Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
291 results
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
92519 days ago
WebGoat preview

WebGoat

GitHubwebgoat/webgoat

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

ctfeducationlabs-practice+4
9.4k4 days ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
93911 months ago
OWASPWebGoatPHP preview

OWASPWebGoatPHP

GitHubowasp/owaspwebgoatphp

A deliberately vulnerable web application for learning web application security.

ctfeducationlabs-practice+3
1611 year ago
IoTGoat preview

IoTGoat

GitHubscriptingxss/iotgoat

IoTGoat is a deliberately insecure firmware based on OpenWrt.

educationfirmware-analysishardware-iot-security+4
1846 years ago
crAPI preview

crAPI

GitHubowasp/crapi

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

api-securityapi-security-testingeducation+3
1.6k18 days ago
DeliberatelyVulnerableWebApp preview
Archived

DeliberatelyVulnerableWebApp

GitHubtimothyjxhn/deliberatelyvulnerablewebapp

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

educationexploitationlabs-practice+3
1 year ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5473 years ago
wpBullet preview

wpBullet

GitHubowasp/wpbullet

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

code-analysispenetration-testingstatic-code-analysis+3
614 years ago
limeyard preview

limeyard

GitHubclickswave/limeyard

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

container-securitydevsecopsdns-subdomain-enumeration+8
115 days ago
simple-maven preview

simple-maven

GitHubmindpatch/simple-maven

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

api-security-testingeducationlabs-practice+3
1 year ago
dvcsharp-api preview

dvcsharp-api

GitHubappsecco/dvcsharp-api

Damn Vulnerable C# Application (API)

api-security-testingeducationlabs-practice+3
863 years ago
www-community preview

www-community

GitHubowasp/www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

curated-resourceseducationinformation-gathering+3
1.4k6h 52m ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

api-securitycloud-securitydefensive-tools+5
1.6k10 days ago
owasp-java-encoder preview

owasp-java-encoder

GitHubowasp/owasp-java-encoder

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

code-analysisdefensive-toolsencryption-decryption-tools+3
54213h 45m ago
cwe-tool preview

cwe-tool

GitHubowasp/cwe-tool

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

code-analysiscurated-resourceseducation+3
655 months ago
TCASVS preview

TCASVS

GitHubowasp/tcasvs

OWASP Thick Client Application Security Verification Standard

code-analysisconfiguration-auditingcryptography+5
323 months ago
OWASP-VWAD preview

OWASP-VWAD

GitHubowasp/owasp-vwad

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

curated-resourceseducationlabs-practice+3
8833 days ago
Previous12…17Next