Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
claude-bug-bounty preview

claude-bug-bounty

GitHubshuvonsec/claude-bug-bounty

AI-powered bug bounty hunting toolkit that works with or without subscription.

ai-securitycloud-securityexploitation+8
5.2k
2 days ago
reFlutter preview

reFlutter

GitHubimpact-i/reflutter

Patches Flutter engine libraries to enable runtime reverse engineering, traffic interception, and SSL pinning bypass for Android and iOS apps without…

android-securitydynamic-analysis-sandboxingios-security+3
2.8k2 days ago
ghostlock-app preview

ghostlock-app

GitHubyukonga/ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

android-securitybinary-analysisexploitation+4
1.1k3 days ago
apk-medit preview

apk-medit

GitHubsterrasec/apk-medit

memory search and patch tool on debuggable apk without root & ndk

android-securitybinary-analysismemory-forensics+2
4346 days ago
LiveContainer preview

LiveContainer

GitHublivecontainer/livecontainer

Run iOS apps without actually installing them!

binary-analysiscode-analysiscontainer-escape+6
12.4k8 days ago
CVE-2026-84600 preview

CVE-2026-84600

GitHubowenpawl/cve-2026-84600

Information on the security content of Apple software updates

ios-securitymobile-securityvulnerability-analysis
9 days ago
objection preview

objection

GitHubsensepost/objection

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

android-securitydynamic-analysis-sandboxingexploitation+9
9.4k9 days ago
gotatun preview

gotatun

GitHubmullvad/gotatun

Userspace WireGuard® Implementation in Rust

cloud-securityencryption-decryption-toolsmobile-security+2
1.4k10 days ago
aotopsy preview

aotopsy

GitHubbronils/aotopsy

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

binary-analysismobile-app-pentestingmobile-security+2
3018 days ago
K50G-POCOF4GT-CVE-2026-43499-PoC preview

K50G-POCOF4GT-CVE-2026-43499-PoC

GitHubcxyofficial/k50g-pocof4gt-cve-2026-43499-poc

Local privilege escalation exploit for Redmi K50G/POCO F4 GT using CVE-2026-43499 (futex UAF) to gain temporary root and load KernelSU without…

android-securitybinary-exploitationexploitation+5
24 days ago
GhostLock-H80GT preview

GhostLock-H80GT

GitHubyakidango-official/ghostlock-h80gt

Honor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading

android-securitybinary-exploitationexploitation+2
1727 days ago
CVE-2021-36460 preview

CVE-2021-36460

GitHubmartinfrancois/cve-2021-36460

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

authenticationexploitationmobile-security+2
1 month ago
CVE-2026-22011-iOS-MDM-Profile-Delivery-over-HTTP preview

CVE-2026-22011-iOS-MDM-Profile-Delivery-over-HTTP

GitHubgeorge0papasotiriou/cve-2026-22011-ios-mdm-profile-delivery-over-http

PoC Flask server for CVE-2026-22011 that serves a malicious iOS MDM enrollment profile over HTTP, enabling man-in-the-middle interception and device…

exploitationios-securitymobile-security+3
1 month ago
signal-without-smartphone preview

signal-without-smartphone

GitHubalmet/signal-without-smartphone

Desktop application to register a Signal account and link Signal Desktop without requiring a smartphone, using Signal's cryptographic protocols for…

authenticationencryption-decryption-toolsmobile-security+2
761 month ago
CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation- preview

CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-

GitHubgeorge0papasotiriou/cve-2026-6666-xpc-service-nskeyedunarchiver-deserialization-attack-macos-ios-simulation-

Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…

educationexploitationios-security+3
1 month ago
Crimson-Cloak-ISH-wrapper-iOS- preview

Crimson-Cloak-ISH-wrapper-iOS-

GitHubsynchancybersecurity/crimson-cloak-ish-wrapper-ios-

Wrapper to maximize ISH iOS app capabilities without jailbreak

ios-securitymobile-securitypenetration-testing+3
2 months ago
CVE-2026-21018 preview

CVE-2026-21018

GitHubpealeap/cve-2026-21018

Minimal PoC for a Samsung SveService buffer overflow, demonstrating an out-of-bounds write via Binder to crash the Android system service without…

android-securitybinary-exploitationexploitation+3
13 months ago
iOS-Bluetooth-Ethernet-Exploit preview

iOS-Bluetooth-Ethernet-Exploit

GitHubf4r3sx0/ios-bluetooth-ethernet-exploit

iOS Bluetooth PAN vulnerability that opens USB port 62078 and displays Ethernet icon without any adapter (€0). Apple sells a €89.95 adapter for the…

bluetooth-securityeducationexploitation+8
73 months ago
Previous123Next