Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k10h 59m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k5 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k19h 26m ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k15 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
778 results
ApplicationInspector preview

ApplicationInspector

GitHubmicrosoft/applicationinspector

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

static-analysisstatic-code-analysisvulnerability-analysis+3
4.4k9 days ago
fix-react2shell-next preview

fix-react2shell-next

GitHubvercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

vulnerability-scannerscode-analysisscripting-automation+3
4019 months ago
GitHound preview

GitHound

GitHubspecterops/githound

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

reconnaissancevulnerability-analysisinformation-gathering+4
1431 month ago
murphysec preview

murphysec

GitHubmurphysecurity/murphysec

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

vulnerability-scannerssupply-chain-security
1.8k5 months ago
supply-chain-monitor preview

supply-chain-monitor

GitHubelastic/supply-chain-monitor

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

vulnerability-analysiscode-analysismalware-analysis+3
5295 months ago
jetty-line-check preview

jetty-line-check

GitHubxiaoqimikko/jetty-line-check

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on…

defensive-toolsstatic-analysisvulnerability-scanners+4
5 days ago
modelaudit preview

modelaudit

GitHubpromptfoo/modelaudit

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

static-analysisstatic-code-analysisvulnerability-analysis+8
738 days ago
CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection preview

CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection

GitHubgeorge0papasotiriou/cve-2026-1122-iot-firmware-update-signature-bypass-via-low-order-point-injection

Demonstrates CVE-2026-1122 Ed25519 signature bypass via low-order point injection, forging malicious IoT firmware updates with Python and C verifier…

embedded-systems-securityiot-securityvulnerability-analysis+4
1 month ago
safety preview

safety

GitHubpyupio/safety

Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.

vulnerability-scannerscode-analysisdevsecops+1
2.0k21 days ago
zizmor preview

zizmor

GitHubzizmorcore/zizmor

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

static-analysisvulnerability-analysiscode-analysis+5
6.0k2 days ago
nono preview

nono

GitHubnolabs-ai/nono

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

container-securitycode-analysisconfiguration-auditing+8
3.6k1 day ago
pipelock preview

pipelock

GitHubluckypipewrench/pipelock

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

vulnerability-scannersids-ips-evasiondata-exfiltration+8
79213h 15m ago
scopeblind-gateway preview

scopeblind-gateway

GitHubtomjwxf/scopeblind-gateway

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

authentication-authorizationencryption-decryption-toolscloud-security+6
95 months ago
log4j-cve-code-search-resources preview

log4j-cve-code-search-resources

GitHubsourcegraph/log4j-cve-code-search-resources

Using code search to help fix/mitigate log4j CVE-2021-44228

vulnerability-analysiscode-analysisthreat-intelligence+3
18 days ago
pyscan preview

pyscan

GitHubohaswin/pyscan

python dependency vulnerability scanner, written in Rust.

static-analysisvulnerability-scannerscode-analysis+2
2493 months ago
Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832 preview

Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832

GitHubthedevappsecguy/log4j-mitigation-cve-2021-44228--cve-2021-45046--cve-2021-45105--cve-2021-44832

Log4J CVE-2021-44228 : Mitigation Cheat Sheet

vulnerability-analysiscloud-securitydevsecops+3
24 years ago
fad-checker preview

fad-checker

GitHub9pings/fad-checker

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

defensive-toolsstatic-analysisvulnerability-scanners+6
14 days ago
hol-guard preview

hol-guard

GitHubhashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

defensive-toolsstatic-analysisvulnerability-scanners+7
6344 days ago
Previous1…345…44Next