Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
94 results
frida-ipa-extract preview

frida-ipa-extract

GitHublautarovculic/frida-ipa-extract

Robust Frida-based tool to dump decrypted iOS apps as .ipa from a jailbroken device supports App Store, sideloaded and system.

information-gatheringios-securitymobile-app-pentesting+3
116
5 months ago
GeckoDroid preview

GeckoDroid

GitHubblacksnufkin/geckodroid

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

android-securitycommand-and-controlmobile-security+4
385 months ago
Artemis preview

Artemis

GitHubhadesscs/artemis

Extracts and investigates infrastructure (IPs, domains) from APK files, with manifest parsing and WHOIS lookup for mobile application reconnaissance.

android-securityinformation-gatheringmobile-security+2
663 years ago
TransitionPlayer preview

TransitionPlayer

GitHubcanyie/transitionplayer

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

android-securitybinary-exploitationeducation+4
331 month ago
CVE-2021-25374_Samsung-Account-Access preview

CVE-2021-25374_Samsung-Account-Access

GitHubreverseclabs/cve-2021-25374_samsung-account-access

This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung…

android-securityexploitationmobile-security+3
322 years ago
aotopsy preview

aotopsy

GitHubbronils/aotopsy

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

binary-analysismobile-app-pentestingmobile-security+2
171 day ago
CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions preview

CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions

GitHub0xjohnnydev/cve-2026-28992-iohidfamily-fastpathuserclient-race-conditions

UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

binary-exploitationexploitationios-security+5
141 month ago
CVE-2026-0047-poc preview

CVE-2026-0047-poc

GitHubmobilehackinglab/cve-2026-0047-poc

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

android-securitybinary-exploitationeducation+6
153 months ago
jadx-magic-strings preview

jadx-magic-strings

GitHub0rshemesh/jadx-magic-strings

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

android-securitybinary-analysiscode-analysis+5
399 months ago
CVE-2023-6241-Pixel7_Adaptation preview

CVE-2023-6241-Pixel7_Adaptation

GitHubilgobbo00/cve-2023-6241-pixel7_adaptation

Adaptation of CVE-2023-6241 for Google Pixel 7 from Google Pixel 8 taken from securitylab/SecurityExploits/Android/Mali/CVE_2023_6241

android-securitybinary-exploitationdebuggers+5
141 year ago
Triple_Fetch-Kernel-Creds preview

Triple_Fetch-Kernel-Creds

GitHubjosephshenton/triple_fetch-kernel-creds

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

exploitationexploit-frameworksios-security+3
79 years ago
CVE-2014-4481 preview

CVE-2014-4481

GitHubfeliam/cve-2014-4481

Apple CoreGraphics framework fails to validate the input when parsing CCITT group 3 encoded data resulting in a heap overflow condition. A small heap…

binary-exploitationexploitationios-security+3
511 years ago
ztewaste preview

ztewaste

GitHubjoshatticus/ztewaste

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

android-securitydata-exfiltrationdigital-forensics+6
32 months ago
CVE-2021-43530-UXSS-On-QRcode-Reader- preview

CVE-2021-43530-UXSS-On-QRcode-Reader-

GitHubhfh86/cve-2021-43530-uxss-on-qrcode-reader-

CVE-2021-43530 A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned…

android-securityexploitationmobile-security+2
22 months ago
NXLoader preview

NXLoader

GitHubresi-le/nxloader

An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability

embedded-systems-securityexploitationhardware-hacking+2
18 months ago
MDC preview

MDC

GitHubtdquang266/mdc

I do some tweaking for iOS from 16.0 to 16.1.2 based on MacDirtyCow (CVE-2022-46689) exploit.

exploitationios-securitymobile-security+2
12 years ago
CTT-Apple-Silicon-Refraction preview

CTT-Apple-Silicon-Refraction

GitHubsimoesctt/ctt-apple-silicon-refraction

webkit_refraction.js (The 33-Layer WebGL Payload) ​This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It…

binary-exploitationexploitationios-security+4
16 months ago
Chrome-Forensic_CVE-2024-0044 preview

Chrome-Forensic_CVE-2024-0044

GitHubjacktekno/chrome-forensic_cve-2024-0044

A robust digital forensics tool for extracting and analyzing Google Chrome artifacts from Android devices

android-securitydata-recoverydigital-forensics+6
7 months ago
Previous123456Next