Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
119 results
unwaf preview

unwaf

GitHubmmarting/unwaf

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
187
7 months ago
waf-detector preview

waf-detector

GitHubammarion/waf-detector

🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness and…

defensive-toolsdns-analysisfingerprint-spoofing+8
11727 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubbhideki/cve-2026-87902

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

exploitationpayload-developmentpenetration-testing+6
8 days ago
CVE-2026-1357 preview

CVE-2026-1357

GitHubsahmsec/cve-2026-1357

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

educationexploitationpenetration-testing+3
11 month ago
React2Shell-Scanner preview

React2Shell-Scanner

GitHubwi3memake/react2shell-scanner

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

api-security-testingdevsecopspenetration-testing+3
319 months ago
cve-2021-44228-waf-tests preview

cve-2021-44228-waf-tests

GitHubrobrankin/cve-2021-44228-waf-tests

Testing WAF protection against CVE-2021-44228 Log4Shell

defensive-toolspenetration-testingvulnerability-scanners+2
4 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubmaximofernandezriera/cve-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

exploitationpayload-developmentpenetration-testing+2
54 years ago
CVE-2026-21876 preview

CVE-2026-21876

GitHubmefhika120/cve-2026-21876

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
CVE-2026-24306 preview

CVE-2026-24306

GitHubexploreunknowed/cve-2026-24306

Proof-of-concept exploit for Azure Front Door privilege escalation (CVE-2026-24306) enabling routing rule injection, backend pool modification, and…

cloud-securityexploitationpenetration-testing+3
8 months ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
11 month ago
wp2shell-Exploit-Waf-Bypass preview

wp2shell-Exploit-Waf-Bypass

GitHubm4xsec/wp2shell-exploit-waf-bypass

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

api-security-testingexploitationpenetration-testing+4
51 month ago
burp-awesome-tls preview

burp-awesome-tls

GitHubsleeyax/burp-awesome-tls

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

anti-botfingerprint-spoofingids-ips-evasion+3
1.9k7 days ago
burp-vps-proxy preview

burp-vps-proxy

GitHubd3mondev/burp-vps-proxy

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

penetration-testingutilities-frameworkswaf-bypass+1
2491 year ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5512 years ago
ffufw preview

ffufw

GitHubpuzzlepeaches/ffufw

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

fuzzinginformation-gatheringpenetration-testing+2
1476 months ago
react2shell-scanner preview

react2shell-scanner

GitHuborwagodfather/react2shell-scanner

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

exploitationpenetration-testingwaf-bypass+3
189 months ago
crlf-powered-desync-scanner preview

crlf-powered-desync-scanner

GitHubt0xodile/crlf-powered-desync-scanner

Burp extension scanner for CRLF injection and HTTP desync attacks, using mutated probes, WAF false-positive checks, and optional…

exploitationpenetration-testingweb-application-exploitation+2
202 months ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
8971 month ago
Previous1234567Next