Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
1day-archive preview

1day-archive

GitHub1dayexploit/1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

binary-analysiscurated-resourceseducation+5
29
8 days ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

cloud-securityctfcurated-resources+10
27.0k1 month ago
LFISuite preview

LFISuite

GitHubd35m0nd142/lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

exploitationpayload-generationpenetration-testing+3
2.0k8 years ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
11.3k22 days ago
android-reverse-engineering-skill preview

android-reverse-engineering-skill

GitHubsimoneavogadro/android-reverse-engineering-skill

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

android-securityapi-security-testingbinary-analysis+8
7.2k2 months ago
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

binary-exploitationcurated-resourceseducation+9
3.9k7 months ago
Inspeckage preview

Inspeckage

GitHubac-pm/inspeckage

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

android-securityapi-security-testingdynamic-analysis-sandboxing+2
3.0k8 years ago
InjuredAndroid preview
Archived

InjuredAndroid

GitHubb3nac/injuredandroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

android-securityctfeducation+5
7635 years ago
pwn2own2018 preview

pwn2own2018

GitHubsaelo/pwn2own2018

Exploit chain for Safari + macOS exploiting JIT type confusion, launchd sandbox escape, and XNU IPC MitM for kernel code execution.

binary-exploitationeducationexploitation+5
7597 years ago
PwnAdventure3 preview

PwnAdventure3

GitHubliveoverflow/pwnadventure3

Intentionally vulnerable open-world MMORPG server for practicing binary exploitation, reverse engineering, network protocol analysis, and web…

binary-exploitationctfeducation+5
6837 years ago
NtTrace preview

NtTrace

GitHubrogerorr/nttrace

An strace-like program for the Windows 'native' API

api-security-testingdebuggersdynamic-code-analysis+2
3881 month ago
pwn-hisilicon-dvr preview

pwn-hisilicon-dvr

GitHubtothi/pwn-hisilicon-dvr

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

binary-analysisembedded-systems-securityexploitation+8
3833 years ago
sagemcom-fast-3890-exploit preview

sagemcom-fast-3890-exploit

GitHublyrebirds/sagemcom-fast-3890-exploit

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

binary-exploitationembedded-systems-securityexploitation+4
2246 years ago
CVE-2016-6366 preview

CVE-2016-6366

GitHubrisksense-ops/cve-2016-6366

Public repository for improvements to the EXTRABACON exploit

binary-analysisexploitationexploit-frameworks+8
1639 years ago
GWTMap preview

GWTMap

GitHubreverseclabs/gwtmap

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.

information-gatheringpenetration-testingreverse-engineering+2
1141 year ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

android-securityauthenticationcryptography+8
1011 year ago
maps_scanner preview

maps_scanner

GitHubhackinglz/maps_scanner

MAPS cloud scanner and response parser for Microsoft Defender research.

api-security-testingdynamic-analysis-sandboxingfuzzing+6
946 months ago
CVE-2024-21633 preview

CVE-2024-21633

GitHub0x33c0unt/cve-2024-21633

Proof-of-concept exploit for CVE-2024-21633 demonstrating remote code execution in MobSF by abusing apktool arbitrary file write to overwrite a…

android-securitybinary-exploitationexploitation+5
792 years ago
Previous123Next