago
Fermion preview

Fermion

GitHubfuzzysecurity/fermion

Fermion, an electron wrapper for Frida & Monaco.

android-securitybinary-analysisdebuggers+4
7001 year ago
mobileAudit preview

mobileAudit

GitHubmpast/mobileaudit

Django application that performs SAST and Malware Analysis for Android APKs

android-securitycode-analysismalware-analysis+4
22628 days ago
jebmcp preview

jebmcp

GitHubflankerhqd/jebmcp
ai-assisted-reversingandroid-securitymobile-app-pentesting+3
2573 months ago
slicer preview

slicer

GitHubmzfr/slicer

A tool to automate the boring process of APK recon

android-securityinformation-gatheringmobile-app-pentesting+2
3433 years ago
android_application_analyzer preview

android_application_analyzer

GitHubnotsosecure/android_application_analyzer

The tool is used to analyze the content of the android application in local storage.

android-securitydynamic-analysis-sandboxingmobile-app-pentesting+2
1752 months ago
ARTful preview

ARTful

GitHublauriewired/artful

The ARTful library for dynamically modifying the Android Runtime

android-securitydynamic-code-analysismobile-app-pentesting+2
3542 years ago
LazyDroid preview

LazyDroid

GitHubnccgroup/lazydroid

bash script to facilitate some aspects of an Android application assessment

android-securitydynamic-analysis-sandboxinginformation-gathering+3
1594 years ago
DVHMA preview

DVHMA

GitHublogicalhacking/dvhma

Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.

android-securityeducationmobile-app-pentesting+1
2738 years ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
2568 months ago
Previous123456Next