Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2537 results
simple-maven preview

simple-maven

GitHubmindpatch/simple-maven

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

api-security-testingeducationlabs-practice+3
1 year ago
cve-2021-31290 preview

cve-2021-31290

GitHubqaisarafridi/cve-2021-31290

Proof-of-concept exploit for CVE-2021-31290, demonstrating a specific vulnerability in a web application. Intended for security testing and…

exploitationvulnerability-analysisweb-application-exploitation
3 years ago
CVE-2022-1040 preview

CVE-2022-1040

GitHubxmr110/cve-2022-1040

Proof-of-concept exploit for CVE-2022-1040, demonstrating exploitation of a web application vulnerability for security testing and research.

exploitationvulnerability-analysisweb-application-exploitation
2 years ago
wstg preview

wstg

GitHubowasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

educationlearning-paths-coursespenetration-testing+2
10.0k1 day ago
ChopChop preview

ChopChop

GitHubmichelin/chopchop

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

configuration-auditingdevsecopsinformation-gathering+2
7135 years ago
snorby preview

snorby

GitHubsnorby/snorby

Ruby On Rails Application For Network Security Monitoring

defensive-toolsincident-responseintrusion-detection+2
1.0k3 years ago
secfixes-tracker preview

secfixes-tracker

GitHubaquasecurity/secfixes-tracker

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

devsecopsinformation-gatheringsupply-chain-security+2
83 months ago
DVWA preview

DVWA

GitHubdigininja/dvwa

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

educationlabs-practicepenetration-testing+2
13.8k2 days ago
Awesome-WAF preview

Awesome-WAF

GitHub0xinfection/awesome-waf

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

curated-resourceseducationwaf-bypass+1
7.6k1 month ago
WebGoat.NET preview

WebGoat.NET

GitLabmbrandner-group/webgoat.net

Deliberately vulnerable .NET web application for learning common web security flaws through hands-on exercises covering XSS, SQL injection, and other…

ctfeducationlabs-practice+3
3 years ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
97417 days ago
OpenHunterAI preview

OpenHunterAI

GitHublumoslab-innovation/openhunterai

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

ai-securityapi-securityapi-security-testing+9
33025 days ago
engagement-mgr preview

engagement-mgr

GitHubleebaird/engagement-mgr

Engagement Manager is a web application for tracking offensive security engagements. It features a modern UI, built with Next.js, Prisma, and…

defensive-toolseducationincident-response+5
266 days ago
cve-2023-27372 preview

cve-2023-27372

GitHubg01d3nw01f/cve-2023-27372

Proof-of-concept exploit for CVE-2023-27372, demonstrating a remote code execution vulnerability in a web application. Intended for educational…

educationexploitationvulnerability-analysis+1
1 year ago
CVE-2021-21315-POC preview

CVE-2021-21315-POC

GitHubxmohamed0/cve-2021-21315-poc

Proof-of-concept exploit for CVE-2021-21315, demonstrating remote code execution in a web application framework. Intended for security testing and…

exploitationpayload-generationpenetration-testing+2
4 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubz3n70/cve-2023-23752

simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose

educationexploitationpenetration-testing+2
183 years ago
Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets- preview

Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-

GitHubartemcyberlab/project-project-chimera-exploiting-a-modern-wordpress-xxe-to-pillage-secrets-

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

educationexploitationinformation-gathering+8
11 year ago
Cve-2023-34804 preview

Cve-2023-34804

GitHubshahibakes/cve-2023-34804

Exploit for CVE-2023-34804, a vulnerability in a web application, providing proof-of-concept code for security testing.

exploitationpenetration-testingvulnerability-analysis
11 months ago
Previous1…456…100Next