Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
589 results
Packer-Fuzzer preview

Packer-Fuzzer

GitHubrtcatc/packer-fuzzer

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

api-security-testingfuzzingvulnerability-scanners+1
3.3k
2 years ago
GraphQLmap preview

GraphQLmap

GitHubswisskyrepo/graphqlmap

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

api-security-testingctffuzzing+3
1.7k3 years ago
waf-bypass preview

waf-bypass

GitHubnemesida-waf/waf-bypass

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

api-security-testingpenetration-testingvulnerability-scanners+2
1.5k2 months ago
SecurityShepherd preview

SecurityShepherd

GitHubowasp/securityshepherd

Web and mobile application security training platform

ctfeducationlabs-practice+3
1.5k25 days ago
Autorize preview

Autorize

GitHubquitten/autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

api-security-testingauthentication-authorizationpenetration-testing+2
1.2k6 months ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k4 days ago
OpenDoor preview

OpenDoor

GitHubstanislav-web/opendoor

OWASP Web Recon & Directory Discovery Platform

information-gatheringpenetration-testingreconnaissance+4
1.0k1 month ago
APKHunt preview

APKHunt

GitHubcyber-buddy/apkhunt

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

android-securitycode-analysismobile-security+3
9853 days ago
numasec preview

numasec

GitHubfrancescostabile/numasec

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

ai-securityctfdevsecops+7
7964 months ago
ssrf-king preview

ssrf-king

GitHubethicalhackingplayground/ssrf-king

SSRF plugin for burp Automates SSRF Detection in all of the Request

api-security-testingpenetration-testingvulnerability-scanners+1
6345 years ago
agent-opfor preview

agent-opfor

GitHubkeyvaluesoftwaresystems/agent-opfor

Open-source adversary emulation for AI agents and MCP servers.

adversarial-attackai-securityapi-security-testing+5
5821 month ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5473 years ago
SecureTea-Project preview

SecureTea-Project

GitHubowasp/securetea-project

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

defensive-toolsintrusion-detectioniot-security+4
3023 years ago
authcov preview
Archived

authcov

GitHubauthcov/authcov

Web app authorisation coverage scanning

api-security-testingauthentication-authorizationcrawler+3
2343 years ago
BWASP preview

BWASP

GitHubbwasp/bwasp

BoB Web Application Security Project

educationpenetration-testingvulnerability-analysis+3
2239 months ago
AutoNessus preview

AutoNessus

GitHubdeepseasred/autonessus

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

api-security-testingvulnerability-scanners
2149 years ago
awesome-cybersec preview

awesome-cybersec

GitHubdhotrey/awesome-cybersec

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

ctfcurated-resourceseducation+8
1952 months ago
openapi_security_scanner preview

openapi_security_scanner

GitHubngalongc/openapi_security_scanner

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

api-security-testingpenetration-testingvulnerability-scanners+1
1735 years ago
Previous1…121314…33Next