Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SecurityExplained — SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create informational content in multiple formats and share with the community to enable knowledge creation and learning. | Kitploit
Tools/GitHubGitHub/harsh-bothra/securityexplained
Authentication & AuthorizationVulnerability AnalysisMobile App PentestingWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingLearning & EducationCurated Resources

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Learning Paths & Courses
GitHubharsh-bothra/securityexplained

SecurityExplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create informational content in multiple formats and share with the community to enable knowledge creation and learning.

View Repository
546102104 years agoReviewed by Kitploit

Security Explained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create informational content in multiple formats and share with the community to enable knowledge creation and learning. Below are the various activities and formats planned under #SecurityExplained series:

  1. Tweets explaining interesting security stuff
  2. Blogs/Tutorials/How-To-Guides about different tools/techniques/attacks
  3. Security Discussion Spaces/Meets
  4. Monthly Mindmap/Mindmap based explainers for different attacks/techniques
  5. My Pentesting Methodology Breakdown
  6. Giveaways and Community Engagement
  7. GitHub Repository to Maintain "SecurityExplained"
  8. Public & Free to Access
  9. Newsletter

Follow me on Twitter for Regular Updates: Harsh Bothra.

Note: Please note that this series will run on irregular scehdules and it is not necessary to produce & share content on a regular or daily basis.

Content by Harsh


S.No.Topic
1My Penetration Testing Methodology [Web]
2FeroxBuster Explained
3Creating Custom Wordlist for Content Discovery
4Escalating HTML Injection to Cloud Metadata SSRF
5Bypassing Privileges & Other Restrictions with Mass Assignment Attacks
6Bypassing Biometrics in iOS with Objection
7My Methodology to Test Premium Features
8Bypassing Filters(and more) with Visual Spoofing
9Path Traversal via File Upload
10Attacking Zip Upload Functionality with ZipSlip Attack
11RustScan - The Modern Port Scanner
12Vulnerable Code Snippet - 1

SecurityExplained NewsLetter


AskMeAnything


S.No.Topic
1AMA-1: AMA with Harsh Bothra
2

Threads


MindMaps

S.No.Topic
1Account Takeover Techniques
2CWE TOP 10 (2021)
Download Tool
13Vulnerable Code Snippet - 2
14Exploiting XXE in JSON Endpoints
15Vulnerable Code Snippet - 3
16Vulnerable Code Snippet - 4
17Vulnerable Code Snippet - 5
18Vulnerable Code Snippet - 6
19Vulnerable Code Snippet - 7
20Vulnerable Code Snippet - 8
21Vulnerable Code Snippet - 9
22Vulnerable Code Snippet - 10
23Vulnerable Code Snippet - 11
24Vulnerable Code Snippet - 12
25Vulnerable Code Snippet - 13
26Vulnerable Code Snippet - 14
27Vulnerable Code Snippet - 15
28Vulnerable Code Snippet - 16
29Vulnerable Code Snippet - 17
30Vulnerable Code Snippet - 18
31Vulnerable Code Snippet - 19
32Account Takeover Methodology
33Vulnerable Code Snippet - 20
34Vulnerable Code Snippet - 21
35Vulnerable Code Snippet - 22
36Vulnerable Code Snippet - 23
37Vulnerable Code Snippet - 24
38Vulnerable Code Snippet - 25
39Vulnerable Code Snippet - 26
40Vulnerable Code Snippet - 27
41Vulnerable Code Snippet - 28
42Vulnerable Code Snippet - 29
43Vulnerable Code Snippet - 30
44Vulnerable Code Snippet - 31
45Vulnerable Code Snippet - 32
46Vulnerable Code Snippet - 33
47Vulnerable Code Snippet - 34
48Vulnerable Code Snippet - 35
49Vulnerable Code Snippet - 36
50Vulnerable Code Snippet - 37
51Vulnerable Code Snippet - 38
52Vulnerable Code Snippet - 39
53Vulnerable Code Snippet - 40
54Vulnerable Code Snippet - 41
55Vulnerable Code Snippet - 42
56Vulnerable Code Snippet - 43
57Vulnerable Code Snippet - 44
58Vulnerable Code Snippet - 45
59Ruby ERB SSTI
60Introduction to CWE
61CWE-787: Out-of-bounds Write
62Vulnerable Code Snippet - 46
63CWE-20: Improper Input Validation
64Vulnerabilities in Cookie Based Authentication
65How do I get Started in Cyber Security? — My Perspective & Learning Path!
66Scope Based Recon Methodology: Exploring Tactics for Smart Recon
67MFA Bypass Techniques
68Vulnerable Code Snippet - 47
69Vulnerable Code Snippet - 48
70Vulnerable Code Snippet - 49
71Vulnerable Code Snippet - 50
72Vulnerable Code Snippet - 51
73Vulnerable Code Snippet - 52
74Vulnerable Code Snippet - 53
75Vulnerable Code Snippet - 54
76Vulnerable Code Snippet - 55
77Vulnerable Code Snippet - 56
78Vulnerable Code Snippet - 57
79Vulnerable Code Snippet - 58
80Vulnerable Code Snippet - 59
81Vulnerable Code Snippet - 60
82Vulnerable Code Snippet - 61
83Vulnerable Code Snippet - 62
84Vulnerable Code Snippet - 63
85Vulnerable Code Snippet - 64
86Vulnerable Code Snippet - 65
87CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
88CWE-732: Incorrect Permission Assignment for Critical Resource
89CWE-522: Insufficiently Protected Credentials
90CWE-918: Server-Side Request Forgery (SSRF)
91CWE-611: Improper Restriction of XML External Entity Reference
92CWE-476: NULL Pointer Dereference
93CWE-276: Incorrect Default Permissions
94CWE-862: Missing Authorization
95CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
96CWE-798: Use of Hard-coded Credentials
97CWE-287: Improper Authentication
S.No.Topic
1Issue-1
2Issue-2
3Issue-3
4Issue-4
5Issue-5
6Issue-6
7Issue-7
8Issue-8
9Issue-9
10Issue-10
11Issue-11
12Issue-12
13Issue-13
14Issue-14
AMA-2: AMA with Six2dez
3AMA-3: AMA with Brumens
S.No.Topic
17 Hacking Books you must read
24 Subdomain Enumeration Tools you must have in your Arsenal 💻
36 Burp Extensions to Check for Access Control & Privilege Escalation Issues
45 Powerful Web Fuzzing & Content Discovery Tools You Must Know
517 Search Engines every Security Professional Must Know
67 Cyber Security Conferences Channel You Must Follow
79 Free Practice Labs to Master Cross-Site Scripting
811 MindMaps I have created that you may find useful!
914 Payload Repositories to find all the required Payloads & Attack Vectors