Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
235 results
truegaze preview

truegaze

GitHubnightwatchcybersecurity/truegaze

Static analysis tool for Android/iOS apps focusing on security issues outside the source code

android-securityios-securitymisconfiguration+3
133
5 years ago
paranoid_crypto preview
Archived

paranoid_crypto

GitHubgoogle/paranoid_crypto

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

cryptographypapers-researchstatic-analysis+2
8021 year ago
droidlysis preview

droidlysis

GitHubcryptax/droidlysis

Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

android-securityinformation-gatheringmalware-analysis+3
31229 days ago
jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1 preview

jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1

GitHubshoucheng3/jenkinsci__workflow-cps-plugin_cve-2022-25173_2646-v6ed3b5b01ff1

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

code-analysisdevsecopsdynamic-analysis-sandboxing+3
11 months ago
regenerator2000 preview

regenerator2000

GitHubricardoquesada/regenerator2000

An interactive disassembler for the CPU 6502, focused on Commodore 8-bit computers. Features a TUI with modern features like x-ref, undo/redo, flow…

binary-analysisdebuggerseducation+3
1641 month ago
struts1filter preview

struts1filter

GitHubrgielen/struts1filter

A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team

code-analysisdevsecopsmisconfiguration+3
129 years ago
gef preview

gef

GitHubhugsy/gef

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

ai-assisted-reversingbinary-analysisbinary-exploitation+10
8.4k1 month ago
fastjson-tp1fn1 preview

fastjson-tp1fn1

GitHubscabench/fastjson-tp1fn1

a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used

code-analysiseducationpapers-research+3
2 years ago
sbox preview

sbox

GitHubx86byte/sbox

Compile-time AES string obfuscation for C++

binary-analysiscryptographyencryption-decryption-tools+2
1084 months ago
jenkinsci__script-security-plugin_CVE-2023-24422_1228.vd93135a_2fb_25 preview

jenkinsci__script-security-plugin_CVE-2023-24422_1228.vd93135a_2fb_25

GitHubshoucheng3/jenkinsci__script-security-plugin_cve-2023-24422_1228.vd93135a_2fb_25

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

api-securityauthentication-authorizationcode-analysis+5
1 year ago
testing-handbook preview

testing-handbook

GitHubtrailofbits/testing-handbook

Trail of Bits Testing Handbook - appsec.guide

code-analysiscryptographycurated-resources+9
1361 month ago
Flerken preview

Flerken

GitHubwe5ter/flerken

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

code-analysisdefensive-toolsdynamic-code-analysis+3
1637 years ago
bithoven preview

bithoven

GitHubchrischo-h/bithoven

Bithoven is a smart contract language for composing powerful and secure instruments on Bitcoin. LR(1) parser with static analysis for compile-time…

cryptographystatic-analysis
4310 days ago
xwiki__xwiki-commons_CVE-2023-31126_14-10-3 preview

xwiki__xwiki-commons_CVE-2023-31126_14-10-3

GitHubshoucheng3/xwiki__xwiki-commons_cve-2023-31126_14-10-3

Java library providing technical commons for XWiki projects, with a focus on vulnerability analysis and static code inspection for security testing.

code-analysisgeneral-purpose-utilitiesstatic-analysis+1
11 months ago
jsc_deobfuscator preview

jsc_deobfuscator

GitHubhasherezade/jsc_deobfuscator

Static deobfuscation toolkit for compiled V8 JavaScript bytecode, focusing on JSCeal payloads. Provides pattern-driven filters, control-flow…

binary-analysiseducationmalware-analysis+2
581 day ago
appsec-agent preview

appsec-agent

GitHubowasp/appsec-agent

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

ai-securitycode-analysisdevsecops+5
131 month ago
external_expat_2.1.0_CVE-2022-43680 preview

external_expat_2.1.0_CVE-2022-43680

GitHubnidhihcl/external_expat_2.1.0_cve-2022-43680

C library for stream-oriented XML parsing with a focus on vulnerability analysis and exploitation of CVE-2022-43680, enabling fuzzing and…

binary-analysiscode-analysisexploitation+3
3 years ago
webp_Android10_r33_CVE-2023-1999 preview

webp_Android10_r33_CVE-2023-1999

GitHubpazhanivelmani/webp_android10_r33_cve-2023-1999

Proof-of-concept exploit for CVE-2023-1999 targeting the WebP codec library on Android 10 (r33). Demonstrates a heap buffer overflow vulnerability in…

binary-analysiscode-analysisexploitation+3
1 year ago
Previous1234…14Next