Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
48 results
log4shell-cve-lab preview

log4shell-cve-lab

GitHubvaibhav91one/log4shell-cve-lab

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

educationexploitationlabs-practice+2
3 days ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

educationexploitationlabs-practice+3
217 days ago
homelab-CVE-2021-44228 preview

homelab-CVE-2021-44228

GitHubricardo354/homelab-cve-2021-44228

Log4j Vulnerability homelab

container-securityeducationexploitation+3
1 month ago
log4shell-lab preview

log4shell-lab

GitHubdaadaismylife/log4shell-lab

Log4Shell (CVE-2021-44228) 보안 실습 환경 - Log4j 2.14.1 취약 로그 수집 서버

educationexploitationlabs-practice+3
2 months ago
CVE-2021-44228_Log4Shell preview

CVE-2021-44228_Log4Shell

GitHubvutiendat323/cve-2021-44228_log4shell

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

educationexploitationlabs-practice+3
3 months ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
4 months ago
solar-exploiting-log4j preview

solar-exploiting-log4j

GitHublavanya2085/solar-exploiting-log4j

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

ctfeducationexploitation+4
5 months ago
Solar-exploiting-log-4j preview

Solar-exploiting-log-4j

GitHublathika-3006/solar-exploiting-log-4j

Step-by-step TryHackMe walkthrough for exploiting the Log4Shell vulnerability (CVE-2021-44228) to achieve remote code execution and capture flags.

educationexploitationlabs-practice+6
25 months ago
log4shell-poc preview

log4shell-poc

GitHubcodepumpking/log4shell-poc

POC for log4shll Vulnerablity (CVE-2021-44228)

educationexploitationlabs-practice+3
5 months ago
Log4Shell-PoC preview

Log4Shell-PoC

GitHubjosemariamicoli/log4shell-poc

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

command-and-controleducationexploitation+6
7 months ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubiamnewbiez/cve-2021-44228

Deliberately vulnerable Apache Solr application (CVE-2021-44228) for practicing Log4Shell exploitation via User-Agent, POST, and admin endpoints.…

educationexploitationlabs-practice+2
8 months ago
Log4j-_Vulnerability preview

Log4j-_Vulnerability

GitHubfauzan-aldi/log4j-_vulnerability

The Web Is Vulnerable to CVE-2021-44228

educationexploitationlabs-practice+2
1 year ago
DeliberatelyVulnerableWebApp preview
Archived

DeliberatelyVulnerableWebApp

GitHubtimothyjxhn/deliberatelyvulnerablewebapp

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

educationexploitationlabs-practice+3
1 year ago
CVE-2021-44228_dockernize preview

CVE-2021-44228_dockernize

GitHubqw3rtyou/cve-2021-44228_dockernize

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

educationexploitationlabs-practice+3
11 year ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
l4s-vulnapp preview

l4s-vulnapp

GitHubktokkawu/l4s-vulnapp

This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).

educationexploitationlabs-practice+3
2 years ago
jankybank preview

jankybank

GitHubeurogig/jankybank

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

ctfeducationexploitation+3
2 years ago
CVE-2021-44228-white-box preview

CVE-2021-44228-white-box

GitHubhotpotcookie/cve-2021-44228-white-box

Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting…

educationexploitationlabs-practice+3
32 years ago
Previous123Next