Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

fingerprint-spoofinginformation-gatheringosint+6
886
18 days ago
xpath preview

xpath

GitHubblue0x1/xpath

Multi-technique XPath injection scanner with error-based, boolean/time-based blind, union, and auth bypass detection. Supports visible and blind data…

information-gatheringpenetration-testingvulnerability-scanners+3
31 month ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

command-and-controlexploitationinformation-gathering+8
11 month ago
HawkScan preview

HawkScan

GitHubc0dejump/hawkscan

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

crawlerfuzzinginformation-gathering+5
4631 month ago
CF-Hero preview

CF-Hero

GitHubmusana/cf-hero

Uncovers origin IPs of Cloudflare-protected web apps using DNS records, historical DNS, Shodan/Censys/ZoomEye OSINT, and related-domain correlation…

dns-analysisfingerprint-spoofinginformation-gathering+5
2.6k2 months ago
Dorkwright preview

Dorkwright

GitHubsan-tus/dorkwright

From Dork to Download: Automating Google Dorks with Playwright

captcha-bypasscrawlerinformation-gathering+3
493 months ago
ore_react2shell_scanner preview

ore_react2shell_scanner

GitHubrapticore/ore_react2shell_scanner

Automated scanner for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Features async endpoint discovery, subdomain…

exploitationpenetration-testingreconnaissance+4
25 months ago
R4venzCl4w preview

R4venzCl4w

GitHubsc4rfurry/r4venzcl4w

A Modular Framework for Pentesters and Bug Hunters written in python.

information-gatheringnetwork-mappingosint+4
57 months ago
r2s preview

r2s

GitHubzamdevio/r2s

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

command-and-controlexploitationinformation-gathering+5
28 months ago
bypass-url-parser preview

bypass-url-parser

GitHublaluka/bypass-url-parser

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

information-gatheringpenetration-testingvulnerability-analysis+2
1.1k1 year ago
identYwaf preview

identYwaf

GitHubstamparm/identywaf

Blind WAF identification tool that recognizes over 80 web protection systems by analyzing responses to non-destructive offensive payloads, enabling…

information-gatheringvulnerability-scannerswaf-bypass+1
7432 years ago
cloudbunny preview

cloudbunny

GitHubwarflop/cloudbunny

Discovers origin server IP addresses behind WAF-protected websites by querying Shodan, Censys, and ZoomEye search engines for domain information.

information-gatheringosintreconnaissance+2
3762 years ago
JSONBee preview

JSONBee

GitHubzigoo0/jsonbee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

crawlerinformation-gatheringpenetration-testing+2
7662 years ago
HatCloud preview

HatCloud

GitHubhatbashbr/hatcloud

Ruby-based tool to bypass Cloudflare protection by discovering the origin server's real IP address through DNS analysis, useful for testing server…

dns-analysisinformation-gatheringreconnaissance+2
5283 years ago
byp4xx preview

byp4xx

GitHublobuhi/byp4xx

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

information-gatheringpenetration-testingwaf-bypass+2
1.9k3 years ago
woodpecker-plugins preview

woodpecker-plugins

GitHubjas502n/woodpecker-plugins

Plugins for Woodpecker framework: WebLogic T3/IIOP scanning, credential extraction, Spring Boot API scan, Log4j2 bypass payloads, and Java exec…

information-gatheringpassword-attackspayload-generation+5
114 years ago
webpwn3r preview

webpwn3r

GitHubzigoo0/webpwn3r

Automated web application security scanner detecting and exploiting RCE, SQL injection, and XSS vulnerabilities with WAF bypass payloads and backend…

information-gatheringpenetration-testingvulnerability-scanners+3
4594 years ago
crithit preview

crithit

GitHubcodingo/crithit

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

information-gatheringpenetration-testingvulnerability-scanners+2
2136 years ago
Previous12Next