Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
279 results
www-community preview

www-community

GitHubowasp/www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

curated-resourceseducationinformation-gathering+3
1.4k
9 days ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

api-securitycloud-securitydefensive-tools+5
1.6k1 day ago
SecureTea-Project preview

SecureTea-Project

GitHubowasp/securetea-project

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

defensive-toolsintrusion-detectioniot-security+4
3022 years ago
OWASP-VWAD preview

OWASP-VWAD

GitHubowasp/owasp-vwad

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

curated-resourceseducationlabs-practice+3
8861 month ago
RedTeamToolkit preview

RedTeamToolkit

GitHubowasp/redteamtoolkit

The WASM Based Security Toolkit for the Web First Paradigm

exploit-frameworksinformation-gatheringpenetration-testing-frameworks+3
362 years ago
awesome-ethical-hacking-resources preview

awesome-ethical-hacking-resources

GitHubhusnainfareed/awesome-ethical-hacking-resources

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

ctfcurated-resourceseducation+7
3.7k4 months ago
Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes preview

Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes

GitHubxalgord/massive-web-application-penetration-testing-bug-bounty-notes

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

curated-resourceseducationlearning-paths-courses+3
1.8k11 months ago
vapi preview

vapi

GitHubroottusk/vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

api-securityapi-security-testingeducation+4
1.3k1 year ago
agent-opfor preview

agent-opfor

GitHubkeyvaluesoftwaresystems/agent-opfor

Open-source adversary emulation for AI agents and MCP servers.

adversarial-attackai-securityapi-security-testing+5
5767 days ago
awesome-cybersec preview

awesome-cybersec

GitHubdhotrey/awesome-cybersec

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

ctfcurated-resourceseducation+8
19426 days ago
OWASP-Calculator preview

OWASP-Calculator

GitHubjavierolmedo/owasp-calculator

🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment

educationvulnerability-analysisweb-security
1625 years ago
zap-scripts preview

zap-scripts

GitHubsepehrdaddev/zap-scripts

Zed Attack Proxy Scripts for finding CVEs and Secrets.

penetration-testingsecret-detectionvulnerability-scanners+1
1264 years ago
xss_vulnerability_challenges preview

xss_vulnerability_challenges

GitHubmoeinfatehi/xss_vulnerability_challenges

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

educationlabs-practicepenetration-testing+3
1194 years ago
BirDuster preview

BirDuster

GitHubytisf/birduster

A multi threaded Python script designed to brute force directories and files names on webservers.

information-gatheringpenetration-testingvulnerability-scanners+1
816 years ago
private-landing preview

private-landing

GitHubvhscom/private-landing

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

api-securityauthenticationauthentication-authorization+8
793 months ago
CVE-2026-34835-Black-box-Analysis preview

CVE-2026-34835-Black-box-Analysis

GitHubcyber-note/cve-2026-34835-black-box-analysis

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

dns-analysiseducationpenetration-testing+3
61 month ago
vuln_apps preview

vuln_apps

GitHubclickswave/vuln_apps

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

api-securityeducationlabs-practice+3
112 days ago
Awesome-Hacking-Resources preview

Awesome-Hacking-Resources

GitHubvitalysim/awesome-hacking-resources

A collection of hacking / penetration testing resources to make you better!

ai-securityctfcurated-resources+9
17.3k3 months ago
Previous1…456…16Next