Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
129 results
masvs preview

masvs

GitHubowasp/masvs

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

android-securitycurated-resourceseducation+3
2.4k
10 months ago
apk.sh preview

apk.sh

GitHubax/apk.sh

Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK.

android-securitybinary-analysisdynamic-analysis-sandboxing+3
3.8k6 months ago
Brida preview

Brida

GitHubfedericodotta/brida

The new bridge between Burp Suite and Frida!

android-securitybinary-analysisdynamic-analysis-sandboxing+5
1.9k9 months ago
WhatsApp-OSINT preview

WhatsApp-OSINT

GitHubkinghacker0/whatsapp-osint

WhatsApp OSINT tool for retrieving profile photos, verifying Business accounts, checking user status, analyzing linked devices, and reviewing privacy…

information-gatheringmobile-securityosint+3
90510 months ago
PenBox preview

PenBox

GitHubx3omdax/penbox

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

exploitationfuzzinginformation-gathering+8
5359 years ago
StaCoAn preview

StaCoAn

GitHubvincentcox/stacoan

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

android-securitymobile-securitystatic-code-analysis+1
8685 years ago
FirmWire preview

FirmWire

GitHubfirmwire/firmwire

FirmWire is a full-system baseband firmware emulation platform for fuzzing, debugging, and root-cause analysis of smartphone baseband firmwares

binary-analysisdebuggersdynamic-analysis-sandboxing+6
8753 years ago
finalrun-agent preview

finalrun-agent

GitHubdroid-ash/finalrun-agent

AI-driven CLI for testing Android and iOS apps using natural language. Generates, runs, and fixes end-to-end tests on emulators/simulators with…

ai-securityandroid-securityeducation+2
30120 days ago
bramble preview

bramble

GitHubflythenimbus/bramble

Offline-first password manager with direct device-to-device sync

authenticationcryptographyencryption-decryption-tools+7
3151 day ago
vendor-android-cves preview

vendor-android-cves

GitHubflankerhqd/vendor-android-cves

Collections of my POCs for android vendor CVEs

android-securitybinary-exploitationexploitation+3
2892 years ago
cve-2015-1538-1 preview

cve-2015-1538-1

GitHubjduck/cve-2015-1538-1

An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution

android-securitybinary-exploitationexploitation+3
20510 years ago
toothpicker preview

toothpicker

GitHubseemoo-lab/toothpicker
bluetooth-securitydynamic-analysis-sandboxingfuzzing+3
2454 years ago
xpfarm preview

xpfarm

GitHubcanuk40/xpfarm

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

ai-securitybinary-analysisexploit-frameworks+7
1944 months ago
MagiskEoP preview

MagiskEoP

GitHubcanyie/magiskeop

Exploit and writeup for installed app to root privilege escalation through CVE-2024-48336 (Magisk Bug #8279), Privileges Escalation / Arbitrary Code…

android-securitybinary-exploitationcode-analysis+5
1991 year ago
whatsapp-mitd-mitm preview

whatsapp-mitd-mitm

GitHubcensus/whatsapp-mitd-mitm

PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)

android-securityexploitationmobile-security+3
1495 years ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubcanyie/cve-2024-0044

RunAsAnyone: PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation…

android-securitybinary-exploitationeducation+5
1801 year ago
android-locdump preview

android-locdump

GitHubpacketlss/android-locdump

android location service cache dumper

android-securitydata-recoverydigital-forensics+4
17913 years ago
CVE-2025-43300 preview

CVE-2025-43300

GitHubhunters-sec/cve-2025-43300

This is POC for IOS 0click CVE-2025-43300

binary-exploitationeducationembedded-systems-security+7
1150 years ago
Previous1…456…8Next