Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
103 results
www-community preview

www-community

GitHubowasp/www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

curated-resourceseducationinformation-gathering+3
1.4k
9 days ago
RedTeamToolkit preview

RedTeamToolkit

GitHubowasp/redteamtoolkit

The WASM Based Security Toolkit for the Web First Paradigm

exploit-frameworksinformation-gatheringpenetration-testing-frameworks+3
376 years ago
Maryam preview
Archived

Maryam

GitHubsaeeddhqan/maryam

Maryam: Open-source Intelligence(OSINT) Framework

dns-subdomain-enumerationinformation-gatheringosint+2
1.2k2 years ago
awesome-security-vul-llm preview

awesome-security-vul-llm

GitHubxu-xiang/awesome-security-vul-llm

本项目通过大模型联动爬虫,检索Github上所有存有有价值漏洞信息与漏洞POC或规则信息的项目,并自动识别项目的目录结构、Readme信息后进行总结分析并分类,所汇总的项目可以帮助安全行业从业者收集漏洞信息、POC信息、规则等。

ai-securitycurated-resourceseducation+2
1632 years ago
BirDuster preview

BirDuster

GitHubytisf/birduster

A multi threaded Python script designed to brute force directories and files names on webservers.

information-gatheringpenetration-testingvulnerability-scanners+1
816 years ago
vbscan preview
Archived

vbscan

GitHubowasp/vbscan

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

exploitationinformation-gatheringpenetration-testing+3
3257 years ago
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

api-securityapi-security-testingdynamic-code-analysis+14
5.6k2 days ago
Nest preview

Nest

GitHubowasp/nest

Your gateway to OWASP. Discover, engage, and help shape the future!

api-securitycurated-resourceseducation+2
45413h 25m ago
D4N155 preview

D4N155

GitHubowasp/d4n155

OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

crawlerinformation-gatheringosint+1
2711 month ago
wwwgrep preview
Archived

wwwgrep

GitHubowasp/wwwgrep

OWASP Foundation Web Respository

code-analysisinformation-gatheringpenetration-testing+3
365 years ago
joomscan preview

joomscan

GitHubowasp/joomscan

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

information-gatheringmisconfigurationvulnerability-scanners+2
1.2k2 years ago
Honeypot-Project preview

Honeypot-Project

GitHubowasp/honeypot-project

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

defensive-toolseducationincident-response+5
10825 days ago
owasp-cstg preview

owasp-cstg

GitHubowasp/owasp-cstg

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

cloud-securitycurated-resourceseducation+8
353 months ago
awscanner preview

awscanner

GitHubowasp/awscanner

Finds internet-exposed resources in an AWS account

cloud-infrastructure-securitycloud-securityinformation-gathering+4
192 years ago
NINJA-PingU preview
Archived

NINJA-PingU

GitHubowasp/ninja-pingu

High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

embedded-systems-securityinformation-gatheringnetwork-mapping+3
777 years ago
BlackWidow preview

BlackWidow

GitHub1n3/blackwidow

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

fuzzinginformation-gatheringosint+3
1.8k5 months ago
Admin-Panel_Finder preview

Admin-Panel_Finder

GitHubmoeinfatehi/admin-panel_finder

Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.

information-gatheringpenetration-testingreconnaissance+2
1234 years ago
amass preview

amass

GitHubowasp-amass/amass

In-depth attack surface mapping and asset discovery

data-exfiltrationdns-analysisdns-fuzzing+10
15.2k5 months ago
Previous123456Next