Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
119 results
Forbidden-Buster preview

Forbidden-Buster

GitHubsn1r/forbidden-buster

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

fuzzingids-ips-evasionpenetration-testing+2
252
2 years ago
cloudbunny preview

cloudbunny

GitHubwarflop/cloudbunny

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

information-gatheringosintreconnaissance+2
3752 years ago
NextSecureScan preview

NextSecureScan

GitHubjmbowes/nextsecurescan

Next.js CVE-2025-29927 Vulnerability Scanner

exploitationpenetration-testingvulnerability-scanners+3
21 year ago
Freeze preview
Archived

Freeze

GitHuboptiv/freeze

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

exploit-frameworksids-ips-evasionpayload-development+8
1.5k3 years ago
CVE-2025-55182-checker preview

CVE-2025-55182-checker

GitHubharness-security-labs/cve-2025-55182-checker

Multi-technique vulnerability detector for CVE-2025-55182 in React/Next.js applications. Tests gadget chains, RCE payloads, and WAF bypass variants…

exploitationpayload-developmentpenetration-testing+3
110 months ago
waf-detector preview

waf-detector

GitHubammarion/waf-detector

🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness and…

defensive-toolsdns-analysisfingerprint-spoofing+8
1261 month ago
log4j-scanner preview

log4j-scanner

GitHubmanishkanyal/log4j-scanner

A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046

exploitationfuzzingpenetration-testing+3
14 years ago
WAFNinja preview

WAFNinja

GitHubkhalilbijjou/wafninja

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

fuzzingpenetration-testingwaf-bypass+1
8341 month ago
gotestwaf preview

gotestwaf

GitHubwallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

api-securityapi-security-testingpenetration-testing+4
1.8k10 days ago
recollapse preview

recollapse

GitHub0xacb/recollapse

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

fuzzingpayload-generationwaf-bypass+1
1.4k1 year ago
CVE-2025-55182-Waf preview

CVE-2025-55182-Waf

GitHubl0n3m4n/cve-2025-55182-waf

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

command-and-controlexploitationpayload-generation+5
29 months ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
54116 days ago
CVE-2025-55182-poc-tool preview

CVE-2025-55182-poc-tool

GitHubdh4v4l8/cve-2025-55182-poc-tool

Automated exploit tool for CVE-2025-55182 in Next.js React Server Components. Enables remote command execution with built-in WAF bypass, custom…

exploitationpenetration-testingremote-access-tool+3
310 months ago
WAF_buster preview

WAF_buster

GitHubviperbluff/waf_buster

Disrupt WAF by abusing SSL/TLS Ciphers

cryptographypenetration-testingwaf-bypass+1
487 years ago
Atlas preview

Atlas

GitHubm4ll0k/atlas

Quick SQLMap Tamper Suggester

penetration-testingvulnerability-scannerswaf-bypass+1
1.4k6 years ago
bypass-url-parser preview

bypass-url-parser

GitHublaluka/bypass-url-parser

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

information-gatheringpenetration-testingvulnerability-analysis+2
1.1k1 year ago
WhatWaf preview

WhatWaf

GitHubekultek/whatwaf

Detect and bypass web application firewalls and protection systems

penetration-testingvulnerability-scannerswaf-bypass+1
2.9k2 years ago
snuck preview

snuck

GitHubmauro-g/snuck

Automatic XSS filter bypass

fuzzingpenetration-testingwaf-bypass+2
9011 years ago
Previous1234567Next