Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
219 results
agent-governance-toolkit preview

agent-governance-toolkit

GitHubmicrosoft/agent-governance-toolkit

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

ai-securitycurated-resourcesdevsecops+2
6.0k
5h 55m ago
appsec-agent preview

appsec-agent

GitHubowasp/appsec-agent

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

ai-securitycode-analysisdevsecops+5
86h 5m ago
OWASP-Subtractive-Hardening-Top-10 preview

OWASP-Subtractive-Hardening-Top-10

GitHubowasp/owasp-subtractive-hardening-top-10

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

ai-securitycloud-securitycontainer-security+6
219h 57m ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

api-securitycloud-securitydefensive-tools+5
1.6k10h 57m ago
pytm preview

pytm

GitHubowasp/pytm

A Pythonic framework for threat modeling

code-analysisdevsecopseducation+1
1.2k12h 23m ago
cornucopia preview

cornucopia

GitHubowasp/cornucopia

The source files and tools needed to build the OWASP Cornucopia decks in various languages

ai-securitycloud-securityeducation+2
14213h 2m ago
CyberStrike preview

CyberStrike

GitHubcyberstrikeus/cyberstrike

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

ai-securitycloud-securityeducation+9
1.9k13h 27m ago
cve-lite-cli preview

cve-lite-cli

GitHubowasp/cve-lite-cli

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

code-analysiscurated-resourcesdevsecops+5
67013h 30m ago
wstg preview

wstg

GitHubowasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

educationpenetration-testingvulnerability-analysis+1
9.7k13h 35m ago
owasp-scs preview

owasp-scs

GitHubowasp/owasp-scs

OWASP Smart Contract Security (SCS) Project

code-analysiscurated-resourceseducation+5
5314h 29m ago
OCSD preview

OCSD

GitHubowasp/ocsd

OWASP Certified Secure-Software Developer

code-analysiseducationlearning-paths-courses+2
3416h 40m ago
PwnzzAI preview

PwnzzAI

GitHubowasp/pwnzzai
ai-securityctfcurated-resources+6
6321h 38m ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
32.9k2 days ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.7k2 days ago
Nest preview

Nest

GitHubowasp/nest

Your gateway to OWASP. Discover, engage, and help shape the future!

api-securitycurated-resourceseducation+2
4252 days ago
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

cloud-securitycontainer-securityctf+5
1.5k2 days ago
mas-website preview

mas-website

GitHubowasp/mas-website

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

android-securitycurated-resourceseducation+4
122 days ago
maswe preview

maswe

GitHubowasp/maswe

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

android-securitycurated-resourceseducation+4
382 days ago
Previous12…13Next