Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k10h 14m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k7h 30m ago
grype preview#3

grype

GitHubanchore/grype
12.7k4 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k5 days ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k14 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k4 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k26 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k1 day ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
541 day ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
777 results
gitleaks preview

gitleaks

GitHubgitleaks/gitleaks

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

static-analysisvulnerability-scannerscode-analysis+3
28.6k2 months ago
OWASP-Top-10-AI-Infrastructure-Security-Risks preview

OWASP-Top-10-AI-Infrastructure-Security-Risks

GitHubowasp/owasp-top-10-ai-infrastructure-security-risks

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

cloud-infrastructure-securitynetwork-securityhardware-security+5
28 days ago
ws4-secure-design-agentic-systems preview

ws4-secure-design-agentic-systems

GitHubcosai-oasis/ws4-secure-design-agentic-systems

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

cloud-securitythreat-intelligenceidentity-access-management+6
1261 day ago
trivy preview

trivy

GitHubaquasecurity/trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

cloud-infrastructure-securitydefensive-toolsvulnerability-scanners+14
37.4k7h 30m ago
halo-record preview

halo-record

GitHubbkuan001/halo-record

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.

forensicssupply-chain-securityincident-response+1
637 days ago
TriSuElla-AIDLCA-Framework preview

TriSuElla-AIDLCA-Framework

GitHubowasp/trisuella-aidlca-framework

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

static-code-analysisvulnerability-analysiscode-analysis+7
28 days ago
fickling preview

fickling

GitHubtrailofbits/fickling

A Python pickling decompiler and static analyzer

static-analysisvulnerability-analysiscode-analysis+5
6704 days ago
skulto preview

skulto

GitHubasteroid-belt/skulto

Offline and security-first tool for syncing and managing agent skills

vulnerability-analysisscripting-automationsecurity-virtualization+3
5115 days ago
agent-scan preview

agent-scan

GitHubsnyk/agent-scan

Security scanner for AI agents, MCP servers and agent skills.

vulnerability-scannersdynamic-analysis-sandboxingcode-analysis+3
2.9k1 day ago
prismor preview

prismor

GitHubprismorsec/prismor

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

defensive-toolscontainer-securitydevsecops+5
2837h 11m ago
advisory-database preview

advisory-database

GitHubpypa/advisory-database

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

vulnerability-analysisdevsecopsthreat-intelligence+2
3705 days ago
pyrite preview

pyrite

GitLabrenich/pyrite

Hardware-bound & Cloud-gated binary execution, cryptographic provenance, and anti-tamper envelope sealing for Crystal.

cryptographycloud-securitydevsecops+3
224 days ago
revera preview

revera

GitHubaaravmaloo/revera

The credit score for npm packages. Analyze package reputation, maintenance, security, publisher trust, and ecosystem health before you install any…

vulnerability-scannersvulnerability-analysisdevsecops+1
112 months ago
flar preview

flar

GitHubswelljoe/flar

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

privilege-escalationcontainer-securityids-ips-evasion+5
511 month ago
SBOM-VEX-Taint-Analysis preview

SBOM-VEX-Taint-Analysis

GitHubowasp/sbom-vex-taint-analysis

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

vulnerability-analysissupply-chain-securitypapers-research+3
22 months ago
DockSec preview

DockSec

GitHubowasp/docksec

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

static-analysisvulnerability-scannerscontainer-security+5
4651 day ago
tanstack-compromise-checker preview

tanstack-compromise-checker

GitHubfabriziosalmi/tanstack-compromise-checker

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

ioc-managementvulnerability-scannerscontainer-security+7
25 days ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

web-application-exploitationweb-securitypenetration-testing+7
1813 days ago
Previous123…44Next