Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
awesome-privacy preview

awesome-privacy

GitHublissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

authenticationcurated-resourceseducation+6
9.9k1 day ago
AppInfoScanner preview

AppInfoScanner

GitHubkelvinben/appinfoscanner

一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。

android-securityinformation-gatheringios-security+6
3.6k4 days ago
Root-My-Galaxy-Payloads preview

Root-My-Galaxy-Payloads

GitHubnewazbenalam/root-my-galaxy-payloads

Device-specific CVE-2026-43499 root payloads and KernelSU artifacts for Samsung Galaxy models, with firmware profiles, exploit source, and a support…

android-securitybinary-exploitationexploitation+6
10 days ago
HydraDragonAV-Mobile preview

HydraDragonAV-Mobile

GitHubhydradragonantivirus/hydradragonav-mobile

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

android-securitydefensive-toolsdynamic-analysis-sandboxing+6
1712 days ago
the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss preview

the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

GitHubhunt-benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

android-securitydynamic-analysis-sandboxingexploitation+6
14 days ago
T3MP3ST preview

T3MP3ST

GitHubelder-plinius/t3mp3st

autonomous red teaming platform; multi-agent offensive-security meta-harness

ai-securitybinary-analysiscloud-security+9
6.2k17 days ago
cerberus-re-skill preview

cerberus-re-skill

GitHubowenpawl/cerberus-re-skill

cerberus-re is a local Apple-focused reverse-engineering workbench for building a repeatable three-headed static/dynamic/instrumentation loop around…

binary-analysisdebuggersdynamic-analysis-sandboxing+7
20126 days ago
CyberMeowfiaNS preview

CyberMeowfiaNS

GitHubxingchenrs/cybermeowfians

The next stage of CyberMeowfil (CVE-2026-43499 and 43074),Possibly biased toward vivo devices?

android-securitybinary-analysiscurated-resources+4
61 month ago
pentest-ai-agents preview

pentest-ai-agents

GitHub0xsteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

ai-securitycloud-securityeducation+8
2.3k1 month ago
IonStack-S22-cve-2026-43499 preview
Archived

IonStack-S22-cve-2026-43499

GitHubcamsshaft/ionstack-s22-cve-2026-43499

Android kernel exploit for Samsung Galaxy S22 that gains kernel-domain root via CVE-2026-43499, with SELinux permissive, device-specific kallsyms,…

android-securitybinary-exploitationexploitation+2
1 month ago
CVE-2026-43499-S24U preview

CVE-2026-43499-S24U

GitHubfusiondrive/cve-2026-43499-s24u

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (COMPLETED)

android-securitybinary-exploitationexploitation+5
41 month ago
abdal-lockbox preview

abdal-lockbox

GitLabprof.shafiei/abdal-lockbox

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

android-securityauthenticationcryptography+5
1 month ago
attack-stix-data preview

attack-stix-data

GitHubmitre-attack/attack-stix-data

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

curated-resourcesioc-managementmobile-security+4
6721 month ago
CVE-2026-43499-A36 preview

CVE-2026-43499-A36

GitHubfusiondrive/cve-2026-43499-a36

Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load

android-securitybinary-exploitationexploitation+4
11 month ago
CVE-2026-43499_OPPO-MT6835 preview

CVE-2026-43499_OPPO-MT6835

GitHub2932796375github/cve-2026-43499_oppo-mt6835

Proof-of-concept exploit chain for CVE-2026-43499 targeting OPPO MT6835 Android devices, with preload payload, build system, and analysis notes for…

android-securitybinary-exploitationeducation+4
41 month ago
CTT-Apple-Silicon-Refraction preview

CTT-Apple-Silicon-Refraction

GitHubsimoesctt/ctt-apple-silicon-refraction

webkit_refraction.js (The 33-Layer WebGL Payload) ​This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It…

binary-exploitationexploitationios-security+4
17 months ago
Olyx preview

Olyx

GitLabshacode/olyx

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

android-securityapi-securitydns-analysis+7
8 months ago
CVE-2025-32407 preview

CVE-2025-32407

GitHubdiegovargasj/cve-2025-32407

Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…

dns-analysisexploitationmobile-security+6
1 year ago
Previous12Next