Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k0 days ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k13h 43m ago
grype preview#3

grype

GitHubanchore/grype
12.7k7h 23m ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k17 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k2 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k29 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k3 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
543 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k14h 37m ago
NewestRelevanceMost popularRecently updated
781 results
xz-utils-vuln-checker preview

xz-utils-vuln-checker

GitHubharekrishnarai/xz-utils-vuln-checker

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…

vulnerability-scannersvulnerability-analysissupply-chain-security+2
12 years ago
CVE-2017-8046 preview

CVE-2017-8046

GitHubbkhablenko/cve-2017-8046

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

vulnerability-analysiscode-analysisweb-application-exploitation+3
8 years ago
raptor preview

raptor

GitHubgadievron/raptor

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

penetration-testing-frameworksdynamic-analysis-sandboxingexploit-frameworks+7
3.6k5h 18m ago
rekor preview

rekor

GitHubsigstore/rekor

Software Supply Chain Transparency Log

cryptographydevsecopssupply-chain-security
1.2k1 day ago
in-toto preview

in-toto

GitHubin-toto/in-toto

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

authentication-authorizationdefensive-toolscryptography+2
1.0k29 days ago
deepsec preview

deepsec

GitHubvercel-labs/deepsec

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

static-analysisvulnerability-scannerscode-analysis+5
6.7k2 days ago
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

cloud-infrastructure-securitystatic-analysiscontainer-security+8
7854 days ago
cyclonedx-cli preview

cyclonedx-cli

GitHubcyclonedx/cyclonedx-cli

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

defensive-toolscryptographydevsecops+2
5452 months ago
DependencyCheck preview

DependencyCheck

GitHubdependency-check/dependencycheck

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

vulnerability-scannersvulnerability-analysisdevsecops+1
7.7k2 days ago
fulcio preview

fulcio

GitHubsigstore/fulcio

Certificate authority issuing short-lived code-signing certificates tied to OpenID Connect identities, enabling verifiable software supply chain…

authentication-authorizationcryptographyidentity-access-management+1
8843 days ago
cve-lite-cli preview

cve-lite-cli

GitHubowasp/cve-lite-cli

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

static-analysisvulnerability-scannerscode-analysis+5
66311h 40m ago
foxguard preview

foxguard

GitHub0sec-labs/foxguard

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

static-analysisvulnerability-scannersencryption-decryption-tools+8
2805 days ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

vulnerability-analysisweb-application-exploitationweb-security+7
341 day ago
cosign preview

cosign

GitHubsigstore/cosign

Code signing and transparency for containers and binaries

authentication-authorizationcontainer-securityencryption-decryption-tools+3
6.2k2 days ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

vulnerability-scannerspenetration-testingprivacy+6
1.4k1 day ago
skills preview

skills

GitHubtrailofbits/skills

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

static-analysisvulnerability-analysiscode-analysis+8
6.5k1 day ago
bromure preview

bromure

GitHubrderaison/bromure

Proper sandboxing for agentic coding and web browsing

vulnerability-scannerscontainer-securitydynamic-analysis-sandboxing+6
2751 day ago
CVE-2007-4559 preview

CVE-2007-4559

GitHubdavidholiday/cve-2007-4559

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

static-analysisvulnerability-analysiscode-analysis+3
3 years ago
Previous1…567…44Next