Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
589 results
web-threat-mitigation preview

web-threat-mitigation

GitHubbrunoh6/web-threat-mitigation

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

configuration-auditingdevsecopseducation+8
1 year ago
CVE-2024-48415 preview

CVE-2024-48415

GitHubkhaliquesx/cve-2024-48415

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

educationpapers-researchvulnerability-analysis+2
1 year ago
OWASP-GoatDroid-Project preview
Archived

OWASP-GoatDroid-Project

GitHubnvisium-jack-mannino/owasp-goatdroid-project

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

android-securityeducationlabs-practice+3
25612 years ago
owasp-modsecurity-crs preview
Archived

owasp-modsecurity-crs

GitHubspiderlabs/owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

api-securitydefensive-toolsintrusion-detection+3
2.5k6 years ago
waf-tester preview

waf-tester

GitHubkpomin57/waf-tester

A program for testing WAF functionality

api-security-testingeducationids-ips-evasion+5
264 months ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

adversarial-attackai-securitycurated-resources+6
1.5k17h 10m ago
HUNT preview

HUNT

GitHubbugcrowd/hunt

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

curated-resourcespenetration-testingvulnerability-analysis+3
2.3k1 month ago
dep-scan preview

dep-scan

GitHubowasp-dep-scan/dep-scan

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

container-securitydevsecopssupply-chain-security+1
1.3k6 days ago
AzureGoat preview

AzureGoat

GitHubine-labs/azuregoat

AzureGoat : A Damn Vulnerable Azure Infrastructure

cloud-infrastructure-securitycloud-securityeducation+5
9671 year ago
faction preview

faction

GitHubfactionsecurity/faction

Pen Test Report Generation and Assessment Collaboration

penetration-testingpenetration-testing-frameworksvulnerability-analysis
60522 days ago
GCPGoat preview

GCPGoat

GitHubine-labs/gcpgoat

GCPGoat : A Damn Vulnerable GCP Infrastructure

cloud-infrastructure-securitycloud-securityeducation+5
4561 year ago
STEWS preview

STEWS

GitHubpalindromelabs/stews

A Security Tool for Enumerating WebSockets

information-gatheringpenetration-testingvulnerability-scanners+1
3794 years ago
autopentest-ai preview

autopentest-ai

GitHubbhavsec/autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

crawlereducationexploit-frameworks+8
2307 months ago
ARTLAS preview

ARTLAS

GitHubmthbernardes/artlas

Apache Real Time Logs Analyzer System

incident-responseintrusion-detectionlog-analysis+3
1255 years ago
AI_Security_Top preview

AI_Security_Top

GitHubghostwolflab/ai_security_top

A structured knowledge base covering AI security fundamentals, threat modeling, red team offensive techniques, and blue team defenses, including LLM…

adversarial-attackai-securitycurated-resources+5
1516 months ago
lbmap preview

lbmap

GitHubwireghoul/lbmap

Advanced HTTP fingerprinting PoC

information-gatheringpenetration-testingreconnaissance+2
459 years ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
195 months ago
CVE-2020-23839 preview

CVE-2020-23839

GitHubboku7/cve-2020-23839

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

exploitationpayload-developmentpenetration-testing+3
125 years ago
Previous1…161718…33Next