Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
Android-Security-Masterclass preview

Android-Security-Masterclass

GitHubowasp/android-security-masterclass

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

android-securitycryptographyeducation+6
3 days ago
DVIA-v2 preview

DVIA-v2

GitHubprateek147/dvia-v2

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

educationios-securitylabs-practice+3
1.1k2 years ago
kfd preview

kfd

GitHubfelix-pb/kfd

kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

binary-exploitationexploitationios-security+1
1.0k2 years ago
MemorizingTrustManager preview

MemorizingTrustManager

GitHubge0rg/memorizingtrustmanager

A "plugin" for Android Java to allow asking the user about SSL certificates

android-securityauthenticationcryptography+3
1813 years ago
kcmd preview

kcmd

Bitbucketaseemjakhar/kcmd

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

cryptographyexploitationhardware-iot-security+4
11 years ago
QuestStack preview

QuestStack

GitHubstarseed12345/queststack

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

android-securitybinary-exploitationembedded-systems-security+5
2061 month ago
rayhunter preview

rayhunter

GitHubefforg/rayhunter

Rust tool to detect cell site simulators on an orbic mobile hotspot

defensive-toolseducationembedded-systems-security+9
5.9k8 days ago
SpyPhone preview

SpyPhone

GitHubnst/spyphone

This project shows the kind of data a rogue iPhone application can collect.

educationinformation-gatheringios-security+3
3273 months ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
93911 months ago
rdroid preview

rdroid

GitHubhuntoai/rdroid

[Android RAT] Remotely manage your android phone using PHP Interface

android-securitycommand-and-controldata-exfiltration+3
2498 years ago
mas-crackmes preview

mas-crackmes

GitHubowasp/mas-crackmes

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

android-securitybinary-analysisctf+6
373 years ago
sslcaudit preview

sslcaudit

GitHubabbbe/sslcaudit

Automated SSL/TLS client security testing tool for detecting MITM vulnerabilities in thick clients, mobile apps, and network appliances.

mobile-securitynetwork-securitypenetration-testing+2
2910 years ago
iDevice_ZH preview

iDevice_ZH

GitHubpxx917144686/idevice_zh

CVE-2025-24203漏洞

binary-exploitationexploitationios-security+3
241 year ago
Stagefright-cve-2015-1538-1 preview

Stagefright-cve-2015-1538-1

GitHubniranjanshr13/stagefright-cve-2015-1538-1

Cve-2015-1538-1

android-securitybinary-exploitationeducation+3
10 years ago
Rootsmart-v2.0 preview

Rootsmart-v2.0

GitHubcrackercat/rootsmart-v2.0

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

android-securitycommand-and-controldata-exfiltration+8
24 years ago
pois0nSword preview

pois0nSword

GitHubgenericcoding/pois0nsword

A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1

binary-exploitationexploitationexploit-frameworks+5
701 month ago
JustALampNothingElse preview

JustALampNothingElse

GitHubcriszalsa/justalampnothingelse

CVE-2021-25337

android-securityeducationexploitation+2
14 months ago
CVE-2025-24203-iOS-Exploit-With-Error-Logging preview

CVE-2025-24203-iOS-Exploit-With-Error-Logging

GitHubgeosn0w/cve-2025-24203-ios-exploit-with-error-logging

Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero

binary-exploitationexploitationexploit-frameworks+4
4111 months ago
Previous123Next