Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
160 results
WebGoat preview

WebGoat

GitHubwebgoat/webgoat

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

ctfeducationlabs-practice+4
9.3k
7 days ago
Resources-for-Application-Security preview

Resources-for-Application-Security

GitHubsecurity-prince/resources-for-application-security

Some good resources for getting started with application security

ctfcurated-resourcesdynamic-analysis-sandboxing+6
1486 years ago
TIWAP preview

TIWAP

GitHubtombstoneghost/tiwap

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

educationlabs-practicepenetration-testing+2
1782 years ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
929 days ago
juice-shop preview

juice-shop

GitHubjuice-shop/juice-shop

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

ctfeducationlabs-practice+3
13.9k1 month ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1811 days ago
CVE-2023-2822-demo preview

CVE-2023-2822-demo

GitHubcberman/cve-2023-2822-demo

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

ctfeducationlabs-practice+3
33 years ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
92413 days ago
CVE-2023-44487 preview

CVE-2023-44487

GitHubhirokiii/cve-2023-44487

Educational environment for LTAT.04.022 Homework 4.

configuration-auditingcontainer-securityeducation+4
4 months ago
pygoat preview

pygoat

GitHubadeyosemanputra/pygoat

intentionally vuln web Application Security in django

educationlabs-practicepenetration-testing+2
3455 months ago
Tiredful-API preview

Tiredful-API

GitHubpayatu/tiredful-api

An intentionally designed broken web application based on REST API.

api-security-testingeducationlabs-practice+2
5836 years ago
lazyweb preview

lazyweb

GitHubramadhanamizudin/lazyweb

LazyWeb is a demonstration web application designed to showcase common server-side application vulnerabilities. Each vulnerability is categorized…

educationlabs-practicepenetration-testing+2
1313 days ago
VulnerableDotNetHTTPRemoting preview

VulnerableDotNetHTTPRemoting

GitHubnccgroup/vulnerabledotnethttpremoting

Example Vulnerable .NET HTTP Remoting

educationexploitationlabs-practice+4
877 years ago
vulpy preview

vulpy

GitHubfportantier/vulpy

Vulnerable Python Application To Learn Secure Development

educationlabs-practicepenetration-testing+2
1286 years ago
libextractor-ole2-rce preview

libextractor-ole2-rce

GitHubhaitam-lazaar/libextractor-ole2-rce

PoC for a Critical stack-based buffer overflow in GNU libextractor ≤ 1.14. A malicious .doc file triggers an unbounded VLA allocation causing…

binary-exploitationexploitationlabs-practice+4
6 days ago
NextJS-CVE-2025-29927 preview

NextJS-CVE-2025-29927

GitHubenochgitgamefied/nextjs-cve-2025-29927

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…

authenticationeducationlabs-practice+3
1 year ago
ravage preview

ravage

GitHubduriantaco/ravage

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

ai-securityctfdynamic-analysis-sandboxing+7
488 days ago
DSP preview

DSP

GitHubdockersecurityplayground/dsp

A Microservices-based framework for the study of Network Security and Penetration Test techniques

container-securityeducationlabs-practice+3
6316 months ago
Previous12…9Next