Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
589 results
waf-tester preview

waf-tester

GitHubkpomin57/waf-tester

A program for testing WAF functionality

api-security-testingeducationids-ips-evasion+5
264 months ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
195 months ago
cwe-tool preview

cwe-tool

GitHubowasp/cwe-tool

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

code-analysiscurated-resourceseducation+3
655 months ago
cwe-sdk-javascript preview

cwe-sdk-javascript

GitHubowasp/cwe-sdk-javascript

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

code-analysiscurated-resourceseducation+3
325 months ago
CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication preview

CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication

GitHubdylvie/cve-2026-30824-flowise-nvidia-nim-authentication

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

api-security-testingexploitationpenetration-testing+3
5 months ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
5 months ago
AI-Vulnerabilities-Playground preview

AI-Vulnerabilities-Playground

GitHubowasp/ai-vulnerabilities-playground

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

adversarial-attackai-securityctf+4
235 months ago
Intrusion-Alert-Educational-Network-IDS preview

Intrusion-Alert-Educational-Network-IDS

GitHubowasp/intrusion-alert-educational-network-ids

Lightweight Python-based IDS that monitors network traffic in real-time using Scapy, detecting DoS/DDoS attacks via per-IP request rate analysis with…

anomaly-detectiondefensive-toolseducation+3
5 months ago
Agent-Skills-Security-Standard preview

Agent-Skills-Security-Standard

GitHubowasp/agent-skills-security-standard

Security standard for agent skills, providing guidelines and best practices to secure AI-driven autonomous agents in cloud and API environments.

ai-securityapi-securitycloud-security+3
25 months ago
Damn-Vulnerable-ML-Model preview

Damn-Vulnerable-ML-Model

GitHubowasp/damn-vulnerable-ml-model

Intentionally vulnerable machine learning model for hands-on security training. Explore common ML vulnerabilities, adversarial attacks, and defensive…

adversarial-attackai-securityeducation+3
25 months ago
Multi-VLAN-Enterprise-Network-Vulnerability-Assessment preview

Multi-VLAN-Enterprise-Network-Vulnerability-Assessment

GitHubklairmanraj/multi-vlan-enterprise-network-vulnerability-assessment

Multi-VLAN enterprise network vulnerability assessment using Nessus, OWASP ZAP, and Wireshark. Confirms Stored XSS on WebGoat and EternalBlue…

exploitationnetwork-mappingnetwork-security+6
5 months ago
Multi-VLAN-Enterprise-Network-Security-Infrastructure preview

Multi-VLAN-Enterprise-Network-Security-Infrastructure

GitHubklairmanraj/multi-vlan-enterprise-network-security-infrastructure

Multi-VM virtual network lab with GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, and Docker services. Includes vulnerability…

configuration-auditingdns-analysiseducation+4
5 months ago
LLM-MCP-Security-Field-Guide preview

LLM-MCP-Security-Field-Guide

GitHubpathakabhi24/llm-mcp-security-field-guide

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

ai-securitycurated-resourceseducation+7
45 months ago
cve-2025-55182-analysis preview

cve-2025-55182-analysis

GitHubmohamedniane/cve-2025-55182-analysis

Security research & exploitation analysis of CVE-2025-55182 (React) — CVSS + OWASP Top 10 mapping

educationexploitationpenetration-testing+2
5 months ago
awesome-ethical-hacking-resources preview

awesome-ethical-hacking-resources

GitHubhusnainfareed/awesome-ethical-hacking-resources

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

ctfcurated-resourceseducation+7
3.8k5 months ago
BlackWidow preview

BlackWidow

GitHub1n3/blackwidow

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

fuzzinginformation-gatheringosint+3
1.8k5 months ago
reconix preview

reconix

GitHubaquibpro/reconix

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

api-security-testingcrawlerexploitation+8
25 months ago
kubernetes-goat preview

kubernetes-goat

GitHubmadhuakula/kubernetes-goat

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

cloud-securitycontainer-escapecontainer-security+4
5.8k5 months ago
Previous1…141516…33Next