Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
48 results
CICD-Goat-Vapt-Writeup preview

CICD-Goat-Vapt-Writeup

GitHubdheeraj-jayaswal/cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

ctfdevsecopseducation+5
1
10 days ago
domain-protect preview

domain-protect

GitHubovotech/domain-protect

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

cloud-securitymisconfigurationreconnaissance+1
33 years ago
domain-protect preview
Archived

domain-protect

GitHubdomain-protect/domain-protect

OWASP Domain Protect - prevent subdomain takeover

cloud-securitydevsecopsdns-analysis+4
3941 year ago
waf-tester preview

waf-tester

GitHubkpomin57/waf-tester

A program for testing WAF functionality

api-security-testingeducationids-ips-evasion+5
265 months ago
AzureGoat preview

AzureGoat

GitHubine-labs/azuregoat

AzureGoat : A Damn Vulnerable Azure Infrastructure

cloud-infrastructure-securitycloud-securityeducation+5
9661 year ago
GCPGoat preview

GCPGoat

GitHubine-labs/gcpgoat

GCPGoat : A Damn Vulnerable GCP Infrastructure

cloud-infrastructure-securitycloud-securityeducation+5
4581 year ago
owasp-modsecurity-crs preview
Archived

owasp-modsecurity-crs

GitHubspiderlabs/owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

api-securitydefensive-toolsintrusion-detection+3
2.5k6 years ago
OWASP-Subtractive-Hardening-Top-10 preview

OWASP-Subtractive-Hardening-Top-10

GitHubowasp/owasp-subtractive-hardening-top-10

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

ai-securitycloud-securitycontainer-security+6
304 days ago
ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-24891_2-2-3-1

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

api-securityauthentication-authorizationcode-analysis+5
1 year ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4081 year ago
openshield preview

openshield

GitHubowasp/openshield

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

cloud-securityconfiguration-auditingcryptography+4
587 days ago
java-html-sanitizer preview

java-html-sanitizer

GitHubowasp/java-html-sanitizer

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

api-securitycode-analysisdefensive-tools+3
95712 days ago
abap-code-scanner preview

abap-code-scanner

GitHubowasp/abap-code-scanner

ABAP Code Analyzer

code-analysisdevsecopsmisconfiguration+2
1311 days ago
SILENTCHAIN preview

SILENTCHAIN

GitHubsilentchainai/silentchain

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

ai-securityapi-security-testingcode-analysis+8
4634 days ago
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

api-security-testingexploitationmisconfiguration+4
1 month ago
CVE-2025-12720 preview

CVE-2025-12720

GitHubd0n601/cve-2025-12720

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

api-security-testingauthenticationexploitation+3
11 months ago
CVE-2024-54369 preview

CVE-2024-54369

GitHubrandomrobbiebf/cve-2024-54369

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

api-security-testingexploitationmisconfiguration+3
1 year ago
CVE-2023-6289 preview

CVE-2023-6289

GitHubrandomrobbiebf/cve-2023-6289

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

api-security-testingexploitationinformation-gathering+3
2 years ago
Previous123Next