Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
http-stalling-detector preview

http-stalling-detector

GitHubcorelight/http-stalling-detector

Detect HTTP stalling attacks like slowloris with Bro

anomaly-detectiondefensive-toolsintrusion-detection+2
19
8 years ago
CVE-2021-31166 preview

CVE-2021-31166

GitHubcorelight/cve-2021-31166

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

exploitationintrusion-detectionnetwork-security+3
121 year ago
gophish preview

gophish

GitHubonvio/gophish

Gophish with Malicious Attachment and HTTP redirect support

email-securityphishingphishing-tools+2
132 years ago
httpx-action preview

httpx-action

GitHubprojectdiscovery/httpx-action

HTTP Web Server probing

devsecopsinformation-gatheringnetwork-mapping+3
142 years ago
CVE-2024-4577-Nuclei-Template preview

CVE-2024-4577-Nuclei-Template

GitHubhuseyinstif/cve-2024-4577-nuclei-template

Nuclei template for detecting CVE-2024-4577 PHP CGI argument injection vulnerability, enabling automated RCE testing via crafted HTTP requests and…

exploitationpenetration-testingvulnerability-analysis+3
212 years ago
GraphQLGrapper preview

GraphQLGrapper

GitHubm19o/graphqlgrapper

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

api-security-testinginformation-gatheringpenetration-testing+3
211 year ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubmonzaviman/cve-2025-62168

Scanner and proof-of-concept for CVE-2025-62168, detecting Squid Proxy information disclosure that leaks HTTP authentication credentials.

exploitationinformation-gatheringpenetration-testing+2
1610 months ago
Mass-Assigner preview

Mass-Assigner

GitHubsn1r/mass-assigner

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

api-security-testingpenetration-testingvulnerability-analysis+1
182 years ago
CVE-2024-38475 preview

CVE-2024-38475

GitHubp0in7s/cve-2024-38475

Proof-of-concept exploit for CVE-2024-38475 targeting Apache HTTP Server mod_rewrite improper escaping, enabling URL-to-filesystem mapping for code…

code-analysisexploitationpenetration-testing+3
162 years ago
cve-2026-75650-magento-validation-lab preview

cve-2026-75650-magento-validation-lab

GitHubdinosn/cve-2026-75650-magento-validation-lab

Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.

curated-resourceseducationexploitation+3
63 days ago
Bulk_403_Bypass preview

Bulk_403_Bypass

GitHubaardwolfsecurityltd/bulk_403_bypass

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

ids-ips-evasionpenetration-testingwaf-bypass+1
203 years ago
CVE-2025-61882 preview

CVE-2025-61882

GitHubsachinart/cve-2025-61882

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

exploitationpenetration-testingreconnaissance+3
1111 months ago
text4shellburpscanner preview

text4shellburpscanner

GitHubf0ng/text4shellburpscanner

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

exploitationpenetration-testingvulnerability-scanners+2
203 years ago
CVE-2023-41717 preview

CVE-2023-41717

GitHubfederella/cve-2023-41717

Detailed write-up and proof of concept for CVE-2023-41717, demonstrating bypass of Zscaler proxy file download/upload restrictions via HTTP Range…

educationexploitationpapers-research+2
123 years ago
SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536 preview

SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536

GitHubtess-ss/sap-memory-pipes-desynchronization-vulnerability-mpi-cve-2022-22536

Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise…

exploitationinformation-gatheringpenetration-testing+3
104 years ago
CVE-2022-1386 preview

CVE-2022-1386

GitHubardzz/cve-2022-1386

Python proof-of-concept for CVE-2022-1386, an unauthenticated SSRF in Fusion Builder WordPress plugin, demonstrating file read via crafted HTTP…

exploitationinformation-gatheringpenetration-testing+3
93 years ago
CVE-2022-2414-Proof-Of-Concept preview

CVE-2022-2414-Proof-Of-Concept

GitHubamitlttwo/cve-2022-2414-proof-of-concept

A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows…

exploitationinformation-gatheringpenetration-testing+2
101 year ago
CVE-2026-21962 preview

CVE-2026-21962

GitHubzeetee1235/cve-2026-21962

Verified PoC and analysis for CVE-2026-21962, an access-control bypass in Oracle HTTP Server/WebLogic Proxy Plug-in via URI normalization…

exploitationpenetration-testingred-teaming+3
320 days ago
Previous1…8910…25Next