Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
84 results
TheLastBundleMismatch preview

TheLastBundleMismatch

GitHubmichalbednarski/thelastbundlemismatch

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

android-securitybinary-analysisexploitation+2
101
2 years ago
cisco_asa_research preview

cisco_asa_research

GitHubjbaines-r7/cisco_asa_research

Cisco ASA Software and ASDM Security Research

exploitationexploit-frameworksinformation-gathering+7
884 years ago
CVE-2023-35671 preview

CVE-2023-35671

GitHubmrtiz/cve-2023-35671

Android App Pin Security Issue Allowing Unauthorized Payments via Google Wallet

android-securityeducationexploitation+3
752 months ago
inside-pegasus preview

inside-pegasus

GitHubamnestytech/inside-pegasus

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

android-securitycurated-resourceseducation+6
582 months ago
slides preview

slides

GitHubthomasking2014/slides

Curated collection of security conference slide decks covering Android rooting, kernel exploitation, browser memory corruption, JIT mitigations, and…

android-securitybinary-exploitationcurated-resources+4
658 months ago
rasputin preview

rasputin

GitHubfrenchyeti/rasputin

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

android-securitybinary-analysiscurated-resources+4
623 years ago
agentsid-scanner preview

agentsid-scanner

GitHubagentsid-dev/agentsid-scanner

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

ai-securityapi-security-testingauthentication+7
255 months ago
CVE-2022-20474 preview

CVE-2022-20474

GitHubcxxsheng/cve-2022-20474

Detailed technical analysis and proof-of-concept for Android CVE-2022-20474, a Bundle mismatch vulnerability exploiting LazyValue with negative…

android-securitybinary-exploitationeducation+3
211 year ago
CyberMeowfiaNS preview

CyberMeowfiaNS

GitHubxingchenrs/cybermeowfians

The next stage of CyberMeowfil (CVE-2026-43499 and 43074),Possibly biased toward vivo devices?

android-securitybinary-analysiscurated-resources+4
61 month ago
MalEval preview

MalEval

GitHubzhengxr930/maleval

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

ai-securityandroid-securitycode-analysis+5
52 months ago
ghostlock-kit preview

ghostlock-kit

GitHubzhubaohe123/ghostlock-kit

One-click root kit for vivo iQOO Neo9S Pro (MT6989) exploiting CVE-2026-43499 futex PI UAF via MCAST transport, with scripts and analysis docs.

android-securitybinary-exploitationexploitation+7
514 days ago
Awesome-MoAI-Security preview

Awesome-MoAI-Security

GitHubjinxhy/awesome-moai-security

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

adversarial-attackai-securityandroid-security+9
61 month ago
cve-2026-43499-aak-an00 preview

cve-2026-43499-aak-an00

GitHubhui191/cve-2026-43499-aak-an00

Honor WIN RT (AAK-AN00) CVE-2026-43499 temporary root - research notes

android-securitybinary-exploitationexploitation+6
312 days ago
CVE-2026-43499-S24U preview

CVE-2026-43499-S24U

GitHubfusiondrive/cve-2026-43499-s24u

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (COMPLETED)

android-securitybinary-exploitationexploitation+5
41 month ago
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day preview

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

android-securityeducationexploitation+7
39 days ago
CVE-2025-48593 preview

CVE-2025-48593

GitHublogesh-git001/cve-2025-48593

"A single malicious packet can own your device." — Android Security Team, Nov 2025

android-securitybluetooth-securityeducation+7
75 months ago
NoFrak preview

NoFrak

GitHubgeorgiev-martin/nofrak

Proof Of Concept for Android. NoFrak is designed to prevent fracking attacks, as described in "Breaking and Fixing Origin-Based Access Control in…

android-securitydefensive-toolsmobile-security+2
1012 years ago
zenfone9-root preview

zenfone9-root

GitHubramenfast/zenfone9-root

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

android-securitybinary-exploitationexploitation+7
29 days ago
Previous12345Next