#1Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.
Kitploit recommended

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
Ghidra is a software reverse engineering (SRE) framework

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Linux kernel source tree

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automatic SQL injection and database takeover tool

Linux operating system for embedded devices with writable filesystem, package management, and build framework. Enables custom firmware creation for…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Pre-Built Vulnerable Environments Based on Docker-Compose

OSS-Fuzz - continuous fuzzing for open source software.

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

The Symfony PHP framework

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open-source IoT Platform - Device management, data collection, processing and visualization.