Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
anubis-fetch preview

anubis-fetch

GitHubfzakaria/anubis-fetch

Like curl, but it gets past Anubis and Cloudflare bot-walls.

anti-botfingerprint-spoofingscripting-automation+3
32
1 month ago
Trust-Decision-Security preview

Trust-Decision-Security

GitHubak3zaidan/trust-decision-security

Reverse Engineer of Trust Decision Chinese Security

anti-botencryption-decryption-toolsfingerprint-spoofing+3
95 months ago
crowdsec preview

crowdsec

GitHubcrowdsecurity/crowdsec

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

anti-botdefensive-toolsids-ips-evasion+6
14.8k3 days ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k2 months ago
cpanel-sessionscribe preview

cpanel-sessionscribe

GitHubrfxn/cpanel-sessionscribe

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery…

defensive-toolsexploitationforensics+7
143 months ago
Check Risk WAF preview

Check Risk WAF

GitLabcheck-risk-waf/check-risk-waf

Cloud-based Web Application Firewall (WAF) providing L3/L7 protection against SQLi, XSS, DDoS, and bot attacks. Features AI assistant, anti-bot…

anti-botapi-securitycloud-security+3
3 months ago
CVE-2017-5638-Attack-and-Defense preview

CVE-2017-5638-Attack-and-Defense

GitHubacharaf06/cve-2017-5638-attack-and-defense

Docker-based security lab demonstrating Apache Struts2 S2-045 (CVE-2017-5638) exploitation and defense, featuring vulnerable and patched applications…

defensive-toolseducationlabs-practice+4
18 months ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4071 year ago
cve-2021-44228-waf-tests preview

cve-2021-44228-waf-tests

GitHubrobrankin/cve-2021-44228-waf-tests

Testing WAF protection against CVE-2021-44228 Log4Shell

defensive-toolspenetration-testingvulnerability-scanners+2
4 years ago
Invisi-Shell preview

Invisi-Shell

GitHubomerya/invisi-shell

Hide your Powershell script in plain sight. Bypass all Powershell security features

defensive-toolsexploitationids-ips-evasion+9
1.3k7 years ago
wafaray preview

wafaray

GitHubalt3kx/wafaray

Enhance your malware detection with WAF + YARA (WAFARAY)

defensive-toolslabs-practicemalware-analysis+4
1083 years ago
NGWAF preview

NGWAF

GitHubfa-pengfei/ngwaf

First iteration of ML based Feedback WAF

anomaly-detectiondefensive-toolseducation+7
603 years ago
anti-jndi preview

anti-jndi

GitHubph0lk3r/anti-jndi

Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.

defensive-toolsids-ips-evasionmisconfiguration+3
24 years ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
4 months ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.0k2 days ago
nodriver preview

nodriver

GitHubultrafunkamsterdam/nodriver

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

anti-botcaptcha-bypasscrawler+8
4.7k3 months ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

anti-botids-ips-evasionmisconfiguration+4
3.3k3 days ago
undetected-httpx preview

undetected-httpx

GitHubmichele0303/undetected-httpx

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

anti-botfingerprint-spoofingids-ips-evasion+5
217 months ago
Previous12Next