Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
HawkScan preview

HawkScan

GitHubc0dejump/hawkscan

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

crawlerfuzzinginformation-gathering+5
463
2 months ago
cloudbunny preview

cloudbunny

GitHubwarflop/cloudbunny

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

information-gatheringosintreconnaissance+2
3762 years ago
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.4k1 day ago
TPASLog4ShellPoC preview
Archived

TPASLog4ShellPoC

GitHubcarlos-mesquita/tpaslog4shellpoc

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

educationexploitationpayload-generation+3
11 year ago
hakoriginfinder preview

hakoriginfinder

GitHubhakluke/hakoriginfinder

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

information-gatheringreconnaissancewaf-bypass+1
1.1k1 month ago
CF-Hero preview

CF-Hero

GitHubmusana/cf-hero

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

dns-analysisfingerprint-spoofinginformation-gathering+5
2.6k2 months ago
Vxscan preview

Vxscan

GitHubal0ne/vxscan

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

crawlerinformation-gatheringosint+7
1.8k6 years ago
byp4xx preview

byp4xx

GitHublobuhi/byp4xx

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

information-gatheringpenetration-testingwaf-bypass+2
1.9k3 years ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
89029 days ago
Zeus-Scanner preview

Zeus-Scanner

GitHubekultek/zeus-scanner

Advanced reconnaissance utility

captcha-bypassinformation-gatheringport-scanning+4
9987 years ago
bypass-firewalls-by-DNS-history preview

bypass-firewalls-by-DNS-history

GitHubvincentcox/bypass-firewalls-by-dns-history

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

dns-analysispenetration-testingreconnaissance+2
1.3k5 years ago
HatCloud preview

HatCloud

GitHubhatbashbr/hatcloud

discontinued

dns-analysisinformation-gatheringreconnaissance+2
5283 years ago
JSONBee preview

JSONBee

GitHubzigoo0/jsonbee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

crawlerinformation-gatheringpenetration-testing+2
7672 years ago
identYwaf preview

identYwaf

GitHubstamparm/identywaf

Blind WAF identification tool

information-gatheringvulnerability-scannerswaf-bypass+1
7472 years ago
bypass-url-parser preview

bypass-url-parser

GitHublaluka/bypass-url-parser

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

information-gatheringpenetration-testingvulnerability-analysis+2
1.1k1 year ago
webpwn3r preview

webpwn3r

GitHubzigoo0/webpwn3r

WebPwn3r - Web Applications Security Scanner.

information-gatheringpenetration-testingvulnerability-scanners+3
4594 years ago
crithit preview

crithit

GitHubcodingo/crithit

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

information-gatheringpenetration-testingvulnerability-scanners+2
2136 years ago
mssqli-duet preview

mssqli-duet

GitHubkeramas/mssqli-duet

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

information-gatheringpenetration-testingwaf-bypass
916 years ago
Previous12Next