Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
160 results
Multi-VLAN-Enterprise-Network-Vulnerability-Assessment preview

Multi-VLAN-Enterprise-Network-Vulnerability-Assessment

GitHubklairmanraj/multi-vlan-enterprise-network-vulnerability-assessment

Professional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP…

exploitationnetwork-mappingnetwork-security+6
4 months ago
ARTLAS preview

ARTLAS

GitHubmthbernardes/artlas

Apache Real Time Logs Analyzer System

incident-responseintrusion-detectionlog-analysis+3
1255 years ago
SAPKiln preview

SAPKiln

GitHubowasp/sapkiln

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

configuration-auditinglateral-movementosint+3
303 years ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4061 year ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k1 month ago
vbscan preview
Archived

vbscan

GitHubowasp/vbscan

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

exploitationinformation-gatheringpenetration-testing+3
3267 years ago
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

information-gatheringnetwork-securitypassword-attacks+7
5.5k6h 6m ago
django-DefectDojo preview

django-DefectDojo

GitHubdefectdojo/django-defectdojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

devsecopspenetration-testingvulnerability-scanners
4.9k2 days ago
autopentest-ai preview

autopentest-ai

GitHubbhavsec/autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

crawlereducationexploit-frameworks+8
2145 months ago
OpenDoor preview

OpenDoor

GitHubstanislav-web/opendoor

OWASP Web Recon & Directory Discovery Platform

information-gatheringpenetration-testingreconnaissance+4
99719 days ago
vulnrepo preview

vulnrepo

GitHubkac89/vulnrepo

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import…

ai-securitycurated-resourceseducation+4
57519 days ago
vapi preview

vapi

GitHubroottusk/vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

api-securityapi-security-testingeducation+4
1.3k1 year ago
agent-opfor preview

agent-opfor

GitHubkeyvaluesoftwaresystems/agent-opfor

Open-source adversary emulation for AI agents and MCP servers.

adversarial-attackai-securityapi-security-testing+5
5767 days ago
zap-scripts preview

zap-scripts

GitHubsepehrdaddev/zap-scripts

Zed Attack Proxy Scripts for finding CVEs and Secrets.

penetration-testingsecret-detectionvulnerability-scanners+1
1254 years ago
malwarescanner preview

malwarescanner

GitHubpassword123456/malwarescanner

Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

hash-analysisincident-responsemalware-analysis+1
901 year ago
BirDuster preview

BirDuster

GitHubytisf/birduster

A multi threaded Python script designed to brute force directories and files names on webservers.

information-gatheringpenetration-testingvulnerability-scanners+1
816 years ago
Astra preview

Astra

GitHubflipkart-incubator/astra

Automated Security Testing For REST API's

api-security-testingdevsecopspenetration-testing+2
2.7k2 years ago
secureCodeBox preview

secureCodeBox

GitHubsecurecodebox/securecodebox

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

cloud-securitycontainer-securitydevsecops+3
9862 days ago
Previous1234…9Next