Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13024 results
CVE-2024-6670 preview

CVE-2024-6670

GitHubsinsinology/cve-2024-6670

Proof-of-concept exploit for Progress WhatsUp Gold SQL injection authentication bypass (CVE-2024-6670). Includes root cause analysis and automated…

authentication-authorizationexploitationpenetration-testing+2
35
2 years ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.0k16h 5m ago
SafeLine preview

SafeLine

GitHubchaitin/safeline

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

anti-botapi-securityapi-security-testing+8
22.5k7 days ago
bunkerweb preview

bunkerweb

GitHubbunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

anti-botcloud-securitycontainer-security+6
10.9k11 days ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

anti-botids-ips-evasionmisconfiguration+4
3.3k2 days ago
awswaf preview

awswaf

GitHubxkiian/awswaf

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

anti-botcaptcha-bypassids-ips-evasion+3
3581 year ago
Predator preview

Predator

GitHubs0md3v/predator

Anti-Automation System

anti-botcrawlerids-ips-evasion+3
1275 years ago
vercel-botid preview

vercel-botid

GitHubxkiian/vercel-botid

Vercel BotID Solver "X-Is-Human" using 100% golang

anti-botcaptcha-bypassweb-application-exploitation+1
678 months ago
EpSiLoNPoInTlnk preview

EpSiLoNPoInTlnk

GitHubepsilonpointori/epsilonpointlnk

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

anti-botexploitationmalware-analysis+4
23 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubtinashelorenzi/cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182, a critical unauthenticated RCE in React Server Components. Includes automated Python exploit, technical…

educationexploitationintrusion-detection+6
8 months ago
PoC---CVE-2023-26482-RCE-LAB-Nextcloud preview

PoC---CVE-2023-26482-RCE-LAB-Nextcloud

GitHubisabbii/poc---cve-2023-26482-rce-lab-nextcloud

Docker-based lab reproducing CVE-2023-26482 (Nextcloud RCE) with automated exploit script for educational vulnerability analysis and exploitation…

educationexploitationlabs-practice+5
6 months ago
CVE-2026-60137_CVE-2026-63030 preview

CVE-2026-60137_CVE-2026-63030

GitHubdungsocool/cve-2026-60137_cve-2026-63030

WordPress unauthenticated RCE exploit combining route confusion and SQL injection. Automated script, lab setup, and detailed vulnerability analysis…

educationexploitationlabs-practice+3
1 month ago
CVE-2026-49777 preview

CVE-2026-49777

GitHubizxci/cve-2026-49777

Python exploit for CVE-2026-49777, a critical unauthenticated RCE in ShapedPlugin Product Slider Pro for WooCommerce. Includes automated detection…

code-analysiseducationexploitation+3
2 months ago
http-request-smuggling preview

http-request-smuggling

GitHubanshumanpattnaik/http-request-smuggling

CLI tool to detect HTTP Request Smuggling vulnerabilities using time-delay analysis with built-in CL.TE and TE.CL payloads for automated security…

penetration-testingvulnerability-scannersweb-application-exploitation+1
5444 years ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
3414h 20m ago
CVE-2022-29056 preview

CVE-2022-29056

GitHubchessredoffsec/cve-2022-29056

Automated Python script with GUI for testing login endpoint responses with configurable payload sizes, designed for educational security testing and…

educationexploitationpenetration-testing+2
11 year ago
CVE-2023-26208 preview

CVE-2023-26208

GitHubchessredoffsec/cve-2023-26208

Python script with GUI for automated payload testing against login endpoints, designed for educational exploitation simulation and vulnerability…

educationexploitationpenetration-testing+3
11 year ago
R2S_CVE-2025-55182 preview

R2S_CVE-2025-55182

GitHubeytannatye/r2s_cve-2025-55182

Automated vulnerability scanner for CVE-2025-55182 (Next.js RCE) with RCE detection, timing analysis, version identification, WAF detection, and…

educationexploitationpenetration-testing+3
8 months ago
Previous12…100Next