Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
180 results
Advanced-SQL-Injection-Cheatsheet preview

Advanced-SQL-Injection-Cheatsheet

GitHubkleiton0x00/advanced-sql-injection-cheatsheet

A cheat sheet that contains advanced queries for SQL Injection of all types.

curated-resourceseducationpenetration-testing+4
3.2k
3 years ago
http-request-smuggler preview

http-request-smuggler

GitHubportswigger/http-request-smuggler
dynamic-analysis-sandboxingpenetration-testingvulnerability-scanners+3
1.2k11 days ago
react2shell-scanner preview

react2shell-scanner

GitHubassetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

exploitationpayload-generationpenetration-testing+3
2.5k8 months ago
byp4xx preview

byp4xx

GitHublobuhi/byp4xx

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

information-gatheringpenetration-testingwaf-bypass+2
1.9k3 years ago
nowafpls preview

nowafpls

GitHubassetnote/nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

ids-ips-evasionpenetration-testingred-teaming+3
1.5k1 year ago
CVE-2021-44228-PoC-log4j-bypass-words preview

CVE-2021-44228-PoC-log4j-bypass-words

GitHubpuliczek/cve-2021-44228-poc-log4j-bypass-words

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

educationexploitationids-ips-evasion+6
9494 years ago
CVE-2025-55182-research preview

CVE-2025-55182-research

GitHubejpir/cve-2025-55182-research

CVE-2025-55182 POC

educationexploitationpapers-research+4
7948 months ago
XSS-LOADER preview

XSS-LOADER

GitHubcapture0x/xss-loader

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

payload-generationpenetration-testingwaf-bypass+2
6223 months ago
Shockwave-OSS preview

Shockwave-OSS

GitHubgal-nagli/shockwave-oss
curated-resourceseducationfuzzing+9
7502 years ago
webpwn3r preview

webpwn3r

GitHubzigoo0/webpwn3r

WebPwn3r - Web Applications Security Scanner.

information-gatheringpenetration-testingvulnerability-scanners+3
4594 years ago
XSS-Bypass-Filters preview

XSS-Bypass-Filters

GitHubedr4/xss-bypass-filters

Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…

curated-resourceseducationpayload-development+4
5981 year ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses
curated-resourcespayload-developmentpenetration-testing+3
5502 years ago
Log4j2-CVE-2021-44228 preview

Log4j2-CVE-2021-44228

GitHubjas502n/log4j2-cve-2021-44228

Remote Code Injection In Log4j

educationexploitationpayload-generation+4
4694 years ago
DAws preview

DAws

GitHubdotcppfile/daws

Advanced Web Shell

ids-ips-evasionpayload-generationpenetration-testing+6
5819 years ago
BurpSuiteHTTPSmuggler preview

BurpSuiteHTTPSmuggler

GitHubnccgroup/burpsuitehttpsmuggler

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

ids-ips-evasionpenetration-testingvulnerability-analysis+3
7447 years ago
spring4shell-scan preview

spring4shell-scan

GitHubfullhunt/spring4shell-scan

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

exploitationvulnerability-scannerswaf-bypass+1
6564 years ago
bantam preview

bantam

GitHubgellin/bantam

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

command-and-controlencryption-decryption-toolsids-ips-evasion+5
2823 years ago
Nextjs_RCE_Exploit_Tool preview

Nextjs_RCE_Exploit_Tool

GitHubpyroxenites/nextjs_rce_exploit_tool

Exploit for CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+6
1428 months ago
Previous1…567…10Next