Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
284 results
riscy-business preview

riscy-business

GitHubthesecretclub/riscy-business

RISC-V Virtual Machine

payload-developmentreverse-engineeringsecurity-virtualization
2981 year ago
ditto preview

ditto

GitHubairbus-cert/ditto

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

code-analysismalware-analysispayload-development+2
4021 days ago
SnatchBox preview

SnatchBox

GitHubliji32/snatchbox

SnatchBox (CVE-2020-27935) is a sandbox escape vulnerability and exploit affecting macOS up to version 10.15.x

binary-exploitationexploitationpayload-development+2
325 years ago
CVE-2017-3000 preview

CVE-2017-3000

GitHubdangokyo/cve-2017-3000

A full exploit of CVE-2017-3000 on Flash Player Constant Blinding PRNG

binary-exploitationexploitationpayload-development+2
108 years ago
CVE-2026-15718-who-put-ptrs-in-my-wasm preview

CVE-2026-15718-who-put-ptrs-in-my-wasm

GitHubsneakynachos/cve-2026-15718-who-put-ptrs-in-my-wasm

PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary…

binary-exploitationexploitationpayload-development+3
122 days ago
cve-2025-9951-ffmpeg-jp2-poc preview

cve-2025-9951-ffmpeg-jp2-poc

GitHubfm0ss/cve-2025-9951-ffmpeg-jp2-poc

Proof-of-concept for CVE-2025-9951 demonstrating controlled callback execution in FFmpeg via JPEG 2000 component-mapping mismatch. Includes write-up,…

binary-exploitationexploitationfuzzing+3
1 month ago
pyshell2bin preview

pyshell2bin

GitHubelevenpaths/pyshell2bin

pyshell2bin

binary-analysisexploitationpayload-development+2
36 years ago
cargo-perm preview

cargo-perm

GitHublucas-cauhe/cargo-perm

Cargo exploit from CVE-2023-38497

code-analysisexploitationpayload-development+3
13 years ago
exploit-starcraft-rop-virtualalloc-EUD preview

exploit-starcraft-rop-virtualalloc-EUD

GitHubspiralbl0ck/exploit-starcraft-rop-virtualalloc-eud
binary-exploitationexploitationpayload-development+2
4 years ago
libpeconv preview

libpeconv

GitHubhasherezade/libpeconv

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

binary-analysismalware-analysismemory-forensics+4
1.4k5 months ago
barf-project preview

barf-project

GitHubprograma-stic/barf-project

BARF : A multiplatform open source Binary Analysis and Reverse engineering Framework

binary-analysisdynamic-analysis-sandboxingeducation+5
1.5k6 years ago
Advanced-Loader-Reverse-Engineering preview

Advanced-Loader-Reverse-Engineering

GitHubkaandemir993/advanced-loader-reverse-engineering

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

binary-analysiscode-analysiseducation+8
142 months ago
javascript-obfuscator preview

javascript-obfuscator

GitHubjavascript-obfuscator/javascript-obfuscator

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

code-analysiscryptographydefensive-tools+3
16.2k7 days ago
defcon33_silence_kill_edr preview

defcon33_silence_kill_edr

GitHubarosenmund/defcon33_silence_kill_edr

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

adversarial-attackeducationlabs-practice+6
3491 year ago
VehApiResolve preview

VehApiResolve

GitHubrad9800/vehapiresolve

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

adversarial-attackpayload-developmentred-teaming
1184 years ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubsudoand3rs0n/cve-2025-5548

Educational repository documenting the analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server buffer overflow). Includes a reusable…

binary-exploitationdebuggerseducation+8
1 month ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubjgs-developer/cve-2025-5548

Stack-based buffer overflow exploit for FreeFloat FTP Server, demonstrating reverse engineering, EIP control, and shellcode execution for educational…

binary-exploitationeducationexploitation+5
6 months ago
patching preview

patching

GitHubgaasedelen/patching

An Interactive Binary Patching Plugin for IDA Pro

binary-analysisbinary-exploitationdebuggers+8
1.3k1 year ago
Previous12…16Next