Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
unwaf preview

unwaf

GitHubmmarting/unwaf

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
187
7 months ago
waf-detector preview

waf-detector

GitHubammarion/waf-detector

🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness and…

defensive-toolsdns-analysisfingerprint-spoofing+8
11727 days ago
IfritProxy preview

IfritProxy

GitHub0tsystemspublicrepos/ifritproxy

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

ai-securitydefensive-toolsids-ips-evasion+7
18 months ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.6k5 months ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5606 months ago
OpenDoor preview

OpenDoor

GitHubstanislav-web/opendoor

OWASP Web Recon & Directory Discovery Platform

information-gatheringpenetration-testingreconnaissance+4
1.0k2 months ago
Reconator preview

Reconator

GitHubgokulapap/reconator

Automated reconnaissance framework with 17+ modules for subdomain enumeration, directory brute-forcing, JS/link mining, WAF fingerprinting, and…

dns-subdomain-enumerationfuzzinginformation-gathering+6
4391 month ago
Cerberus preview

Cerberus

GitHubyagamiilight/cerberus

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全…

dns-subdomain-enumerationinformation-gatheringpenetration-testing+6
6436 years ago
undetected-httpx preview

undetected-httpx

GitHubmichele0303/undetected-httpx

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

anti-botfingerprint-spoofingids-ips-evasion+5
218 months ago
CVE-2024-21546 preview

CVE-2024-21546

GitHubdigitalsurgn/cve-2024-21546

Automated exploit toolkit and detection template for CVE-2024-21546, an unauthenticated RCE in UniSharp Laravel Filemanager, with WAF evasion and…

code-analysisexploitationpayload-development+4
28 days ago
ffufw preview

ffufw

GitHubpuzzlepeaches/ffufw

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

fuzzinginformation-gatheringpenetration-testing+2
1476 months ago
wpx preview

wpx

GitHubgreg-randall/wpx

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

api-security-testingcrawlerinformation-gathering+6
106 months ago
cloudbunny preview

cloudbunny

GitHubwarflop/cloudbunny

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

information-gatheringosintreconnaissance+2
3752 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsentinelxofficial/cve-2025-55182

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

exploitationids-ips-evasionpayload-development+5
13 months ago
CVE-2025-55182-NextJS-Scanner-React2Shell-PoC preview

CVE-2025-55182-NextJS-Scanner-React2Shell-PoC

GitHubexrienz/cve-2025-55182-nextjs-scanner-react2shell-poc

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

command-and-controlexploitationpayload-generation+5
9 months ago
cve-2025-64446-fortiweb-exploit preview

cve-2025-64446-fortiweb-exploit

GitHuban5i/cve-2025-64446-fortiweb-exploit

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

educationexploitationpayload-development+5
110 months ago