Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

api-securityapi-security-testingcrawler+12
38.4k2 days ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9853 months ago
commix preview

commix

GitHubcommixproject/commix

Automated All-in-One OS Command Injection Exploitation Tool

exploitationpenetration-testingvulnerability-scanners+2
5.8k1 day ago
recollapse preview

recollapse

GitHub0xacb/recollapse

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

fuzzingpayload-generationwaf-bypass+1
1.4k1 year ago
WAF_buster preview

WAF_buster

GitHubviperbluff/waf_buster

Disrupt WAF by abusing SSL/TLS Ciphers

cryptographypenetration-testingwaf-bypass+1
487 years ago
identYwaf preview

identYwaf

GitHubstamparm/identywaf

Blind WAF identification tool

information-gatheringvulnerability-scannerswaf-bypass+1
7472 years ago
impersonate-proxy preview

impersonate-proxy

GitHubytkoka/impersonate-proxy

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

fingerprint-spoofingimpersonation-toolspenetration-testing+3
3812 days ago
gotestwaf preview

gotestwaf

GitHubwallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-securityapi-security-testingpenetration-testing+4
1.8k1 year ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.1k1 day ago
nomore403 preview

nomore403

GitHubdevploit/nomore403

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

ids-ips-evasionpenetration-testingreconnaissance+3
1.9k2 months ago
Trust-Decision-Security preview

Trust-Decision-Security

GitHubak3zaidan/trust-decision-security

Reverse Engineer of Trust Decision Chinese Security

anti-botencryption-decryption-toolsfingerprint-spoofing+3
95 months ago
forbidden preview

forbidden

GitHubivan-sincek/forbidden

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

fuzzingids-ips-evasioninformation-gathering+5
25711 months ago
pFuzz preview

pFuzz

GitHubredsection/pfuzz

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

fuzzingpenetration-testingred-teaming+2
1615 years ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.5k4 months ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
341 day ago
Pegasus---Forbidden-Buster preview

Pegasus---Forbidden-Buster

GitHubsobri3195/pegasus---forbidden-buster

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

ids-ips-evasioninformation-gatheringpenetration-testing+3
41 year ago
CVE-2026-6875-PoC-Exploit preview

CVE-2026-6875-PoC-Exploit

GitHubtc4dy/cve-2026-6875-poc-exploit

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

exploitationlateral-movementpenetration-testing+7
31 month ago
hakoriginfinder preview

hakoriginfinder

GitHubhakluke/hakoriginfinder

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

information-gatheringreconnaissancewaf-bypass+1
1.1k1 month ago
Previous1234Next