Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
6623 results
purpleteam-s2-containers preview
Archived

purpleteam-s2-containers

GitLabpurpleteam-labs/purpleteam-s2-containers

Stage two containers

cloud-securitycontainer-securitydevsecops+5
1
5 years ago
awesome-web-security preview

awesome-web-security

GitHubqazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

ctfcurated-resourceseducation+7
13.9k23 days ago
DVWA preview

DVWA

GitHubdigininja/dvwa

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

educationlabs-practicepenetration-testing+2
13.8k18h 36m ago
wstg preview

wstg

GitHubowasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

educationlearning-paths-coursespenetration-testing+2
10.0k2 days ago
TIWAP preview

TIWAP

GitHubtombstoneghost/tiwap

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

educationlabs-practicepenetration-testing+2
1782 years ago
cybersecurity-interview-questions preview

cybersecurity-interview-questions

GitHubexcalibra/cybersecurity-interview-questions

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…

curated-resourceseducationincident-response+4
132 months ago
Aperisite preview

Aperisite

GitLabaperikube/aperisite

CTF team website aggregating writeups and resources for web security challenges including XSS, SQLi, CSRF, SSRF, and XXE.

ctfeducationweb-security
44 years ago
WebGoat.NET preview

WebGoat.NET

GitLabmbrandner-group/webgoat.net

Deliberately vulnerable .NET web application for learning common web security flaws through hands-on exercises covering XSS, SQL injection, and other…

ctfeducationlabs-practice+3
3 years ago
Notes preview

Notes

GitHubgracenolan/notes

Curated study notes and interview preparation guide for security engineering roles, covering networking, web security, cryptography, malware…

cryptographycurated-resourcesdigital-forensics+6
2.7k8 months ago
open-source-web-scanners preview

open-source-web-scanners

GitHubpsiinon/open-source-web-scanners

Curated list of open-source web security scanners, including general-purpose scanners, infrastructure scanners, and fuzzers, ordered by GitHub stars.

curated-resourceseducationfuzzing+3
1.6k1 year ago
VulnLab preview

VulnLab

GitHubyavuzlar/vulnlab

Deliberately vulnerable web application lab for practicing exploitation of SQLi, XSS, CSRF, SSTI, IDOR, XXE, and 15+ other common web security flaws…

educationlabs-practiceweb-application-exploitation+1
5291 year ago
ASST preview

ASST

GitHubowasp/asst

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

code-analysiseducationstatic-code-analysis+2
1881 year ago
modo preview

modo

GitHubmohshomis/modo

Curated collection of cybersecurity learning resources, CTF writeups, research papers, and practical labs for hands-on skill development across web…

ctfcurated-resourceseducation+9
1926 months ago
ravage preview

ravage

GitHubduriantaco/ravage

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

ai-securityctfdynamic-analysis-sandboxing+7
5025 days ago
rawsec-cybersecurity-inventory preview

rawsec-cybersecurity-inventory

GitLabrawsec/rawsec-cybersecurity-list

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

cryptographyctfcurated-resources+9
361 month ago
OWASP-WSTG-Rag preview

OWASP-WSTG-Rag

GitHubzilbonn/owasp-wstg-rag

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

ai-securityapi-security-testingauthentication+8
2210 months ago
PortSwigger-Web-Security-Academy preview

PortSwigger-Web-Security-Academy

GitHubnu11secur1ty/portswigger-web-security-academy

Curated solutions and walkthroughs for PortSwigger Web Security Academy labs, covering web vulnerabilities, JWT attacks, and exploitation techniques…

ctfeducationpenetration-testing+2
51 month ago
security-writeups preview

security-writeups

GitHubalzeaty1/security-writeups

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

ctfeducationlabs-practice+5
12 days ago
Previous12…100Next