Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.7k2 days ago
MHDDoS preview

MHDDoS

GitHubmatrixtm/mhddos

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

dns-analysisids-ips-evasionnetwork-mapping+4
16.6k3 days ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
336 days ago
bunkerweb preview

bunkerweb

GitHubbunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

anti-botcloud-securitycontainer-security+6
10.9k9 days ago
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.6k10 days ago
wp2shell-Exploit-Waf-Bypass preview

wp2shell-Exploit-Waf-Bypass

GitHubm4xsec/wp2shell-exploit-waf-bypass

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

api-security-testingexploitationpenetration-testing+4
421 days ago
waf-bypass preview

waf-bypass

GitHubnemesida-waf/waf-bypass

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

api-security-testingpenetration-testingvulnerability-scanners+2
1.5k1 month ago
janusec preview

janusec

GitHubjanusec/janusec

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

api-securityauthenticationcloud-security+8
1.2k1 month ago
CVE-2026-21876 preview

CVE-2026-21876

GitHubdaytriftnewgen/cve-2026-21876

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

ids-ips-evasionpenetration-testingvulnerability-analysis+3
2 months ago
pythia-sql-clairvoyance preview

pythia-sql-clairvoyance

GitHubrodhnin/pythia-sql-clairvoyance

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlerdevsecops+5
24 months ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
4 months ago
CVE-2022-31813 preview

CVE-2022-31813

GitHubyiliufeng168/cve-2022-31813

Demonstrates CVE-2022-31813 Apache HTTP Server bypass using X-Real-IP header manipulation to evade access controls, with a Docker-based test…

exploitationpenetration-testingvulnerability-analysis+2
6 months ago
autopentest-ai preview

autopentest-ai

GitHubbhavsec/autopentest-ai

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

crawlereducationexploit-frameworks+8
2176 months ago
CVE-2026-21876 preview

CVE-2026-21876

GitHubmefhika120/cve-2026-21876

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

exploitationpenetration-testingvulnerability-analysis+2
7 months ago
CVE-2017-5638-Attack-and-Defense preview

CVE-2017-5638-Attack-and-Defense

GitHubacharaf06/cve-2017-5638-attack-and-defense

Docker-based security lab demonstrating Apache Struts2 S2-045 (CVE-2017-5638) exploitation and defense, featuring vulnerable and patched applications…

defensive-toolseducationlabs-practice+4
18 months ago
React2Shell preview

React2Shell

GitHubsho-luv/react2shell

CVE-2025-55182 security test kit: CLI scanner + Chrome extension + Nuclei templates + Docker lab.

ctfeducationexploit-frameworks+7
108 months ago
React2Shell-CVE-2025-55182-Advanced-Scanner preview

React2Shell-CVE-2025-55182-Advanced-Scanner

GitHubysfcndgr/react2shell-cve-2025-55182-advanced-scanner

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

command-and-controlexploitationpayload-generation+4
8 months ago
react2shell-exploit preview

react2shell-exploit

GitHubrubensuxo-eh/react2shell-exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

command-and-controleducationexploit-frameworks+6
48 months ago
Previous12Next