Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

code-analysisconfiguration-auditingdefensive-tools+4
9
1 year ago
SmartScanner-Source preview

SmartScanner-Source

GitHubfauxrougee/smartscanner-source

Web vulnerability scanner built with C++17 and Qt 6, featuring a GUI, CLI, configurable crawling, and JSON reports. Reconstructed for educational…

configuration-auditingcrawlereducation+7
118 days ago
ipaforge preview

ipaforge

GitHubvighnesh91/ipaforge

Dependency-free Python CLI to unpack, inspect, edit, and rebuild iOS .ipa archives, converting plists and strings to XML while preserving Mach-O…

binary-analysiscode-analysisios-security+6
119 days ago
Vulnerability-DLink-CVE-2025-14659 preview

Vulnerability-DLink-CVE-2025-14659

GitHubpeterlinccl/vulnerability-dlink-cve-2025-14659

Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in…

embedded-systems-securityexploitationfirmware-analysis+6
22 days ago
wheelaudit preview

wheelaudit

GitHubkriskimmerle/wheelaudit

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

code-analysisconfiguration-auditingdevsecops+5
37 months ago
class-dump preview

class-dump

GitHubnygard/class-dump

Generate Objective-C headers from Mach-O files.

binary-analysisios-securityreverse-engineering+1
3.6k7 years ago
AgentTesla-Config-Extractor preview

AgentTesla-Config-Extractor

GitHubembee-research/agenttesla-config-extractor

Config extractor for AgentTesla - Discord/Telegram Variant

binary-analysiscommand-and-controlioc-management+4
33 years ago
machofile preview

machofile

GitHubpstirparo/machofile

machofile is a module to parse Mach-O binary files

binary-analysisforensicsmalware-analysis+2
997 months ago
CVE-2026-67595 preview

CVE-2026-67595

GitHubilhomjonr/cve-2026-67595

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

command-and-controlmalware-analysisstatic-analysis+4
1 month ago
jsluice preview

jsluice

GitHubbishopfox/jsluice

Extract URLs, paths, secrets, and other interesting bits from JavaScript

code-analysisinformation-gatheringpenetration-testing+3
1.9k2 years ago
mtk_bp preview

mtk_bp

GitHubnccgroup/mtk_bp

Tools for analyzing and reverse engineering MediaTek baseband firmware, including file extraction, symbol parsing, and Ghidra integration for modem…

binary-analysisembedded-systems-securityfirmware-analysis+4
814 months ago
cwe-tool preview

cwe-tool

GitHubowasp/cwe-tool

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

code-analysiscurated-resourceseducation+3
655 months ago
Cheshire preview

Cheshire

GitHubblacksnufkin/cheshire

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

command-and-controldynamic-analysis-sandboxingexploit-frameworks+4
665 months ago
pyghidra-mcp preview

pyghidra-mcp

GitHubclearbluejar/pyghidra-mcp

Python Command-Line Ghidra MCP

ai-assisted-reversingbinary-analysiscode-analysis+7
43210 days ago
CVE-2022-1292 preview

CVE-2022-1292

GitHubrama291041610/cve-2022-1292

CVE-2022-1292 OpenSSL c_rehash Vulnerability

code-analysiscommand-and-controlexploitation+2
54 years ago
whitesource__curekit_CVE-2022-23082_1-1-3 preview

whitesource__curekit_CVE-2022-23082_1-1-3

GitHubshoucheng3/whitesource__curekit_cve-2022-23082_1-1-3

Java security library providing contextual encoders and sanitizers to automatically remediate vulnerabilities like XSS, path traversal, and command…

code-analysisdevsecopsencryption-decryption-tools+3
1 year ago
mcp-server-attestation preview

mcp-server-attestation

GitHubstudiomeyer-io/mcp-server-attestation

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

code-analysiscommand-and-controlcryptography+3
6 days ago
gef preview

gef

GitHubhugsy/gef

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

ai-assisted-reversingbinary-analysisbinary-exploitation+10
8.4k1 month ago
Previous123Next