Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
56 results
ftw preview

ftw

GitHubcoreruleset/ftw

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

devsecopspenetration-testingvulnerability-scanners+2
143
4 years ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9944 months ago
recollapse preview

recollapse

GitHub0xacb/recollapse

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

fuzzingpayload-generationwaf-bypass+1
1.4k1 year ago
XXStrike preview

XXStrike

GitHubanonmoty/xxstrike

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

dynamic-code-analysisfuzzingpenetration-testing+5
314 days ago
CVE-2024-4577-PHP-RCE preview

CVE-2024-4577-PHP-RCE

GitHuba-roshbaik/cve-2024-4577-php-rce

Exploit for CVE-2024-4577 PHP-CGI RCE on Windows, with WAF bypass and SSRF support. Provides multiple exploit variants for default, WAF, and SSRF…

exploitationpayload-generationpenetration-testing+3
2 years ago
XSS-LOADER preview

XSS-LOADER

GitHubcapture0x/xss-loader

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

payload-generationpenetration-testingwaf-bypass+2
6214 months ago
forbiddenpass preview

forbiddenpass

GitHubgotr00t0day/forbiddenpass

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

penetration-testingwaf-bypassweb-application-exploitation+1
2013 years ago
undetected-chromedriver preview

undetected-chromedriver

GitHubultrafunkamsterdam/undetected-chromedriver

Custom Selenium Chromedriver | Zero-Config | Passes ALL bot mitigation systems (like Distil / Imperva/ Datadadome / CloudFlare IUAM)

anti-botcaptcha-bypasscrawler+2
12.9k1 year ago
anubis-fetch preview

anubis-fetch

GitHubfzakaria/anubis-fetch

Like curl, but it gets past Anubis and Cloudflare bot-walls.

anti-botfingerprint-spoofingscripting-automation+3
3620 days ago
Bulk_403_Bypass preview

Bulk_403_Bypass

GitHubaardwolfsecurityltd/bulk_403_bypass

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

ids-ips-evasionpenetration-testingwaf-bypass+1
203 years ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5512 years ago
XSSFuzzer preview

XSSFuzzer

GitHubnytrorst/xssfuzzer

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

fuzzingpayload-generationwaf-bypass+1
1377 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubroxas-tan/cve-2021-44228

This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce

exploitationpayload-generationremote-access-tool+3
104 years ago
waf-bypass preview

waf-bypass

GitHubnemesida-waf/waf-bypass

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

api-security-testingpenetration-testingvulnerability-scanners+2
1.5k2 months ago
react2shell-ultimate preview

react2shell-ultimate

GitHubhackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

command-and-controlexploitationpayload-generation+4
1559 months ago
CVE-2021-44228-Apache-Log4j-Rce-main preview

CVE-2021-44228-Apache-Log4j-Rce-main

GitHubravid-checkmarx/cve-2021-44228-apache-log4j-rce-main

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI LDAP/RMI injection, payload compilation, and WAF bypass techniques for testing…

exploitationpayload-generationpenetration-testing+4
4 years ago
react2shell-CVE-2025-55182-poc preview

react2shell-CVE-2025-55182-poc

GitHubjoelvaiju/react2shell-cve-2025-55182-poc

Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing.

exploitationpayload-developmentpenetration-testing+3
39 months ago
react2shell-scanner preview

react2shell-scanner

GitHubassetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

exploitationpayload-generationpenetration-testing+3
2.5k9 months ago
Previous1234Next