Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
203 results
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

anti-botids-ips-evasionmisconfiguration+4
3.2k
4 days ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.8k2 days ago
Advanced-SQL-Injection-Cheatsheet preview

Advanced-SQL-Injection-Cheatsheet

GitHubkleiton0x00/advanced-sql-injection-cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

curated-resourceseducationpenetration-testing+4
3.2k3 years ago
http-request-smuggler preview

http-request-smuggler

GitHubportswigger/http-request-smuggler

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

dynamic-analysis-sandboxingpenetration-testingvulnerability-scanners+3
1.2k14 days ago
nodriver preview

nodriver

GitHubultrafunkamsterdam/nodriver

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

anti-botcaptcha-bypasscrawler+8
4.7k3 months ago
HackBar preview

HackBar

GitHubd3vilbug/hackbar

HackBar plugin for Burpsuite

penetration-testingwaf-bypassweb-application-exploitation+1
1.6k5 years ago
Shockwave-OSS preview

Shockwave-OSS

GitHubgal-nagli/shockwave-oss

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

curated-resourceseducationfuzzing+9
7502 years ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5502 years ago
Log4j2-CVE-2021-44228 preview

Log4j2-CVE-2021-44228

GitHubjas502n/log4j2-cve-2021-44228

CVE-2021-44228 Log4j2 remote code injection exploit with JNDI payload generation, WAF bypass techniques, and practical exploitation walkthrough for…

educationexploitationpayload-generation+4
4694 years ago
spring4shell-scan preview

spring4shell-scan

GitHubfullhunt/spring4shell-scan

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

exploitationvulnerability-scannerswaf-bypass+1
6564 years ago
Nextjs_RCE_Exploit_Tool preview

Nextjs_RCE_Exploit_Tool

GitHubpyroxenites/nextjs_rce_exploit_tool

Exploit for CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+6
1428 months ago
Imperva_gzip_WAF_Bypass preview

Imperva_gzip_WAF_Bypass

GitHubbishopfox/imperva_gzip_waf_bypass

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

ids-ips-evasionpenetration-testingvulnerability-analysis+2
1684 years ago
react2shell-ultimate preview

react2shell-ultimate

GitHubhackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

command-and-controlexploitationpayload-generation+4
1528 months ago
xss_vulnerability_challenges preview

xss_vulnerability_challenges

GitHubmoeinfatehi/xss_vulnerability_challenges

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

educationlabs-practicepenetration-testing+3
1194 years ago
nmap-log4shell preview

nmap-log4shell

GitHubgiterlizzi/nmap-log4shell

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

exploitationnetwork-securitypayload-generation+4
794 years ago
CVE-2025-55182-scanner preview

CVE-2025-55182-scanner

GitHubfatguru/cve-2025-55182-scanner

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

exploitationpenetration-testingred-teaming+4
1128 months ago
watchTowr-vs-Fortiweb-AuthBypass preview

watchTowr-vs-Fortiweb-AuthBypass

GitHubwatchtowrlabs/watchtowr-vs-fortiweb-authbypass

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

exploitationpenetration-testingvulnerability-analysis+2
769 months ago
waf-tester preview

waf-tester

GitHubkpomin57/waf-tester

A program for testing WAF functionality

api-security-testingeducationids-ips-evasion+5
263 months ago
Previous1…345…12Next