Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k13h 42m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k13h 11m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
Red-Teaming-TTPs preview

Red-Teaming-TTPs

GitHubrosesecurity/red-teaming-ttps

Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike!

ctfpenetration-testingeducation+3
1.9k9 days ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

static-analysisvulnerability-analysiscode-analysis+5
9231 day ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubloufa0/cve-2025-24813

right payload for java CVE

vulnerability-scannersexploitationweb-security+3
2 months ago
CVE-2025-11262-Lab preview

CVE-2025-11262-Lab

GitHubrootdirective-sec/cve-2025-11262-lab

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

vulnerability-analysisweb-application-exploitationctf+3
2 months ago
SUDO_KILLER preview

SUDO_KILLER

GitHubth3xace/sudo_killer

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

privilege-escalationvulnerability-analysisexploitation+5
2.5k6 months ago
redthread preview

redthread

GitHubmatheusht/redthread

An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision…

defensive-toolspenetration-testing-frameworksexploit-frameworks+7
434 days ago
OneRuleToRuleThemStill preview

OneRuleToRuleThemStill

GitHubstealthsploit/oneruletorulethemstill

A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule

password-crackingeducationlabs-practice
6501 year ago
Tiredful-API preview

Tiredful-API

GitHubpayatu/tiredful-api

An intentionally designed broken web application based on REST API.

web-application-exploitationapi-security-testingpenetration-testing+2
5836 years ago
staged-DLL-Injection-SMB- preview

staged-DLL-Injection-SMB-

GitHubkasturixbm5/staged-dll-injection-smb-

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

exploitationshellcodepenetration-testing+5
423 months ago
CVE-2019-7609 preview

CVE-2019-7609

GitHubhekadan/cve-2019-7609

Docker-based lab environment and exploit for CVE-2019-7609 (Kibana Timelion RCE) with reverse shell payload and patch analysis.

vulnerability-analysisexploitationweb-application-exploitation+3
206 years ago
wrongsecrets-binaries preview

wrongsecrets-binaries

GitHubowasp/wrongsecrets-binaries

Source code for the Binaries of OWASP WrongSecrets

static-analysisvulnerability-analysiscode-analysis+6
114 days ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

privilege-escalationpassword-attacksvulnerability-analysis+5
1 month ago
awesome-web3-security preview

awesome-web3-security

GitHubgmh5225/awesome-web3-security

A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.

vulnerability-analysisctfeducation+3
2214 days ago
WhatTheHack preview

WhatTheHack

GitHubmicrosoft/whatthehack

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

cloud-infrastructure-securitycontainer-securityiot-security+6
1.9k2 months ago
DumpsterFire preview

DumpsterFire

GitHubtrycatchhcf/dumpsterfire

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…

defensive-toolspenetration-testingeducation+3
1.0k6 years ago
spring4shell_victim preview

spring4shell_victim

GitHubfracturelabs/spring4shell_victim

Intentionally vulnerable Spring app to test CVE-2022-22965

vulnerability-analysisexploitationweb-application-exploitation+3
24 years ago
CVE-2026-50055 preview

CVE-2026-50055

GitHubhorkimhab/cve-2026-50055

CVE-2026-50055 - Draft

vulnerability-analysisexploitationctf+3
1 month ago
Bluekeep-Metasploit-Lab-Project preview

Bluekeep-Metasploit-Lab-Project

GitHubnweks/bluekeep-metasploit-lab-project

Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)

exploit-frameworksvulnerability-analysispenetration-testing+3
4 months ago
Previous1234…100Next