Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Web Security

Tools for testing, exploiting, and securing web applications and APIs.

Kitploit recommended

Top tools

10 selected
zaproxy preview#1

zaproxy

GitHubzaproxy/zaproxy
15.6k1 day ago
nuclei preview#2

nuclei

GitHubprojectdiscovery/nuclei
30.4k2 days ago
sqlmap preview#3

sqlmap

GitHubsqlmapproject/sqlmap
38.2k3 days ago
ffuf preview#4

ffuf

GitHubffuf/ffuf
16.5k2 days ago
dirsearch preview#5

dirsearch

GitHubmaurosoria/dirsearch
14.6k12h 57m ago
feroxbuster preview#6

feroxbuster

GitHubepi052/feroxbuster
8.0k6 days ago
nikto preview#7

nikto

GitHubsullo/nikto
10.6k28 days ago
wpscan preview#8

wpscan

GitHubwpscanteam/wpscan
9.7k22 days ago
XSStrike preview#9

XSStrike

GitHubs0md3v/xsstrike
15.1k1 year ago
wapiti preview#10

wapiti

GitHubwapiti-scanner/wapiti
1.9k27 days ago
NewestRelevanceMost popularRecently updated
18499 results
log4jcheck preview

log4jcheck

GitHubnorthwavesecurity/log4jcheck

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

reconnaissancevulnerability-scannersweb-vulnerability-scanners+3
1264 years ago
wotop preview

wotop

GitHubnishitm/wotop

Web on top of any protocol

web-proxies-interceptionnetwork-security
1116 years ago
NTLMRecon preview

NTLMRecon

GitHubpraetorian-inc/ntlmrecon

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.

reconnaissanceinformation-gatheringweb-security+2
1185 months ago
notionterm preview

notionterm

GitHubariary/notionterm

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

payload-generationexploitationreverse-engineering+3
1373 years ago
CVE-2019-11043 preview

CVE-2019-11043

GitHubjas502n/cve-2019-11043

php-fpm+Nginx RCE

payload-generationvulnerability-analysisexploitation+3
1056 years ago
proxyshell preview

proxyshell

GitHubhorizon3ai/proxyshell

Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207

reconnaissancevulnerability-analysisexploitation+3
1215 years ago
CitrixHoneypot preview

CitrixHoneypot

GitHubmalwaretech/citrixhoneypot

Detect and log CVE-2019-19781 scan and exploitation attempts.

vulnerability-scannersweb-securitythreat-intelligence+2
1206 years ago
ffufPostprocessing preview

ffufPostprocessing

GitHubdsecuredcom/ffufpostprocessing

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

reconnaissanceinformation-gatheringweb-security+3
1441 year ago
CVE-2017-11882-metasploit preview

CVE-2017-11882-metasploit

GitHub0x09al/cve-2017-11882-metasploit

This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerabilit…

penetration-testing-frameworksexploit-frameworkspayload-generation+3
988 years ago
hakuin preview

hakuin

GitHubpruzko/hakuin

A blazing fast and fully configurable Blind SQL Injection optimization and automation framework.

vulnerability-scannersweb-securitypenetration-testing
1411 year ago
HTTP3-attacks preview

HTTP3-attacks

GitHubefchatz/http3-attacks

Educational exploit scripts for HTTP/3 attacks (CVE-2022-30592) including HTTP3-loris, HTTP3-stream, and HTTP3-flooding, tested against QUIC-enabled…

vulnerability-analysisexploitationweb-security+2
813 years ago
cloudrasp-log4j2 preview

cloudrasp-log4j2

GitHubboundaryx/cloudrasp-log4j2

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

defensive-toolsexploit-frameworksvulnerability-analysis+1
1264 years ago
warf preview

warf

GitHubiamnihal/warf

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

osintreconnaissanceinformation-gathering+3
1944 years ago
OSWE-Labs-Poc preview

OSWE-Labs-Poc

GitHubsvdwi/oswe-labs-poc

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

vulnerability-analysisexploitationweb-application-exploitation+4
1295 years ago
fprobe preview

fprobe

GitHubtheblackturtle/fprobe

Take a list of domains/subdomains and probe for working http/https server.

reconnaissancenetwork-mappinginformation-gathering+1
1936 years ago
log4shell-tools preview

log4shell-tools

GitHubalexbakker/log4shell-tools

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

vulnerability-scannersvulnerability-analysisexploitation+3
862 years ago
Admin-Panel_Finder preview

Admin-Panel_Finder

GitHubmoeinfatehi/admin-panel_finder

A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

reconnaissancevulnerability-scannersinformation-gathering+2
1234 years ago
scansploit preview

scansploit

GitHubhuntergregal/scansploit

Exploit using barcodes, QRcodes, earn13, datamatrix

payload-generationexploitationweb-security+1
11610 years ago
Previous1…99100Next