Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
244 results
rzweb preview

rzweb

GitHubindalok/rzweb

A complete browser-based reverse engineering platform built on Rizin, running entirely client-side via WebAssembly.

binary-analysisdebuggersdynamic-analysis-sandboxing+5
7621 month ago
log4j-detector preview

log4j-detector

GitHubmergebase/log4j-detector

File-system scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046) by analyzing compiled Java classes, including nested…

static-analysissupply-chain-securityvulnerability-analysis+1
6404 years ago
nCPU preview

nCPU

GitHubrobertcprice/ncpu

Research runtime for differentiable neural computers, GPU-based CPU emulation, and program synthesis. Features neural ALU, constant-time crypto, JEPA…

ai-securitybinary-analysiscryptography+8
6602 months ago
binsync preview

binsync

GitHubbinsync/binsync

A reversing plugin for cross-decompiler collaboration, built on git.

binary-analysisreverse-engineeringstatic-analysis+1
7481 month ago
log4j-finder preview

log4j-finder

GitHubfox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

code-analysisincident-responsestatic-analysis+3
4393 years ago
stringsifter preview

stringsifter

GitHubmandiant/stringsifter

A machine learning tool that ranks strings based on their relevance for malware analysis.

binary-analysismachine-learningmalware-analysis+2
7653 years ago
Limon preview

Limon

GitHubmonnappa22/limon

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

dynamic-analysis-sandboxingmalware-analysismemory-forensics+1
40510 years ago
peframe preview

peframe

GitHubguelfoweb/peframe

PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

forensicsmalware-analysisreverse-engineering+2
6285 years ago
dawnscanner preview

dawnscanner

GitHubthesp0nge/dawnscanner

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

code-analysisstatic-analysisvulnerability-scanners+1
7492 years ago
PortEx preview

PortEx

GitHubstruppigel/portex

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

anomaly-detectionbinary-analysisforensics+3
5386 months ago
aura preview

aura

GitHubsourcecode-ai/aura

Python source code auditing and static analysis on a large scale

code-analysiseducationmalware-analysis+4
4933 years ago
PEpper preview

PEpper

GitHub0x0be/pepper

An open source script to perform malware static analysis on Portable Executable

binary-analysisforensicsmalware-analysis+1
3344 years ago
workshop_firmware_reverse_engineering preview

workshop_firmware_reverse_engineering

GitHubemproof-com/workshop_firmware_reverse_engineering

Workshop on firmware reverse engineering

binary-analysiseducationembedded-systems-security+6
4531 year ago
Vulnhalla preview

Vulnhalla

GitHubcyberark/vulnhalla

Automated security analysis pipeline that runs CodeQL queries on GitHub repositories and uses LLMs to classify and filter true vulnerabilities from…

ai-securitycode-analysisdevsecops+4
2062 months ago
sec-af preview

sec-af

GitHubagent-field/sec-af

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

ai-securitycode-analysisdevsecops+7
1991 month ago
replica preview

replica

GitHubreb311ion/replica

Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions…

binary-analysiscryptographymalware-analysis+2
3146 years ago
Flerken preview

Flerken

GitHubwe5ter/flerken

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

code-analysisdefensive-toolsdynamic-code-analysis+3
1637 years ago
regenerator2000 preview

regenerator2000

GitHubricardoquesada/regenerator2000

An interactive disassembler for the CPU 6502, focused on Commodore 8-bit computers. Features a TUI with modern features like x-ref, undo/redo, flow…

binary-analysisdebuggerseducation+3
1641 month ago
Previous123…14Next