Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
fuzzilli preview

fuzzilli

GitHubgoogleprojectzero/fuzzilli

Coverage-guided fuzzer for JavaScript engines using a custom intermediate language (FuzzIL) to mutate and generate semantically valid programs,…

binary-analysiseducationfuzzing+2
2.3k
4 days ago
CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field preview

CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field

GitHubtheopaid/cve-2026-66748-camaleon-cms---authenticated-rce-via-select_eval-custom-field

Python exploit script and advisory for CVE-2026-66748: authenticated RCE in Camaleon CMS via select_eval custom field, with root cause analysis and…

code-analysisexploitationpapers-research+4
27 days ago
sjcam preview

sjcam

GitHubkeowu/sjcam

Reverse engineering research and custom firmware for Allwinner V3-based IoT cameras, including firmware parsers, an AVIOCTRL client, and a…

educationembedded-systems-securityexploitation+7
81 month ago
Logitech-G-Cloud-GhostLock-CVE-2026-43499 preview

Logitech-G-Cloud-GhostLock-CVE-2026-43499

GitHubhycqaq/logitech-g-cloud-ghostlock-cve-2026-43499

Kernel exploit for CVE-2026-43499 (GhostLock) targeting Logitech G Cloud (Snapdragon 720G). Includes futex PI race trigger, KASLR bypass via…

binary-exploitationeducationexploitation+4
11 month ago
it-sec-toolshell preview

it-sec-toolshell

GitHubdoerrdan/it-sec-toolshell

Marp slide deck detailing CVE-2025-53770, a SharePoint zero-day vulnerability, with modular slides, custom themes, and build scripts for HTML, PDF,…

curated-resourceseducationpapers-research+2
2 months ago
datadome-vm-internals preview

datadome-vm-internals

GitHubmanjustice/datadome-vm-internals

Analysis of DataDome's custom obfuscated VM and bytecode format, revealing string encryption, S-box ciphers, and browser fingerprinting signals for…

anti-botbinary-analysiseducation+3
274 months ago
btrfs_fixes preview

btrfs_fixes

GitHubmsedek/btrfs_fixes

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

data-recoveryeducationforensics+2
94 months ago
DesckVB-RAT preview

DesckVB-RAT

GitHubshadowopcode/desckvb-rat

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

command-and-controldigital-forensicseducation+8
96 months ago
zirgen preview

zirgen

GitHubrisc0/zirgen

Domain-specific language compiler for creating arithmetic circuits targeting the RISC Zero zero-knowledge proof system, enabling custom accelerators…

cryptographyeducationpapers-research+1
1287 months ago
CVE-2025-55182-POC-SCANNER preview

CVE-2025-55182-POC-SCANNER

GitHubim-hanzou/cve-2025-55182-poc-scanner

Python-based scanner for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Features vulnerability detection, gadget discovery, and…

educationexploitationpapers-research+6
8 months ago
VMDragonSlayer preview

VMDragonSlayer

GitHubpoppopjmp/vmdragonslayer

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

binary-analysisdebuggersdynamic-analysis-sandboxing+8
43110 months ago
Bad_Hoist-WriteUp preview

Bad_Hoist-WriteUp

GitHuba0zhar/bad_hoist-writeup

A Writeup for Sleirsgoevy's version of the Exploit Implementation of CVE-2018-4386 by Fire30 called Bad_Hoist

binary-exploitationeducationexploitation+3
1 year ago
NSEC3-Encloser-Attack preview

NSEC3-Encloser-Attack

GitHubgoethe-universitat-cybersecurity/nsec3-encloser-attack

This project generates DNS zonefiles with custom NSEC3 parameters to reproduce and evaluate the attacks in CVE-2023-50868.

dns-analysisdns-fuzzingeducation+3
62 years ago
CVE-2018-4416-exploit preview

CVE-2018-4416-exploit

GitHuberupmi/cve-2018-4416-exploit

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

binary-exploitationeducationexploitation+4
102 years ago