Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
PSCF preview

PSCF

GitHubowasp/pscf

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

curated-resourcesdevsecopseducation+2
28
11 months ago
FIASSE preview

FIASSE

GitHubowasp/fiasse

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

code-analysiscurated-resourcesdevsecops+7
1422 days ago
RiskAssessmentFramework preview
Archived

RiskAssessmentFramework

GitHubowasp/riskassessmentframework

The Secure Coding Framework

code-analysisdevsecopsstatic-code-analysis+1
2726 years ago
Mobile-Security-Framework-MobSF preview

Mobile-Security-Framework-MobSF

GitHubmobsf/mobile-security-framework-mobsf

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

android-securityapi-security-testingdevsecops+8
21.7k17 days ago
React2Shell-Scanner preview

React2Shell-Scanner

GitHubwi3memake/react2shell-scanner

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

api-security-testingdevsecopspenetration-testing+3
318 months ago
HybridTestFramework preview

HybridTestFramework

GitHubdipjyotimetia/hybridtestframework

End to End testing of Web, API, Cloud, Events and Security

api-security-testingcloud-securitycontainer-security+3
1530 years ago
glue preview

glue

GitHubowasp/glue

Application Security Automation

code-analysisdevsecopsvulnerability-scanners
5276 years ago
ftw preview

ftw

GitHubcoreruleset/ftw

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

devsecopspenetration-testingvulnerability-scanners+2
1424 years ago
purpleteam-orchestrator preview
Archived

purpleteam-orchestrator

GitLabpurpleteam-labs/purpleteam-orchestrator

Orchestration component of purpleteam

cloud-securitydevsecopspenetration-testing-frameworks+2
15 years ago
pytm preview

pytm

GitHubowasp/pytm

A Pythonic framework for threat modeling

code-analysisdevsecopseducation+1
1.2k20 days ago
security-culture preview

security-culture

GitHubowasp/security-culture

OWASP Security Culture repository

curated-resourcesdevsecopseducation+2
51 year ago
SecurityRAT preview

SecurityRAT

GitHubsecurityrat/securityrat

OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

devsecops
1911 year ago
KubeLight preview

KubeLight

GitHubowasp/kubelight

OWASP Kubernetes security and compliance tool [WIP]

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
1073 years ago
Teach-AppSec preview

Teach-AppSec

GitHubowasp/teach-appsec

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

devsecopseducationlearning-paths-courses
2 months ago
Astra preview

Astra

GitHubflipkart-incubator/astra

Automated Security Testing For REST API's

api-security-testingdevsecopspenetration-testing+2
2.7k2 years ago
burpa preview

burpa

GitHub0x4d31/burpa

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

api-security-testingdevsecopsvulnerability-scanners+1
5369 years ago
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

api-security-testingcrawlerdevsecops+8
126 days ago
directus-security preview

directus-security

GitHubperufitlife/directus-security

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

api-security-testingcrawlerdevsecops+6
2 months ago
Previous12345Next