Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k1 day ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k10h 19m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k9h 47m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
CVE-2025-32463_chwoot preview

CVE-2025-32463_chwoot

GitHubashardev002/cve-2025-32463_chwoot

🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.

privilege-escalationcontainer-securityvulnerability-analysis+3
12h 39m ago
wrongsecrets preview

wrongsecrets

GitHubowasp/wrongsecrets

Vulnerable app with examples showing how to not use secrets

container-securityvulnerability-analysisctf+5
1.5k9h 47m ago
crAPI preview

crAPI

GitHubowasp/crapi

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

vulnerability-analysisapi-security-testingweb-security+3
1.6k10h 19m ago
digital-forensics-lab preview

digital-forensics-lab

GitHubfrankwxu/digital-forensics-lab

Free hands-on digital forensics labs for students and faculty

disk-forensicspassword-crackingmemory-forensics+9
2.9k10h 58m ago
superpowers-evals preview

superpowers-evals

GitHubprime-radiant-inc/superpowers-evals

Behavioral eval lab (Quorum) for the superpowers project that drives real coding-agent CLIs (Claude, Codex, Gemini, Kimi, and more) through a QA…

scripting-automationpenetration-testingutilities-frameworks+3
9711h 48m ago
screenpipe preview

screenpipe

GitHubscreenpipe/screenpipe

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

osintscripting-automationinformation-gathering+8
20.9k17h 26m ago
FreeLabFriday_Labs preview

FreeLabFriday_Labs

GitHubblackhillsinfosec/freelabfriday_labs

This repository contains all lab instructions for the following content: Info Sec Core Skills, SOC Core Skills, ADCD Labs, SOC Analyst Labs, & BnB…

defensive-toolsctfpenetration-testing+2
1617h 48m ago
attackgen preview

attackgen

GitHubmrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

ctfpenetration-testingthreat-intelligence+5
1.2k18h 33m ago
cve-2010-4221-lab preview

cve-2010-4221-lab

GitHubdiegslva/cve-2010-4221-lab

From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented

exploit-frameworksvulnerability-analysisexploitation+5
0 days ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

static-analysisvulnerability-analysiscode-analysis+5
9231 day ago
metasploit-lab-report preview

metasploit-lab-report

GitHubsamirchapagain/metasploit-lab-report

Educational penetration testing lab report documenting exploitation of vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable 2 using Metasploit,…

reconnaissanceexploit-frameworksvulnerability-analysis+4
1 day ago
POC-AIOWPM-CVE-2026-19949 preview

POC-AIOWPM-CVE-2026-19949

GitHub686f6c61/poc-aiowpm-cve-2026-19949

Reproducible Docker-based proof-of-concept for CVE-2026-19949, a second-order SQL injection in All-in-One WP Migration <= 7.109 that leaks the…

vulnerability-analysisexploitationweb-application-exploitation+4
11 day ago
droidground preview

droidground

GitHubsecforce/droidground

A flexible playground for Android CTF challenges.

android-securitydynamic-analysis-sandboxingexploitation+5
1171 day ago
CVE-2026-83548-CVE-2026-83549 preview

CVE-2026-83548-CVE-2026-83549

GitHubhorkimhab/cve-2026-83548-cve-2026-83549

Educational repository for researching CVE-2026-83548 and CVE-2026-83549, providing proof-of-concept resources and guidance for authorized security…

vulnerability-analysisexploitationeducation+2
1 day ago
cve-2026-75650-magento-validation-lab preview

cve-2026-75650-magento-validation-lab

GitHubdinosn/cve-2026-75650-magento-validation-lab

Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.

vulnerability-analysisexploitationweb-security+3
21 day ago
CVE-2025-54424 preview

CVE-2025-54424

GitHubhophtien/cve-2025-54424

CVE-2025-54424: 1Panel TLS client cert bypass enables RCE via forged CN 'panel_client' using a bundled scanning and exploitation tool. Affected: <=…

vulnerability-scannersexploitationweb-security+3
31 day ago
ravage preview

ravage

GitHubduriantaco/ravage

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

reconnaissancevulnerability-scannersdynamic-analysis-sandboxing+7
31 day ago
log4shell-exploitation-detection preview

log4shell-exploitation-detection

GitHubkalidoulabghaly/log4shell-exploitation-detection

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

container-securityvulnerability-analysisexploitation+5
1 day ago
Previous12…100Next