Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
589 results
raider preview

raider

GitHubowasp/raider

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

api-security-testingauthenticationpenetration-testing+3
1003 years ago
Python-Honeypot preview

Python-Honeypot

GitHubowasp/python-honeypot

OWASP Honeypot, Automated Deception Framework.

api-securitycontainer-securitydefensive-tools+4
4842 years ago
rbac preview

rbac

GitHubowasp/rbac

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

authentication-authorizationdevsecopsidentity-access-management+2
43511 years ago
RedTeamToolkit preview

RedTeamToolkit

GitHubowasp/redteamtoolkit

The WASM Based Security Toolkit for the Web First Paradigm

exploit-frameworksinformation-gatheringpenetration-testing-frameworks+3
376 years ago
SAPKiln preview

SAPKiln

GitHubowasp/sapkiln

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

configuration-auditinglateral-movementosint+3
303 years ago
SecureML preview

SecureML

GitHubowasp/secureml

SecureML - Securing and Watermarking AL models

ai-securitycryptographydevsecops+2
29 months ago
SecureCodingDojo preview

SecureCodingDojo

GitHubowasp/securecodingdojo

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

authenticationcode-analysisctf+6
61110 months ago
Software-Component-Verification-Standard preview

Software-Component-Verification-Standard

GitHubowasp/software-component-verification-standard

Software Component Verification Standard (SCVS)

configuration-auditingcurated-resourceseducation+2
1702 years ago
WebGoat.NET preview

WebGoat.NET

GitHubowasp/webgoat.net

OWASP WebGoat.NET

code-analysiseducationlabs-practice+3
7313 years ago
wpBullet preview

wpBullet

GitHubowasp/wpbullet

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

code-analysispenetration-testingstatic-code-analysis+3
614 years ago
kstg preview

kstg

GitHubowasp/kstg

Kubernetes Security Testing Guide

cloud-securitycontainer-securitycurated-resources+3
286 years ago
json-sanitizer preview

json-sanitizer

GitHubowasp/json-sanitizer

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

code-analysisencryption-decryption-toolsgeneral-purpose-utilities+3
2192 years ago
mas-crackmes preview

mas-crackmes

GitHubowasp/mas-crackmes

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

android-securitybinary-analysisctf+6
373 years ago
KubeLight preview

KubeLight

GitHubowasp/kubelight

OWASP Kubernetes security and compliance tool [WIP]

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
1073 years ago
masvs preview

masvs

GitHubowasp/masvs

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

android-securitycurated-resourceseducation+3
2.5k7 days ago
CVE-2025-53640 preview

CVE-2025-53640

GitHubrafaelcorvino1/cve-2025-53640

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

api-security-testinginformation-gatheringosint+3
18 months ago
ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-23457_2-2-3-1

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

api-securityauthentication-authorizationcode-analysis+6
1 year ago
ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-24891_2-2-3-1

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

api-securityauthentication-authorizationcode-analysis+5
1 year ago
Previous1…121314…33Next