Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
learn365 — This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection. | Kitploit
Tools/GitHubGitHub/harsh-bothra/learn365
Web SecurityPenetration TestingCloud SecurityMobile SecurityLearning & EducationCurated ResourcesAPI SecurityLearning Paths & Courses
GitHubharsh-bothra/learn365

learn365

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

View Repository
1.7k419194 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Learn365

This repository contains all the information shared during my Learn 365 Challenge. Learn 365 is a challenge to keep the learning spirit going on and challenge myself to learn something daily for the whole year, it can be anything from infosec to general life. Follow me on Twitter for Regular Updates: Harsh Bothra. Huge thanks to Mehedi Hasan Remon, who originally created and maintained this repository.


S.NOMind Map
12FA Bypass Techniques
2Scope Based Recon
3Cookie Based Authentication Vulnerabilities
4Unauthenticated JIRA CVEs
5Android Application Penetration Testing Checklist

DayTopic
12FA Bypass Techniques
2Regular Expression Denial Of Service
3SAML Vulnerabilities
4Unauthenticated & Exploitable JIRA Vulnerabilities
5Client-Side Template Injection(CSTI)
6Cross-Site Leaks (XS-Leaks)
7Cross-Site Script Includes (XSSI)
8JSON Padding Attacks
9JSON Attacks
10Abusing Hop-by-Hop Headers
11Cache Poisoned Denial of Service (CPDos)
12Unicode Normalization
13WebSocket Vulns (Part-1)
14WebSocket Vulns (Part-2)
15WebSocket Vulns (Part-3)
16Web Cache Deception Attack
17Session Puzzling Attack
18Mass Assignment Attack
19HTTP Parameter Pollution
20GraphQL Series (Part-1)
21GraphQL Vulnerabilities (Part-2)
22GraphQL WrapUp (Part-3)
23Password Reset Token Issues
24My previous works
25Salesforce Security Misconfiguration (Part-1)
26Salesforce Security Misconfiguration (Part-2))
27Salesforce Configuration Review (Wrap)
28Common Business Logic Issues: Part-1
29Common Business Logic Issues (Part-2)
30Common Business Logic Issues (Wrap)
31Captcha Bypass Techniques
32Pentesting Kibana Service
33Pentesting Docker Registry
34HTML Scriptless Attacks / Dangling Markup Attacks (Part - 1)
35HTML Scriptless Attacks / Dangling Markup Attacks (Wrap)
36Pentesting Rsync Service
37CRLF Injection
38Pentesting FTP Service
39OpenID Connect Implementation Issues
40Cookie Based Authentication Vulnerabilities
41Cobalt Vulnerability Wiki - Resource
42Race Conditions
43SMTP Open Relay Attack
44Pentesting BACNet
45API Security Tips
46Pentesting SSH - Talk
47CORS Misconfiguration
48Incomplete Trailing Escape Pattern Issue
49Pivoting & Exploitation in Docker Environments - Talk
50Detect Complex Code Patterns using Semantic grep - Talk
51Student Roadmap to Become a Pentester - Talk
52Hacking How-To Series - Playlist
53JS Prototype Pollution
54JSON Deserialization Attacks
55Android App Dynamic Analysis using House
56Testing IIS Servers
57Secure Code Review - Talk
58JSON Interoperability Vulnerabilities - Research Blog
59HTTP Desync Attacks - Talk
60XSLT Injection
61Bypassing AWS Policies - Talk
62Source Code Review Guidelines - Resource
63All of the Threats: Intelligence, Modelling and Hunting - Talk
64Hidden Property Abuse (HPA) attack in Node.js - Talk
Download Tool