Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
87 results
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9803 months ago
SafeLine preview

SafeLine

GitHubchaitin/safeline

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

anti-botapi-securityapi-security-testing+8
22.4k2 days ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

api-securityintrusion-detectionlog-analysis+3
9.7k1 month ago
commix preview

commix

GitHubcommixproject/commix

Automated All-in-One OS Command Injection Exploitation Tool

exploitationpenetration-testingvulnerability-scanners+2
5.8k1 day ago
log4j-scan preview

log4j-scan

GitHubfullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

dns-analysisexploitationvulnerability-scanners+2
3.4k3 years ago
Advanced-SQL-Injection-Cheatsheet preview

Advanced-SQL-Injection-Cheatsheet

GitHubkleiton0x00/advanced-sql-injection-cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

curated-resourceseducationpenetration-testing+4
3.2k3 years ago
WhatWaf preview

WhatWaf

GitHubekultek/whatwaf

Detect and bypass web application firewalls and protection systems

penetration-testingvulnerability-scannerswaf-bypass+1
2.9k2 years ago
Atlas preview

Atlas

GitHubm4ll0k/atlas

Quick SQLMap Tamper Suggester

penetration-testingvulnerability-scannerswaf-bypass+1
1.4k5 years ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
88614 days ago
spring4shell-scan preview

spring4shell-scan

GitHubfullhunt/spring4shell-scan

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

exploitationvulnerability-scannerswaf-bypass+1
6564 years ago
CRLFsuite preview

CRLFsuite

GitHubraghavd3v/crlfsuite

The most powerful CRLF injection (HTTP Response Splitting) scanner.

penetration-testingvulnerability-scannerswaf-bypass+2
5982 years ago
lightbulb-framework preview

lightbulb-framework

GitHublightbulb-framework/lightbulb-framework

Tools for auditing WAFS

fuzzingpenetration-testingvulnerability-analysis+2
4655 years ago
sqlmap-ai preview

sqlmap-ai

GitHubatiilla/sqlmap-ai

This script automates SQL injection testing using SQLMap with AI-powered decision making.

payload-generationpenetration-testingvulnerability-scanners+3
4456 months ago
ftw preview
Archived

ftw

GitHubfastly/ftw

Framework for Testing WAFs (FTW!)

devsecopspenetration-testingvulnerability-scanners+2
2633 years ago
wafpass preview

wafpass

GitHubwafpassproject/wafpass

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

penetration-testingvulnerability-analysiswaf-bypass+2
2222 years ago
CVE-2024-4577-PHP-RCE preview

CVE-2024-4577-PHP-RCE

GitHubxcanwin/cve-2024-4577-php-rce

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。

exploitationpayload-developmentpenetration-testing+3
1612 years ago
react2shell-ultimate preview

react2shell-ultimate

GitHubhackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

command-and-controlexploitationpayload-generation+4
1528 months ago
ftw preview

ftw

GitHubcoreruleset/ftw

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

devsecopspenetration-testingvulnerability-scanners+2
1424 years ago
Previous12345Next