Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
61 results
AndroidKernelVulnerability preview

AndroidKernelVulnerability

GitHubsharif-dev/androidkernelvulnerability

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

android-securitybinary-exploitationdynamic-analysis-sandboxing+5
72
3 years ago
sast-scan preview

sast-scan

GitHubshiftleftsecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

cloud-securitycode-analysisconfiguration-auditing+6
8792 years ago
nginx-rift-scanner preview

nginx-rift-scanner

GitHubsimota/nginx-rift-scanner

Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis.…

code-analysisconfiguration-auditingstatic-analysis+3
12 months ago
Limon preview

Limon

GitHubmonnappa22/limon

Automated Linux malware sandbox that performs static, dynamic, and memory analysis to collect runtime indicators and report on process, file system,…

dynamic-analysis-sandboxingmalware-analysismemory-forensics+1
40410 years ago
php-malware-finder preview

php-malware-finder

GitHubnbs-system/php-malware-finder

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

malware-analysisstatic-analysisvulnerability-scanners+1
3434 years ago
recaptcha preview

recaptcha

GitHubelyelysiox/recaptcha

Technical documentation and reverse engineering analysis of Google's reCAPTCHA anti-bot system, covering payload structure, obfuscation techniques,…

anti-botcaptcha-bypassdynamic-code-analysis+3
2391 month ago
AMDH preview

AMDH

GitHuba-yatta/amdh

Automated Android device hardening tool that scans installed apps for malware, audits system settings against CIS benchmarks, revokes dangerous…

android-securityconfiguration-auditingforensics+4
2233 years ago
lfi preview

lfi

GitHublfi-project/lfi

In-process native code sandboxing system using compiler-based fault isolation. Supports Arm64, x86-64, and RISC-V with minimal overhead for…

binary-analysiscode-analysisdynamic-analysis-sandboxing+4
1166 months ago
kin preview

kin

GitHubfirelock-ai/kin

The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…

ai-securitycode-analysiscurated-resources+4
461 day ago
wcw-cyberring-pav-decryptor preview

wcw-cyberring-pav-decryptor

GitHubblakebratcher/wcw-cyberring-pav-decryptor

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

binary-analysiscryptographydata-recovery+5
256 months ago
interactive-binary-structures preview

interactive-binary-structures

GitHubproteqtum/interactive-binary-structures

Interactive documentation and visual reference for binary formats and system memory layouts.

binary-analysiseducationforensics+3
131 month ago
ci-supplychain-guard preview

ci-supplychain-guard

GitHubotsmane-ahmed/ci-supplychain-guard

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

code-analysiscontainer-securitydevsecops+5
286 months ago
pe-signgen preview

pe-signgen

GitHubforentfraps/pe-signgen

Universal signature generation for any system function from all Windows Builds using Winbindex

binary-analysisforensicsmalware-analysis+3
208 months ago
CVE-2025-64459 preview

CVE-2025-64459

GitHubnunpa/cve-2025-64459

Lightweight shell script to detect if a system is running a python-django version vulnerable to CVE-2025-64459, enabling rapid security assessment.

code-analysisstatic-analysisvulnerability-analysis+2
19 months ago
expat_CVE-2024-28757 preview

expat_CVE-2024-28757

GitHubrenukaselvar/expat_cve-2024-28757

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

code-analysisdynamic-analysis-sandboxingexploitation+3
2 years ago
ApplicationInspector preview

ApplicationInspector

GitHubmicrosoft/applicationinspector

Static source code analyzer that identifies software features, APIs, and security characteristics using 400+ regex-based rules. Helps determine what…

code-analysisdevsecopsstatic-analysis+3
4.4k6 days ago
binsync preview

binsync

GitHubbinsync/binsync

A reversing plugin for cross-decompiler collaboration, built on git.

binary-analysisreverse-engineeringstatic-analysis+1
7433 days ago
zeno preview

zeno

GitHubtraxes/zeno

Plugin-based binary analysis framework for automatic discovery of memory corruption vulnerabilities including buffer overflows, integer overflows,…

binary-analysisfuzzingstatic-analysis+1
397 years ago
Previous1234Next