Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
302 results
Nginx-chain-Rift-Poolslip preview

Nginx-chain-Rift-Poolslip

GitHuby198nt/nginx-chain-rift-poolslip

ASLR-independent nginx RCE chain PoC combining the PoolSlip heap over-read leak (CVE-2026-9256) with the rift overflow (CVE-2026-42945) to reach…

binary-exploitationeducationexploitation+7
14
4 months ago
cve-2026-28912 preview

cve-2026-28912

GitHubjvidhan/cve-2026-28912

Reverse engineering notes and a working PoC for the macOS PackageKit symlink-following bug (CVE-2026-28912), with disassembly diff of the 26.6 fix.

binary-analysiseducationexploitation+5
17 days ago
Relapse-Exploit preview

Relapse-Exploit

GitHubntfargo/relapse-exploit

PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

binary-exploitationeducationexploitation+5
8326 days ago
CVE-2026-43786 preview

CVE-2026-43786

GitHub0xblackash/cve-2026-43786

Documentation and research notes for CVE-2026-43786, a macOS local privilege-escalation flaw caused by improper entitlement validation, covering root…

binary-analysiseducationexploitation+4
27 days ago
ReflectivePluginLoader preview

ReflectivePluginLoader

GitHubracoten/reflectivepluginloader

A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

binary-exploitationdefensive-toolseducation+7
4721 days ago
cve-2026-43687 preview

cve-2026-43687

GitHubjvidhan/cve-2026-43687

Reverse engineering notes and a self-contained PoC for the macOS NFS client access-cache race (CVE-2026-43687), with kext disassembly diff and dtrace…

binary-analysiseducationexploitation+4
10 days ago
PixelSmash preview

PixelSmash

GitHubse1ims/pixelsmash

Proof-of-concept and lab harness for CVE-2026-8461, an out-of-bounds write in FFmpeg's MagicYUV decoder, with payload generator and Qt demo player.

binary-exploitationeducationexploitation+6
11 days ago
malware-analysis-fake-hwmonitor preview

malware-analysis-fake-hwmonitor

GitHubdmitry-matvienko/malware-analysis-fake-hwmonitor

Technical analysis, writeup, and YARA rules for a DLL Sideloading campaign disguised as HWMonitor

defensive-toolsdigital-forensicseducation+6
13 days ago
CVE-2020-15368-AsrDrv103-research preview

CVE-2020-15368-AsrDrv103-research

GitHubegorrsp/cve-2020-15368-asrdrv103-research

Reverse engineering research of ASRock AsrDrv103.sys (CVE-2020-15368), covering its driver interface, encrypted request protocol, and privileged…

binary-analysiseducationhardware-security+4
612 days ago
CVE-2026-87902-Toolkit preview

CVE-2026-87902-Toolkit

GitHubtc4dy/cve-2026-87902-toolkit

WordPress CVE-2026-87902 LFI-to-RCE toolkit with a weaponized exploit chain (PEAR RCE, webshell, admin creation, loot) and a non-intrusive…

defensive-toolseducationexploitation+8
108 days ago
recurse preview

recurse

GitHubrecurse-labs/recurse

Agentic reverse engineering IDE with a pure-Rust multi-architecture disassembler, native decompiler, debugger, and LLM agent for binary analysis and…

ai-assisted-reversingai-securitybinary-analysis+7
2845 days ago
CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM- preview

CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM-

GitHubg4sp4rcs/cve-2019-11707-from-an-ionmonkey-type-confusion-to-system-

Windows proof-of-concept exploit chain for CVE-2019-11707, a Firefox IonMonkey type confusion, combining browser RCE with sandbox escape to achieve…

binary-exploitationeducationexploitation+6
7 days ago
autofs-cve-2026-84568 preview

autofs-cve-2026-84568

GitHubjvidhan/autofs-cve-2026-84568

Reverse engineering notes and working PoC for CVE-2026-84568, a macOS automountd trust-boundary violation allowing mounts from localhost or the…

binary-analysiseducationexploitation+4
114 days ago
CVE-2026-68121 preview

CVE-2026-68121

GitHub0xblackash/cve-2026-68121

Research repository for CVE-2026-68121, a Linux kernel PPPoE use-after-free in pppoe_sendmsg() enabling local privilege escalation, with PoC,…

binary-exploitationeducationexploitation+6
7 days ago
CVE-2026-81000 preview

CVE-2026-81000

GitHub0xblackash/cve-2026-81000

Research repository for CVE-2026-81000 (TUNderflow), a Linux kernel TUN/TAP receive headroom integer underflow enabling local privilege escalation,…

binary-exploitationeducationexploitation+6
7 days ago
Veridiff preview

Veridiff

GitHubveridiff/veridiff

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

binary-analysisbinary-exploitationcode-analysis+7
64 days ago
ios.CVE-2026-84616-84607 preview

ios.CVE-2026-84616-84607

GitHubping-2o/ios.cve-2026-84616-84607

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

binary-analysiseducationexploitation+6
1119 days ago
CVE-2025-5548-FreeFloat-FTP-Lab preview

CVE-2025-5548-FreeFloat-FTP-Lab

GitHubm4rc0s-s3c/cve-2025-5548-freefloat-ftp-lab

Laboratorio académico de análisis y explotación de CVE-2025-5548 en FreeFloat FTP Server 1.0.

binary-exploitationctfdebuggers+6
20 days ago
Previous12…17Next