Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-ethical-hacking-resources — 😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing. | Kitploit
Tools/GitHubGitHub/husnainfareed/awesome-ethical-hacking-resources
Vulnerability AnalysisWeb SecurityMalware AnalysisCTFPenetration TestingPapers & ResearchLearning & EducationCurated ResourcesLearning Paths & Courses
Labs & Practice
GitHubhusnainfareed/awesome-ethical-hacking-resources

awesome-ethical-hacking-resources

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

View Repository
3.7k559635 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Awesome Resources For Learning Ethical Hacking & Pentesting ⚡️ Awesome Awesome Hacking Awesome community

What I’m sharing here is a collection of some best resources about Hacking & Penetration Testing to make you learn faster! Let's make it the best resource repository for our community.

Contents

  • Books
  • Online
  • Offline
  • Vulnerable Machines and Websites
  • Vulnerability Databases And Resources
  • Malware Analysis
  • Linux Penetration Testing OS
  • Courses
  • Workshop Playlists
  • Security Talks and Conferences
  • YouTube Channels
  • Forums

You are welcome to fork and contribute.

Also you can find my writeups/tutorials on medium: @hussnainfareed :)

Books

  1. The Hacker Playbook 2: Practical Guide To Penetration Testing
  2. The Basics of Hacking and Penetration Testing, Second Edition: Ethical Hacking and Penetration Testing Made Easy
  3. Breaking into Information Security: Learning the Ropes 101
  4. Penetration Testing: A Hands-On Introduction to Hacking
  5. Social Engineering: The Art of Human Hacking
  6. Hacking: The Art of Exploitation, 2nd Edition
  7. Web Hacking 101
  8. OWASP Testing Guide (A must-read for web application developers and penetration testers)
  9. The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  10. The Basics of Web Hacking: Tools and Techniques to Attack the Web

Learning Platforms to Sharpen Your Skills

Online

NameDescription
CTF Hacker101The Hacker101 CTF is a game designed to let you learn to hack in a safe, rewarding environment. Hacker101 is a free educational site for hackers.
Hack The Box :: Penetration Testing LabsAn online platform to test and advance your skills in penetration testing and cyber security. Join today and start training in our online labs.
TryHackMeTryHackMe is an online platform that teaches cyber security through short, gamified real-world labs.
CTF365An account-based ctf site, awarded by Kaspersky, MIT, and T-Mobile.
BackdoorPen testing labs that have a space for beginners, a practice arena, and various competitions, account required.
Hack.meLets you build/host/attack vulnerable web apps.
CTFLearnAn account-based ctf site, where users can go in and solve a range of challenges.
OWASP Vulnerable Web Applications Directory Project (Online)List of online available vulnerable applications for learning purposes.
Pentestit labsHands-on Pentesting Labs (OSCP style)
Root-me.orgHundreds of challenges are available to train yourself in different and not simulated environments
Vulnhub.comVulnerable By Design VMs for practical 'hands-on' experience in digital security
Windows / Linux Local Privilege Escalation WorkshopPractice your Linux and Windows privilege escalation.
Hacking ArticlesCTF Brief Write-up collection with a lot of screenshots good for beginners.
Rafay Hacking Articles, a great blogWrite up collections by Rafay Baloch.
PentesterLab20$ signature, complete content basic to write exploits, web, android.
CyberSec WTFEmulated web pentesting challenges from bounty write-ups
Pentest-GroundPentest Ground is a free playground with deliberately vulnerable web applications and network services.
pwn.guideA cybersecurity education website, offering about 100 tutorials, ranging from web, wireless... hacking to defense tutorials & forensics. Offers free plan.
HTB WriteupsThe most comprehensive collection of Hack The Box writeups on GitHub - 500+ machines, 400+ challenges, ProLabs, Sherlocks (DFIR), endgames, and CTF events with full walkthroughs.

Off-Line

NameDescription
Damn Vulnerable Xebia Training EnvironmentDocker Container including several vulnerable web applications (DVWA, DVWServices, DVWSockets, WebGoat, Juiceshop, Railsgoat, django.NV, Buggy Bank, Mutilidae II and more)
OopsSec StoreAn intentionally vulnerable e-commerce app built with Next.js for web security training (OWASP Top 10, API security, CTF challenges). Quick start with npx create-oss-store.
OWASP Vulnerable Web Applications Directory Project (Offline)List of offline available vulnerable applications for learning purposes

Vulnerable Machines/Websites

  1. FiringRange

Vulnerability Databases And Resources

Vulnerability Databases are the first place to start your day as a security professional. Any new vulnerability detection is generally available through the public vulnerability databases. These databases are a big source of information for hackers to be able to understand and exploit/avoid/fix the vulnerability.

  • http://www.exploit-db.com/
  • http://1337day.com/
  • http://securityvulns.com/
  • http://www.securityfocus.com/
  • http://www.osvdb.org/
  • http://www.securiteam.com/
  • http://secunia.com/advisories/
  • http://insecure.org/sploits_all.html
  • http://zerodayinitiative.com/advisories/published/
  • http://nmrc.org/pub/index.html
  • http://web.nvd.nist.gov
  • http://www.vupen.com/english/security-advisories/
  • http://www.vupen.com/blog/
  • http://cvedetails.com/
  • http://www.rapid7.com/vulndb/index.jsp
  • http://oval.mitre.org/
  • http://sploitus.com/
  • http://cxsecurity.com/

Malware Analysis

NameDescription
Malware traffic analysislist of traffic analysis exercises
Malware Analysis - CSCI 4976another class from the folks at RPISEC, quality content
Bad Binarieswalkthrough documents of malware traffic analysis exercises and some occasional malware analysis.

Linux Penetration Testing OS

NameDescription
Kalithe infamous pen-testing distro from the folks at Offensive Security
Parrot Debian includes a full portable lab for security, DFIR, and development
Android TamerAndroid Tamer is a Virtual / Live Platform for Android Security professionals.
BlackArchArch Linux-based pentesting distro, compatible with Arch installs
LionSec Linuxpentesting OS based on Ubuntu
NullSec LinuxSecurity-focused distro with automotive hacking, forensics, and advanced pentesting tools

Courses

Download Tool