Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-security — A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. | Kitploit
Tools/GitHubGitHub/sbilly/awesome-security
Web SecurityNetwork SecurityMalware AnalysisDigital ForensicsPenetration TestingThreat IntelligencePapers & ResearchLearning & EducationCurated ResourcesLearning Paths & CoursesTop in Curated Resources #7
14.7k2.4k338 months agoReviewed by Kitploit
Top in Learning & Education #7
Top in Learning Paths & Courses #11
GitHubsbilly/awesome-security

awesome-security

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Awesome Security

Awesome

A collection of awesome software, libraries, documents, books, resources and cool stuff about security.

Inspired by awesome-php, awesome-python.

Thanks to all contributors, you're awesome and wouldn't be possible without you! The goal is to build a categorized community-driven collection of very well-known resources.

  • Awesome Security
    • Network
      • Scanning / Pentesting
      • Monitoring / Logging
      • IDS / IPS / Host IDS / Host IPS
      • Honey Pot / Honey Net
      • Full Packet Capture / Forensic
      • Sniffer
      • Security Information & Event Management
      • VPN
      • Fast Packet Processing
      • Firewall
      • Anti-Spam
      • Docker
    • Endpoint
      • Anti-Virus / Anti-Malware
      • Content Disarm & Reconstruct
      • Configuration Management
      • Authentication
      • Mobile / Android / iOS
      • Forensics
    • Threat Intelligence
    • Social Engineering
    • Web
      • Organization
      • Web Application Firewall
      • Scanning / Pentesting
      • Runtime Application Self-Protection
      • Development
    • Red Team Infrastructure Deployment
    • Exploits & Payloads
    • Usability
    • Big Data
    • DevOps
    • Terminal
    • Operating Systems
      • Online resources
    • Datastores
    • Fraud prevention
    • EBooks
    • Other Awesome Lists
      • Other Security Awesome Lists
      • Other Common Awesome Lists
    • Contributing

Network

Network architecture

  • Network-segmentation-cheat-sheet - This project was created to publish the best practices for segmentation of the corporate network of any company. In general, the schemes in this project are suitable for any company.

Scanning / Pentesting

  • OpenVAS - OpenVAS is a framework of several services and tools offering a comprehensive and powerful vulnerability scanning and vulnerability management solution.
  • Metasploit Framework - A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.
  • Kali - Kali Linux is a Debian-derived Linux distribution designed for digital forensics and penetration testing. Kali Linux is preinstalled with numerous penetration-testing programs, including nmap (a port scanner), Wireshark (a packet analyzer), John the Ripper (a password cracker), and Aircrack-ng (a software suite for penetration-testing wireless LANs).
  • tsurugi - heavily customized Linux distribution that designed to support DFIR investigations, malware analysis and OSINT activities. It is based on Ubuntu 20.04(64-bit with a 5.15.12 custom kernel)
  • pig - A Linux packet crafting tool.
  • scapy - Scapy: the python-based interactive packet manipulation program & library.
  • Pompem - Pompem is an open source tool, which is designed to automate the search for exploits in major databases. Developed in Python, has a system of advanced search, thus facilitating the work of pentesters and ethical hackers. In its current version, performs searches in databases: Exploit-db, 1337day, Packetstorm Security...
  • Nmap - Nmap is a free and open source utility for network discovery and security auditing.
  • Amass - Amass performs DNS subdomain enumeration by scraping the largest number of disparate data sources, recursive brute forcing, crawling of web archives, permuting and altering names, reverse DNS sweeping and other techniques.
  • Anevicon - The most powerful UDP-based load generator, written in Rust.
  • Finshir - A coroutines-driven Low & Slow traffic generator, written in Rust.
  • Legion - Open source semi-automated discovery and reconnaissance network penetration testing framework.
  • Lonkero - Enterprise-grade web vulnerability scanner with 60+ attack modules, built in Rust for penetration testing and security assessments.
  • Sublist3r - Fast subdomains enumeration tool for penetration testers
  • RustScan - Faster Nmap scanning with Rust. Take a 17 minute Nmap scan down to 19 seconds.
  • Boofuzz - Fuzzing engine and fuzz testing framework.
  • monsoon - Very flexible and fast interactive HTTP enumeration/fuzzing.
  • Netz- Discover internet-wide misconfigurations, using zgrab2 and others.
  • Deepfence ThreatMapper - Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless.
  • Deepfence SecretScanner - Find secrets and passwords in container images and file systems.
  • Cognito Scanner - CLI tool to pentest Cognito AWS instance. It implements three attacks: unwanted account creation, account oracle and identity pool escalation
Download Tool