Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
FLAWED preview

FLAWED

GitHuboff-by-1-labs/flawed

Fix-Like Artifacts With Embedded Defects

ai-securitycode-analysisdefensive-tools+8
241 month ago
ghost-hoock preview

ghost-hoock

GitHubdeaurity/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
18 days ago
ghost-hoock preview

ghost-hoock

GitHubgenksome/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
39 days ago
CVE-2026-28576-poc preview

CVE-2026-28576-poc

GitHubmobilehackinglab/cve-2026-28576-poc

Educational proof-of-concept demonstrating a SQL injection vulnerability in Android 17's Contacts Provider, allowing a zero-permission app to…

android-securityeducationexploitation+4
3816 days ago
CVE-2026-28956-jxl-messages-surface preview

CVE-2026-28956-jxl-messages-surface

GitHubeddinos2/cve-2026-28956-jxl-messages-surface

iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.

exploitationios-securitymalware-analysis+3
18 days ago
TheLastBundleMismatch preview

TheLastBundleMismatch

GitHubmichalbednarski/thelastbundlemismatch

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

android-securitybinary-analysisexploitation+2
1012 years ago
ResourcePoison preview

ResourcePoison

GitHubmichalbednarski/resourcepoison

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

android-securityexploitationmobile-security+3
10711 months ago
patch-diffing-in-the-dark preview

patch-diffing-in-the-dark

GitHubvulnerabilityresearchcentre/patch-diffing-in-the-dark

Leveraging patch diffing to discover new vulnerabilities

binary-analysisbinary-exploitationeducation+3
1441 year ago
onelogon preview

onelogon

GitHubrub-softsec/onelogon

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

authenticationexploitationnetwork-security+4
12622 days ago
CVE-2026-63030-Wp2Shell preview

CVE-2026-63030-Wp2Shell

GitHubghostinexile/cve-2026-63030-wp2shell

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

code-analysiseducationexploitation+3
42 months ago
CVE-2021-41081 preview

CVE-2021-41081

GitHubsudaiv/cve-2021-41081

N-DAY VULNERABILITY RESEARCH (FROM PATCH TO EXPLOIT ANALYSIS OF CVE-2021-41081)

binary-analysiseducationexploitation+2
4 years ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubcanyie/cve-2024-0044

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

android-securitybinary-exploitationeducation+5
1801 year ago
CVE-2025-60719-AFD.SYS preview

CVE-2025-60719-AFD.SYS

GitHubakamai/cve-2025-60719-afd.sys

Proof-of-concept and root-cause analysis of CVE-2025-60719, a use-after-free vulnerability in Windows afd.sys leading to local privilege escalation,…

ai-assisted-reversingbinary-exploitationeducation+3
49 months ago