Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
CVE-2024-32002-POC preview

CVE-2024-32002-POC

GitHubmasamuneee/cve-2024-32002-poc

PoC for CVE-2024-32002: RCE via malicious git submodule hooks on case-insensitive filesystems

educationexploitationpapers-research+2
1 year ago
CVE-2023-38873-G1 preview

CVE-2023-38873-G1

GitHubk9-modz/cve-2023-38873-g1

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

educationexploitationpapers-research+3
1 year ago
zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri preview

zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

GitHubhunt-benito/zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

binary-exploitationeducationembedded-systems-security+5
1 month ago
cve-2026-8697 preview

cve-2026-8697

GitHubitzmetanjim/cve-2026-8697

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

educationexploitationhardware-iot-security+7
13 months ago
MalEval preview

MalEval

GitHubzhengxr930/maleval

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

ai-securityandroid-securitycode-analysis+5
51 month ago
avet preview

avet

GitHubgovolution/avet

AntiVirus Evasion Tool

adversarial-attackeducationencryption-decryption-tools+8
1.8k1 year ago
CVE-2025-48593 preview

CVE-2025-48593

GitHublogesh-git001/cve-2025-48593

"A single malicious packet can own your device." — Android Security Team, Nov 2025

android-securitybluetooth-securityeducation+7
74 months ago
VXUG-Papers preview

VXUG-Papers

GitHubvxunderground/vxug-papers

Research code & papers from members of vx-underground.

curated-resourcesmalware-analysispapers-research+2
1.4k4 years ago
DGA preview

DGA

GitHubandrewaeva/dga

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

dns-analysiseducationmachine-learning+4
2269 years ago
HosTaGe preview

HosTaGe

GitHubaau-network-security/hostage

Low Interaction Mobile Honeypot

android-securitydefensive-toolseducation+5
995 years ago
POC-CVE-2025-24104-Py preview

POC-CVE-2025-24104-Py

GitHubmissaels235/poc-cve-2025-24104-py

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

data-exfiltrationeducationexploitation+4
31 year ago
CVE-2026-63621 preview

CVE-2026-63621

GitHuboscerd/cve-2026-63621

Proof-of-concept reproducers for Apache Camel camel-knative structured CloudEvent header injection (CVE-2026-63621), demonstrating header injection…

educationexploitationpapers-research+2
13 days ago
CVE-2025-55182-research preview

CVE-2025-55182-research

GitHubejpir/cve-2025-55182-research

Technical proof-of-concept and deep-dive analysis of CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol via path traversal, fake…

educationexploitationpapers-research+4
7939 months ago
PrintNightmare preview

PrintNightmare

GitHubjumpseclabs/printnightmare

Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527

educationexploitationforensics+2
195 years ago
CVE-2025-61303 preview

CVE-2025-61303

GitHubegkritsis/cve-2025-61303

Critical Vulnerability (9.8) - RecordedFuture Triage dynamic analysis engine can fail to record malicious behavior when samples produce very…

dynamic-analysis-sandboxingeducationexploitation+3
29 months ago
CVE-2025-31200-iOS-AudioConverter-RCE preview

CVE-2025-31200-iOS-AudioConverter-RCE

GitHubserundengsapi/cve-2025-31200-ios-audioconverter-rce

Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.

educationexploitationios-security+3
21 year ago
CVE-2026-48813-POC preview

CVE-2026-48813-POC

GitHub7alen7/cve-2026-48813-poc

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

educationexploitationpapers-research+2
3 months ago
CVE-2023-21716 preview

CVE-2023-21716

GitHubgyaansastra/cve-2023-21716

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

binary-exploitationeducationexploitation+3
5910 months ago
Previous123Next