Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
446 results
agent-vault preview

agent-vault

GitHubinfisical/agent-vault

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

ai-securityapi-securityauthentication-authorization+3
2.2k
2 days ago
tirreno preview

tirreno

GitHubtirrenotechnologies/tirreno

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

anomaly-detectionanti-botapi-security+3
1.5k20 days ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
9272 months ago
API-Security preview

API-Security

GitHubowasp/api-security

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

api-securitycurated-resourceseducation+3
2.3k8 months ago
kiterunner preview

kiterunner

GitHubassetnote/kiterunner

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

api-securityapi-security-testingdynamic-code-analysis+5
3.3k5 years ago
crAPI preview

crAPI

GitHubowasp/crapi

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

api-securityapi-security-testingeducation+3
1.6k3 months ago
pingap preview

pingap

GitHubvicanso/pingap

A reverse proxy like nginx, built on pingora, simple and efficient.

api-securityauthenticationauthentication-authorization+4
1.4k2 days ago
OpenAM preview

OpenAM

GitHubopenidentityplatform/openam

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

api-securityauthentication-authorizationcloud-security+3
88722 days ago
sandbox-agent preview

sandbox-agent

GitHubrivet-dev/sandbox-agent

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

api-securitycontainer-securitydevsecops+3
1.6k2 months ago
tiny_tracer preview

tiny_tracer

GitHubhasherezade/tiny_tracer

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…

api-securitybinary-analysisdynamic-analysis-sandboxing+2
1.7k3 months ago
cve-mcp-server preview

cve-mcp-server

GitHubmukul975/cve-mcp-server

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

api-securitydevsecopsincident-response+6
1.4k2 months ago
Nest preview

Nest

GitHubowasp/nest

Your gateway to OWASP. Discover, engage, and help shape the future!

api-securitycurated-resourceseducation+2
4431 day ago
reproxy preview

reproxy

GitHubumputun/reproxy

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

api-securityauthentication-authorizationgeneral-purpose-utilities+2
1.3k14 days ago
gotestwaf preview

gotestwaf

GitHubwallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-securityapi-security-testingpenetration-testing+4
1.8k1 year ago
PatrowlManager preview

PatrowlManager

GitHubpatrowl/patrowlmanager

PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

api-securityincident-responsethreat-intelligence+1
6384 years ago
Damn-Vulnerable-GraphQL-Application preview

Damn-Vulnerable-GraphQL-Application

GitHubdolevf/damn-vulnerable-graphql-application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

api-securityapi-security-testingctf+5
1.7k1 year ago
JSAnalyzer preview

JSAnalyzer

GitHubjenish-sojitra/jsanalyzer

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

api-securityemail-harvestinginformation-gathering+4
1.2k7 months ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
53222 days ago
Previous1234…25Next