Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Labs & Practice

Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.

Kitploit recommended

Top tools

10 selected
vulhub preview#1

vulhub

GitHubvulhub/vulhub
21.1k1 month ago
juice-shop preview#2

juice-shop

GitHubjuice-shop/juice-shop
13.6k29 days ago
WebGoat preview#3

WebGoat

GitHubwebgoat/webgoat
9.3k3 days ago
DVWA preview#4

DVWA

GitHubdigininja/dvwa
13.5k2 days ago
crAPI preview#5

crAPI

GitHubowasp/crapi
1.6k13h 42m ago
NodeGoat preview#6

NodeGoat

GitHubowasp/nodegoat
2.1k3 years ago
SecurityShepherd preview#7

SecurityShepherd

GitHubowasp/securityshepherd
1.5k6 days ago
wrongsecrets preview#8

wrongsecrets

GitHubowasp/wrongsecrets
1.5k13h 10m ago
metasploitable3 preview#9

metasploitable3

GitHubrapid7/metasploitable3
5.7k1 year ago
GOAD preview#10

GOAD

GitHuborange-cyberdefense/goad
8.1k6 months ago
NewestRelevanceMost popularRecently updated
2399 results
CVE-2012-2982 preview

CVE-2012-2982

GitHubcpyre/cve-2012-2982

Practice POC scripting in Tryhackme’s intro poc scripting room (For Linux)

vulnerability-analysisexploitationweb-application-exploitation+3
2 years ago
Zerologon_CVE-2020-1472 preview

Zerologon_CVE-2020-1472

GitHubjolynngsc/zerologon_cve-2020-1472

Step-by-step lab guide for simulating, detecting, and mitigating the Zerologon vulnerability (CVE-2020-1472) on Windows Server 2016 using Kali Linux…

vulnerability-analysisexploitationpenetration-testing+2
2 years ago
CVE-Lab preview

CVE-Lab

GitHubdcm2406/cve-lab

Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604

vulnerability-analysisexploitationweb-application-exploitation+3
22 years ago
Telstra-Cybersecurity-Virtual-Experience- preview

Telstra-Cybersecurity-Virtual-Experience-

GitHubbl34chig0/telstra-cybersecurity-virtual-experience-

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

vulnerability-analysisweb-securityeducation+2
22 years ago
CVE-2024-23334-PoC preview

CVE-2024-23334-PoC

GitHubz3robyte/cve-2024-23334-poc

A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1

vulnerability-analysisexploitationweb-application-exploitation+3
202 years ago
CVE-2024-1071-Docker preview

CVE-2024-1071-Docker

GitHubmatrexdz/cve-2024-1071-docker

Docker-based lab for practicing WordPress CVE-2024-1071 exploitation with automated PoC scripts and step-by-step setup instructions.

container-securityvulnerability-analysisexploitation+3
12 years ago
l4s-vulnapp preview

l4s-vulnapp

GitHubktokkawu/l4s-vulnapp

This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).

vulnerability-analysisexploitationweb-application-exploitation+3
2 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubyoryio/cve-2024-23897

Scanner for CVE-2024-23897 - Jenkins

reconnaissancevulnerability-scannersexploitation+3
52 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubcmnatic/cve-2024-21413

CVE-2024-21413 PoC for THM Lab

vulnerability-analysisexploitationctf+4
2742 years ago
jankybank preview

jankybank

GitHubeurogig/jankybank

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

vulnerability-analysisexploitationweb-security+3
2 years ago
CVE-2024-1071-Docker preview

CVE-2024-1071-Docker

GitHubtrackflaw/cve-2024-1071-docker

CVE-2024-1071 with Docker

vulnerability-analysisexploitationweb-application-exploitation+3
32 years ago
Bug-Bounty-Beginner-Roadmap preview

Bug-Bounty-Beginner-Roadmap

GitHubbittentech/bug-bounty-beginner-roadmap

This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.

vulnerability-analysisexploitationinformation-gathering+7
2.4k2 years ago
DC30_Workshop preview

DC30_Workshop

GitHubmainframed/dc30_workshop

DEFCON 30 Mainframe buffer overlow workshop container

vulnerability-analysisexploitationreverse-engineering+4
962 years ago
CVE-2023-39362-cacti-snmp-command-injection-poc preview

CVE-2023-39362-cacti-snmp-command-injection-poc

GitHubjakabakos/cve-2023-39362-cacti-snmp-command-injection-poc

Proof-of-concept exploit for CVE-2023-39362, an authenticated command injection in Cacti's SNMP options. Includes a vulnerable Docker environment for…

vulnerability-analysisexploitationweb-application-exploitation+4
22 years ago
sheepl preview

sheepl

GitHublorentzenman/sheepl

Emulates realistic user behavior in Active Directory lab environments for red and blue team tradecraft development. Generates random benign user…

scripting-automationpenetration-testingeducation+2
3982 years ago
CVE-2023-50387 preview

CVE-2023-50387

GitHubknqyf263/cve-2023-50387

Educational proof-of-concept for the DNSSEC KeyTrap vulnerability (CVE-2023-50387) with a Docker-based lab environment to demonstrate algorithmic…

vulnerability-analysisexploitationnetwork-security+3
452 years ago
cnappgoat preview

cnappgoat

GitHubtenable/cnappgoat

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

cloud-infrastructure-securityvulnerability-analysisctf+5
2962 years ago
vulnerable-PDF preview

vulnerable-PDF

GitHubnu11secur1ty/vulnerable-pdf

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

phishing-toolspayload-generationweb-application-exploitation+3
112 years ago
Previous1…9899100Next