Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
98 results
CVE-2024-50379-PoC preview

CVE-2024-50379-PoC

GitHubisee857/cve-2024-50379-poc

Batch detection script for Apache Tomcat CVE-2024-50379 race condition remote code execution vulnerability. Supports single and mass scanning via…

exploitationpenetration-testingvulnerability-analysis+3
24
1 year ago
cisco-CVE-2023-20198-tester preview

cisco-CVE-2023-20198-tester

GitHubsecurityphoenix/cisco-cve-2023-20198-tester

cisco-CVE-2023-20198-tester

exploitationnetwork-securitypenetration-testing+2
2 years ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
366 years ago
pivotnacci preview

pivotnacci

GitHubblackarrowsec/pivotnacci

A tool to make socks connections through HTTP agents

lateral-movementpenetration-testingred-teaming+1
7255 years ago
requests-ip-rotator preview

requests-ip-rotator

GitHubge0rg3/requests-ip-rotator

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

crawlerids-ips-evasioninformation-gathering+5
1.7k3 months ago
ipsourcebypass preview

ipsourcebypass

GitHubp0dalirius/ipsourcebypass

This Python script can be used to bypass IP source restrictions using HTTP headers.

information-gatheringpenetration-testingvulnerability-analysis+1
4061 year ago
cloudformation-waf-acl preview

cloudformation-waf-acl

GitLabfer1035_aws/cloudformation/cloudformation-waf-acl

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

cloud-securityconfiguration-auditingmisconfiguration+2
3 months ago
fireprox preview

fireprox

GitHubustayready/fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

api-securitycloud-securityinformation-gathering+5
2.3k4 years ago
CloakQuest3r preview

CloakQuest3r

GitHubspyboy-productions/cloakquest3r

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

cloud-securitydns-analysisdns-subdomain-enumeration+7
2.3k9 months ago
shodanwave preview

shodanwave

GitHubjimywork/shodanwave

Shodanwave is a tool for exploring and obtaining information from Netwave IP Camera.

exploitationinformation-gatheringiot-security+5
2688 years ago
unwaf preview

unwaf

GitHubmmarting/unwaf

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
1927 months ago
bing-ip2hosts preview

bing-ip2hosts

GitHuburbanadventurer/bing-ip2hosts

bingip2hosts is a Bing.com web scraper that discovers websites by IP address

crawlerinformation-gatheringosint+3
1405 years ago
subdosec preview

subdosec

GitHubxcapri/subdosec

Fast, accurate subdomain takeover scanner with zero false positives. Detects vulnerable subdomains, collects metadata (IP, CNAME, title, status…

information-gatheringreconnaissancesubdomain-enumeration+2
621 month ago
XIP preview

XIP

GitHubimmunit/xip

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

ids-ips-evasioninformation-gatheringpenetration-testing+2
767 years ago
url-status-checker preview

url-status-checker

GitHubblack-scorp10/url-status-checker

Async Python CLI tool for bulk URL status checking with color-coded HTTP response categorization, IP tracking, and redirect following for web service…

general-purpose-utilitiesinformation-gatheringweb-security
511 year ago
ip-obfuscation preview

ip-obfuscation

GitHubhackinglz/ip-obfuscation

Generates obfuscated IP addresses and URLs using DWORD, octal, hex, IPv6-mapped, and fake-domain @ tricks for penetration testing, phishing…

educationimpersonation-toolspenetration-testing+6
4710 months ago
Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed preview

Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed

GitHubmrcl0wnlab/nuclei-template-cve-2022-1388-big-ip-icontrol-rest-exposed

This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP…

exploitationinformation-gatheringpenetration-testing+3
284 years ago
CVE-2000-0649 preview

CVE-2000-0649

GitHubrafaelh/cve-2000-0649

Test for CVE-2000-0649, and return an IP address if vulnerable

exploitationinformation-gatheringpenetration-testing+3
82 years ago
Previous123456Next