Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
分类

API安全测试

用于评估REST、SOAP和GraphQL API安全性的工具。

Kitploit 推荐

精选工具

10 已选择
kiterunner preview#1

kiterunner

GitHubassetnote/kiterunner
3.2k5年前
zaproxy preview#2

zaproxy

GitHubzaproxy/zaproxy
15.6k4天前
nuclei preview#3

nuclei

GitHubprojectdiscovery/nuclei
30.4k1天前
sqlmap preview#4

sqlmap

GitHubsqlmapproject/sqlmap
38.2k15小时48分前
graphql-cop preview#5

graphql-cop

GitHubdolevf/graphql-cop
68410个月前
graphw00f preview#6

graphw00f

GitHubdolevf/graphw00f
8844个月前
Arjun preview#7

Arjun

GitHubs0md3v/arjun
6.4k1年前
jwt_tool preview#8

jwt_tool

GitHubticarpi/jwt_tool
6.7k1年前
crAPI preview#9

crAPI

GitHubowasp/crapi
1.6k20天前
automatic-api-attack-tool preview#10

automatic-api-attack-tool

GitHubimperva/automatic-api-attack-tool
4956年前
最新相关性最受欢迎最近更新
380 结果
内容在请求的语言中不可用。显示英文版本。
bugbounty-lab101 preview

bugbounty-lab101

GitHubdevcop95/bugbounty-lab101

面向HackerOne研究人员的完整漏洞赏金工作区。包含范围强制执行、自动化侦察/漏洞流水线(400+工具)、报告模板、CVE/CWE监视列表,以及本地VM练习实验室。专为有纪律、合乎道德的狩猎而构建。

reconnaissancevulnerability-scannersweb-vulnerability-scanners+8
4111个月前
bifrost preview

bifrost

GitHubbifrost-proxy/bifrost

High-performance HTTP/HTTPS/SOCKS5 MITM proxy in Rust with TLS interception, rule-based request rewriting, traffic capture, breakpoints, script…

packet-sniffing-analysisweb-proxies-interceptionreverse-engineering+6
14116天前
akca preview

akca

GitHubakha-security/akca

面向证据的 Go 语言 DAST 扫描器,可爬取 Web 应用和 API,然后运行自适应 SQLi、XSS、RCE、SSRF 和认证检查,并提供可重放的证明。

defensive-toolsreconnaissancevulnerability-scanners+9
1772天前
reSolver preview

reSolver

GitHubtheqmaks/resolver

该扩展将流行的 CAPTCHA 解决方案服务集成到 BurpSuite 中,无需人工干预即可处理不同类型的 CAPTCHA。

scripting-automationweb-application-exploitationapi-security-testing+5
147个月前
XXERipper preview

XXERipper

GitHubkamalx06/xxeripper

黑盒XXE扫描器,通过统计基线、解析器指纹识别和OOB确认检测带内、基于错误和盲注带外注入,并支持SARIF输出。

reconnaissancevulnerability-scannersweb-vulnerability-scanners+9
3天前
reburp preview

reburp

GitHubforefy/reburp

一个将完整的 Montoya API 暴露为本地 REST API 的 Burp Suite 扩展,并带有 Swagger UI

vulnerability-scannersweb-proxies-interceptionscripting-automation+7
1037天前
HTTP3-Adapter preview

HTTP3-Adapter

GitHubt0xodile-swig/http3-adapter

Burp Suite 扩展,用于拦截请求并通过 HTTP/3 发送,再将响应转换回 Burp,支持 kettled 请求和 HTTP/3 能力检测。

web-proxies-interceptionapi-security-testingweb-security+3
13天前
cve-2026-75157-poc preview

cve-2026-75157-poc

GitHublicitrasimone/cve-2026-75157-poc

针对 CVE-2026-75157 的独立授权通用 HTTP PoC

vulnerability-analysisexploitationweb-application-exploitation+3
10天前
Aresius preview

Aresius

GitHub0xmarik/aresius

面向渗透测试人员和漏洞赏金猎人的原生 HTTP/HTTPS 拦截代理,支持实时请求篡改、请求重放、高速模糊测试和 HTTPQL 过滤。

vulnerability-analysisweb-proxies-interceptionweb-application-exploitation+6
611天前
CVE-2026-65013-BOLA-IDOR preview

CVE-2026-65013-BOLA-IDOR

GitHubisaca0315/cve-2026-65013-bola-idor

针对 Onlook 的 tRPC API 的可复现 BOLA/IDOR PoC(CVE-2026-65013),包含 12 步利用链、存在漏洞和已修补的 Docker 目标,以及技术文档。

authentication-authorizationvulnerability-analysisexploitation+7
14天前
OpenHunterAI preview

OpenHunterAI

GitHublumoslab-innovation/openhunterai

面向 Web、API 和 LLM 应用安全的本地优先 AI 红队。攻击者式推理、有证据支撑的发现,以及面向 AI 编码代理的技能。

defensive-toolsreconnaissancevulnerability-scanners+9
32814天前
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

exploitationweb-application-exploitationapi-security-testing+4
55天前
Roxy preview

Roxy

GitHubvid4l-07/roxy

基于终端的 HTTP 拦截代理,带有 TUI,可实时捕获、检查和修改请求,并配有 Repeater 用于重发和调整请求。

web-proxies-interceptionweb-application-exploitationapi-security-testing+3
614天前
gori preview

gori

GitHubhahwul/gori

一个快速、键盘驱动的 HTTP 拦截代理,以及面向终端的黑客与渗透测试工具包。

vulnerability-scannersweb-proxies-interceptionscripting-automation+8
1113天前
sast-scan-action preview

sast-scan-action

GitHuboffensive360/sast-scan-action

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

vulnerability-scannersstatic-code-analysiscode-analysis+4
1个月前
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP 服务器,可在本地代码库上运行 SAST 扫描,并返回带有严重级别和修复建议的发现结果,使 AI 助手能够执行安全分析和修复。

static-code-analysisvulnerability-analysiscode-analysis+3
1个月前
SDK preview

SDK

GitHubintelligencex/sdk

用于查询 Intelligence X 搜索引擎和数据存档的 SDK,支持邮箱、域名、IP 和电话等选择器。包含 Python、PHP、Go 的 API 封装,以及用于 OSINT 调查的 Maltego 转换。

osintapi-security-testinginformation-gathering+2
5544个月前
pwnproxy preview

pwnproxy

GitHubericmtzmtz/pwnproxy

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

vulnerability-scannersweb-proxies-interceptionapi-security-testing+6
89天前
上一页12…22下一页