Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
69 results
CICD-Goat-Vapt-Writeup preview

CICD-Goat-Vapt-Writeup

GitHubdheeraj-jayaswal/cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

ctfdevsecopseducation+5
1
1 day ago
studio preview

studio

GitHubshipsecai/studio

Workflow automation for Security Teams

cloud-securitydevsecopseducation+7
3807 months ago
git-all-secrets preview

git-all-secrets

GitHubanshumanbh/git-all-secrets

A tool to capture all the git secrets by leveraging multiple open source git searching tools

code-analysisdevsecopsinformation-gathering+1
1.1k7 years ago
mcp-shark preview

mcp-shark

GitHubmcp-shark/mcp-shark

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

ai-securityapi-securityconfiguration-auditing+7
1795 months ago
CVE-2026-42533-Config-Scanner preview

CVE-2026-42533-Config-Scanner

GitHub0xcyberstan/cve-2026-42533-config-scanner

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

code-analysisconfiguration-auditingdevsecops+4
302 months ago
opencode preview

opencode

GitHubanomalyco/opencode

The open source coding agent.

ai-securitydevsecopseducation+2
210.6k2h 21m ago
webvm preview

webvm

GitHubleaningtech/webvm

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

cloud-securityctfdevsecops+3
17.4k7 days ago
PentestingEverything preview

PentestingEverything

GitHubm14r41/pentestingeverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

api-securitycloud-securityctf+9
2.1k9 days ago
f8x preview

f8x

GitHubffffffff0x/f8x

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

cloud-securityctfdevsecops+7
2.2k2 months ago
terragoat preview

terragoat

GitHubbridgecrewio/terragoat

Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.

cloud-securitydevsecopseducation+2
1.3k3 years ago
CodeAnalysis preview

CodeAnalysis

GitHubtencent/codeanalysis

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

code-analysisdevsecopseducation+3
1.8k10 months ago
pytm preview

pytm

GitHubowasp/pytm

A Pythonic framework for threat modeling

code-analysisdevsecopseducation+1
1.2k1 month ago
cicd-goat preview

cicd-goat

GitHubcider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

ctfdevsecopseducation+3
2.3k2 years ago
SecureCodingDojo preview

SecureCodingDojo

GitHubowasp/securecodingdojo

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

authenticationcode-analysisctf+6
61110 months ago
CyberRange preview

CyberRange

GitHubsecdevops-cuse/cyberrange

The Open-Source AWS Cyber Range

cloud-securitydevsecopseducation+6
4986 years ago
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
7974 months ago
terminal-bench-2 preview

terminal-bench-2

GitHubharbor-framework/terminal-bench-2

Benchmark for evaluating AI agents on real-world tasks including vulnerability resolution, code debugging, and protein assembly in containerized…

ctfdevsecopseducation+5
4165 months ago
JavaSecLab preview

JavaSecLab

GitHubwhgojp/javaseclab

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

code-analysisctfdevsecops+6
8813 months ago
Previous1234Next