Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
624 results
Chimay-Red preview

Chimay-Red

GitHubbignerd95/chimay-red

Working POC of Mikrotik exploit from Vault 7 CIA Leaks

binary-exploitationembedded-systems-securityexploitation+8
6684 years ago
SimpleVisor preview

SimpleVisor

GitHubionescu007/simplevisor

Minimal Intel VT-x hypervisor for Windows and UEFI that virtualizes a live host for introspection, supporting dynamic hyperjacking, unhyperjacking,…

binary-analysiseducationhardware-security+4
2.0k2 years ago
javascript-deobfuscator preview

javascript-deobfuscator

GitHublolcaken/javascript-deobfuscator

Deobfuscator for javascript-obfuscator 5.x output (string arrays, control-flow flattening, self-defending, RC4/base64)

code-analysisdynamic-code-analysismalware-analysis+4
22 days ago
BinDiffHelper preview

BinDiffHelper

GitHububfx/bindiffhelper

Ghidra Extension to integrate BinDiff for function matching

binary-analysisbinary-exploitationcode-analysis+4
29625 days ago
kli-ex preview

kli-ex

GitHubgmh5225/kli-ex

Extended kernel lazy importer for Windows drivers that resolves APIs at runtime with encrypted, cached import names to hide kernel function usage…

binary-analysiscryptographydefensive-tools+4
343 years ago
Python-Shellcode-Anydesk-Apc-injection-Remote-IP-Address-Analysis preview

Python-Shellcode-Anydesk-Apc-injection-Remote-IP-Address-Analysis

GitHubkaandemir993/python-shellcode-anydesk-apc-injection-remote-ip-address-analysis

Reverse engineering write-up of Python shellcode that APC-injects into AnyDesk, exfiltrates to a C2 over HTTPS with AES/RSA, and persists via…

binary-analysiscommand-and-controldata-exfiltration+7
13 days ago
static-arm-bins preview

static-arm-bins

GitHubtherealsaumil/static-arm-bins

Statically compiled ARM binaries for debugging and runtime analysis

binary-analysisdebuggersdynamic-analysis-sandboxing+6
5285 years ago
jscd preview

jscd

GitHubejfkdev/jscd

Reverse bytenode .jsc (V8 code cache) to JavaScript — static, pure Rust, no patched V8/Node. Node 8→26 / V8 5.8–14.6; 25k .jsc tested, 0 fail.

binary-analysiscode-analysisdynamic-code-analysis+4
3 days ago
Nginx-chain-Rift-Poolslip preview

Nginx-chain-Rift-Poolslip

GitHuby198nt/nginx-chain-rift-poolslip

ASLR-independent nginx RCE chain PoC combining the PoolSlip heap over-read leak (CVE-2026-9256) with the rift overflow (CVE-2026-42945) to reach…

binary-exploitationeducationexploitation+7
144 months ago
ASC preview

ASC

GitHubmg1937/asc

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

android-securitybinary-analysiscode-analysis+6
2.1k8 days ago
seetong-ts81xxd3x-rce preview

seetong-ts81xxd3x-rce

GitHubheapframe/seetong-ts81xxd3x-rce

CVE-2026-100886 | Unauthenticated Remote Code Execution toolkit.

binary-analysisembedded-systems-securityexploitation+6
10 days ago
cve-2026-1668-poc preview

cve-2026-1668-poc

GitHubwuyou6956-glitch/cve-2026-1668-poc

Proof-of-concept exploit for CVE-2026-1668 in TP-Link switch firmware, delivering a MIPS payload that yields a root shell on vulnerable devices.

binary-exploitationembedded-systems-securityexploitation+6
8 days ago
ghostlock-app preview

ghostlock-app

GitHubariyanpegu/ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

android-securitybinary-analysisbinary-exploitation+8
15 days ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubyym8538/cve-2026-33017

Proof-of-concept exploit for CVE-2026-33017, an unauthenticated RCE in Langflow's build_public_tmp endpoint, injecting a malicious custom component…

ai-securityexploitationpayload-development+6
11 month ago
libheif-grid-nextjs-rce preview

libheif-grid-nextjs-rce

GitHubfortbridge-uk/libheif-grid-nextjs-rce

Private Fortbridge PoC for the CVE-2026-32740 Next.js/sharp leak-to-memcpy-GOT RCE chain

binary-exploitationexploitationlabs-practice+6
111 days ago
FUD-C2-Framework preview

FUD-C2-Framework

GitHubx3r0day/fud-c2-framework

A fileless reverse shell and C2 framework leveraging direct syscalls, proxy tunneling, and ChaCha20 encryption for AV evasion.

command-and-controlencryption-decryption-toolsids-ips-evasion+9
75 months ago
ICALL-GADGET preview

ICALL-GADGET

GitHubgmh5225/icall-gadget

Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

binary-exploitationexploitationids-ips-evasion+5
12 years ago
ida-claude-code-plugins preview

ida-claude-code-plugins

GitHubgmh5225/ida-claude-code-plugins

Plugins integrating Claude Code with IDA Pro to assist reverse engineering and binary analysis workflows through AI-driven disassembly and code…

ai-assisted-reversingai-securitybinary-analysis+5
29 months ago
Previous12…35Next