100% offline · ethical · beginner-friendly

Learn security the safe, legal way

AegisKit is a self-contained ethical-security toolkit and practice range. Scan, audit passwords, analyze logs, and hunt web vulnerabilities — all on your own machine, against targets that ship with it. Nothing on the internet. Nothing you can get in trouble for.

5 tools1 vulnerable practice target0 setup headachesruns on Python 3

Everything you need to practice — in one kit

Real, working tools written for learning. Each is small, readable, and safe to run offline.

🛰️

Port-scan simulator

Understand how scanning works against a safe local target — service discovery, banners, and timing, without touching a real network.

🔑

Password & hash auditor

Score password strength by real entropy, spot weak patterns, and identify hash types — all offline, no wordlists phoning home.

📜

Log analyzer

Parse auth and access logs to surface brute-force attempts, odd hours, and suspicious IP patterns — the way a defender would.

🔐

Crypto utilities

Hands-on encoding, hashing, and classic ciphers so the fundamentals actually click.

🎯

Vulnerable practice target

A deliberately-insecure mini web app to attack legally — SQLi, XSS, IDOR and more, with hints and a built-in scoreboard.

📘

Guided workbook

Step-by-step exercises and write-ups so you build real skill, not just run commands.

Simple pricing

Start free. Upgrade for the full range and workbook.

Starter
Free
  • 3 core tools
  • 1 practice challenge
  • Community updates
⬇ Download free
Pro
$29 / one-time
  • All 5 tools
  • Full vulnerable target + scoreboard
  • Guided workbook & write-ups
  • Lifetime updates
Get Pro

Set your own price and connect your checkout (Gumroad, Lemon Squeezy, Stripe Payment Link, etc.) by replacing the buttons above.

🛡️ Built to keep you safe and legal. AegisKit is 100% offline. Every tool works only against the practice targets that come with it — never the live internet. It's made for learning and for authorized testing you run yourself. It cannot and will not attack real systems.