Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
FIASSE preview

FIASSE

GitHubowasp/fiasse

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

code-analysiscurated-resourcesdevsecops+7
142 days ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

adversarial-attackai-securitycurated-resources+6
1.5k13h 32m ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1817 days ago
mcp-xray preview

mcp-xray

GitHubtraceforce/mcp-xray

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

api-security-testingcode-analysisconfiguration-auditing+8
871 month ago
PSCF preview

PSCF

GitHubowasp/pscf

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

curated-resourcesdevsecopseducation+2
290 years ago
Owasp-top-10-k8s-2025 preview

Owasp-top-10-k8s-2025

GitHubhac01/owasp-top-10-k8s-2025

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

cloud-securitycontainer-securityctf+8
492 months ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k4 days ago
DockSec preview

DockSec

GitHubowasp/docksec

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

ai-securitycode-analysiscontainer-security+5
4934 days ago
APTS preview

APTS

GitHubowasp/apts

OWASP Autonomous Penetration Testing Standard

api-securitycloud-securitycurated-resources+5
69524 days ago
Software-Component-Verification-Standard preview

Software-Component-Verification-Standard

GitHubowasp/software-component-verification-standard

Software Component Verification Standard (SCVS)

configuration-auditingcurated-resourceseducation+2
1702 years ago
awesome-nodejs-security preview

awesome-nodejs-security

GitHublirantal/awesome-nodejs-security

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

code-analysiscurated-resourceseducation+5
3.0k1 month ago
cve-lite-cli preview

cve-lite-cli

GitHubowasp/cve-lite-cli

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

code-analysiscurated-resourcesdevsecops+5
74315h 11m ago
DependencyCheck preview

DependencyCheck

GitHubdependency-check/dependencycheck

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

devsecopssupply-chain-securityvulnerability-analysis+1
7.7k12h 52m ago
SEDATED preview

SEDATED

GitHubowasp/sedated

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

code-analysisconfiguration-auditingdevsecops+3
1106 years ago
VulnReach preview

VulnReach

GitHubowasp/vulnreach

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

code-analysisdevsecopsdynamic-analysis-sandboxing+5
161 day ago
cve-lite-on-pi preview

cve-lite-on-pi

GitHubaz9713/cve-lite-on-pi

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

code-analysisdevsecopseducation+3
3 months ago
dep-scan preview

dep-scan

GitHubowasp-dep-scan/dep-scan

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

container-securitydevsecopssupply-chain-security+1
1.3k6 days ago
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

ai-securityapi-security-testingcloud-infrastructure-security+8
8476 days ago
Previous123Next