Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
java-html-sanitizer preview

java-html-sanitizer

GitHubowasp/java-html-sanitizer

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

api-securitycode-analysisdefensive-tools+3
948
5 months ago
abap-code-scanner preview

abap-code-scanner

GitHubowasp/abap-code-scanner

ABAP Code Analyzer

code-analysisdevsecopsmisconfiguration+2
101 month ago
SILENTCHAIN preview

SILENTCHAIN

GitHubsilentchainai/silentchain

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

ai-securityapi-security-testingcode-analysis+8
3311 month ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.7k3 days ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

ids-ips-evasionmisconfigurationvulnerability-scanners+3
3.2k1 day ago
AzureGoat preview

AzureGoat

GitHubine-labs/azuregoat

AzureGoat : A Damn Vulnerable Azure Infrastructure

cloud-infrastructure-securitycloud-securityeducation+5
9581 year ago
GCPGoat preview

GCPGoat

GitHubine-labs/gcpgoat

GCPGoat : A Damn Vulnerable GCP Infrastructure

cloud-infrastructure-securitycloud-securityeducation+5
4521 year ago
pentest-guide preview

pentest-guide

GitHubvoorivex/pentest-guide

Penetration tests guide based on OWASP including test cases, resources and examples.

authenticationcryptographyeducation+6
2.8k5 years ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
183 months ago
domain-protect preview

domain-protect

GitHubovotech/domain-protect

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

cloud-securitymisconfigurationreconnaissance+1
33 years ago
OWASP-Subtractive-Hardening-Top-10 preview

OWASP-Subtractive-Hardening-Top-10

GitHubowasp/owasp-subtractive-hardening-top-10

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

ai-securitycloud-securitycontainer-security+6
211 day ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4061 year ago
Owasp-top-10-k8s-2025 preview

Owasp-top-10-k8s-2025

GitHubhac01/owasp-top-10-k8s-2025

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

cloud-securitycontainer-securityctf+8
461 month ago
joomscan preview

joomscan

GitHubowasp/joomscan

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

information-gatheringmisconfigurationvulnerability-scanners+2
1.2k2 years ago
Serverless-Goat preview

Serverless-Goat

GitHubowasp/serverless-goat

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

cloud-securityeducationlabs-practice+3
3302 years ago
DonkAI preview

DonkAI

GitHubowasp/donkai

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

ai-securityctfeducation+6
122 months ago
Docker-Security preview

Docker-Security

GitHubowasp/docker-security

Getting a handle on container security

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
6872 years ago
awscanner preview

awscanner

GitHubowasp/awscanner

Finds internet-exposed resources in an AWS account

cloud-infrastructure-securitycloud-securityinformation-gathering+4
181 year ago
Previous123Next