Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1237 results
SecurityShepherd preview

SecurityShepherd

GitHubowasp/securityshepherd

Web and mobile application security training platform

ctfeducationlabs-practice+3
1.5k16 days ago
SecureCodingDojo preview

SecureCodingDojo

GitHubowasp/securecodingdojo

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

authenticationcode-analysisctf+6
6089 months ago
sh00t preview

sh00t

GitHubpavanw3b/sh00t

Security Testing is not as simple as right click > Scan. It's messy, a tough game. What if you had missed to test just that one thing and had to…

educationpenetration-testingutilities-frameworks+2
2761 year ago
PwnzzAI preview

PwnzzAI

GitHubowasp/pwnzzai

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

ai-securityctfcurated-resources+6
648 days ago
HaccTheHub preview

HaccTheHub

GitHubj4fsec/haccthehub

Open source self-hosted cyber security learning platform

educationlabs-practicepenetration-testing+1
523 years ago
AI-Vulnerabilities-Playground preview

AI-Vulnerabilities-Playground

GitHubowasp/ai-vulnerabilities-playground

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

adversarial-attackai-securityctf+4
134 months ago
wvctf preview

wvctf

GitHubsyn-4ck/wvctf

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

ctfeducationlabs-practice+3
12 years ago
Multi-Stage-Exploitation-and-Detection-Engineering-Analysis-of-CVE-2023-34362-in-MOVEit-Transfer preview

Multi-Stage-Exploitation-and-Detection-Engineering-Analysis-of-CVE-2023-34362-in-MOVEit-Transfer

GitHubkarmanyat28/multi-stage-exploitation-and-detection-engineering-analysis-of-cve-2023-34362-in-moveit-transfer

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

educationincident-responselog-analysis+3
3 months ago
CVE-2023-37596 preview

CVE-2023-37596

GitHubsahiloj/cve-2023-37596

CVE-2023-37596 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in Issabel PBX version 4.0.0-6, a widely used open-source Unified…

educationexploitationpenetration-testing+3
16 months ago
TCL-xss-Labs preview

TCL-xss-Labs

GitHubthe-cyber-ledger/tcl-xss-labs

An interactive, self-hosted XSS training platform with 33 progressively harder challenges

ctfeducationlabs-practice+5
15 months ago
CVE-2025-68613 preview

CVE-2025-68613

GitHubnehkark/cve-2025-68613

This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow…

educationexploitationinformation-gathering+3
8 months ago
mimosa preview

mimosa

GitHubowasp/mimosa

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

ctfeducationlabs-practice+3
3 years ago
Compose Aperisite preview

Compose Aperisite

GitLabaperikube/compose-aperisite

Docker Compose wrapper to deploy AperiSite, a curated platform hosting CTF writeups, security challenges, and educational resources covering web,…

ctfcurated-resourceseducation+1
15 years ago
Detecting-and-Analyzing-CVE-2024-24919-Exploitation preview

Detecting-and-Analyzing-CVE-2024-24919-Exploitation

GitHubmacuchegit/detecting-and-analyzing-cve-2024-24919-exploitation

Step-by-step walkthrough of detecting and analyzing CVE-2024-24919 exploitation using a SIEM platform, including traffic analysis, IOC documentation,…

digital-forensicseducationincident-response+5
1 year ago
CVE-2025-27893 preview

CVE-2025-27893

GitHubnastycrow/cve-2025-27893

Detailed disclosure of CVE-2025-27893: an authenticated web parameter manipulation vulnerability in Archer Platform 6.x allowing unauthorized…

educationpapers-researchpenetration-testing+3
1 year ago
Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467- preview

Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-

GitHubahmedmansour93/event-id-217-rule-name-soc254-apache-ofbiz-auth-bypass-and-code-injection-0day-cve-2023-51467-

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

educationexploitationincident-response+3
1 year ago
xwiki__xwiki-rendering_CVE-2023-32070_14-5 preview

xwiki__xwiki-rendering_CVE-2023-32070_14-5

GitHubshoucheng3/xwiki__xwiki-rendering_cve-2023-32070_14-5

Generic rendering system converting wiki syntax, HTML, and other formats into XHTML. Part of the XWiki platform, providing a flexible and extensible…

code-analysiseducationgeneral-purpose-utilities+2
9 months ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k1 month ago
Previous12…69Next