Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
108 results
WAF-A-MoLE preview

WAF-A-MoLE

GitHubavalz/waf-a-mole

A guided mutation-based fuzzer for ML-based Web Application Firewalls

adversarial-attackfuzzingmachine-learning+2
2052 years ago
nGixshell preview

nGixshell

GitHubmateusverass/ngixshell

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

command-and-controlexploit-frameworkspayload-development+8
223 months ago
CVE-2025-55182-NextJS-Scanner-React2Shell-PoC preview

CVE-2025-55182-NextJS-Scanner-React2Shell-PoC

GitHubexrienz/cve-2025-55182-nextjs-scanner-react2shell-poc
command-and-controlexploitationpayload-generation+5
8 months ago
next.js_cve-2025-29927 preview

next.js_cve-2025-29927

GitHub0xpthree/next.js_cve-2025-29927
authentication-authorizationids-ips-evasionpenetration-testing+3
1 year ago
JSONBee preview

JSONBee

GitHubzigoo0/jsonbee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

crawlerinformation-gatheringpenetration-testing+2
7662 years ago
CVE-2026-60206-PoC-Exploit preview

CVE-2026-60206-PoC-Exploit

GitHubtc4dy/cve-2026-60206-poc-exploit

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

authentication-authorizationexploitationexploit-frameworks+8
427 days ago
CVE-2026-6875-PoC-Exploit preview

CVE-2026-6875-PoC-Exploit

GitHubtc4dy/cve-2026-6875-poc-exploit

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

exploitationlateral-movementpenetration-testing+7
31 month ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc
command-and-controlexploitationinformation-gathering+8
11 month ago
Magnohost-Vulnerabilities-pentest preview

Magnohost-Vulnerabilities-pentest

GitHubwyllowsec/magnohost-vulnerabilities-pentest

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

cloud-securitydatabase-securitydns-analysis+8
13 months ago
MeterPwrShell preview
Archived

MeterPwrShell

GitHubgetrektboy724/meterpwrshell

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

command-and-controlexploit-frameworksids-ips-evasion+7
2274 years ago
bunkerweb preview

bunkerweb

GitHubbunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

anti-botcloud-securitycontainer-security+6
10.8k1 month ago
htrace.sh preview

htrace.sh

GitHubtrimstray/htrace.sh

My simple Swiss Army knife for http/https troubleshooting and profiling.

dns-subdomain-enumerationinformation-gatheringpenetration-testing+3
3.9k1 year ago
dfir-malware-investigation preview

dfir-malware-investigation

GitHubsuyash-r-k/dfir-malware-investigation

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

digital-forensicseducationincident-response+9
6 months ago
web-threat-mitigation preview

web-threat-mitigation

GitHubbrunoh6/web-threat-mitigation

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

configuration-auditingdevsecopseducation+8
1 year ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
13 days ago
NGWAF preview

NGWAF

GitHubfa-pengfei/ngwaf

First iteration of ML based Feedback WAF

anomaly-detectiondefensive-toolseducation+7
603 years ago
propox preview

propox

GitHubtorxx666/propox
anti-botapi-security-testingdefensive-tools+6
17 months ago
Cerberus preview

Cerberus

GitHubyagamiilight/cerberus

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全…

dns-subdomain-enumerationinformation-gatheringpenetration-testing+6
6456 years ago
Previous123456Next