Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k18h 3m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k4h 43m ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k16 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
778 results
halo-record preview

halo-record

GitHubbkuan001/halo-record

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.

forensicssupply-chain-securityincident-response+1
639 days ago
cs50-cybersecurity-final-project preview

cs50-cybersecurity-final-project

GitHubnamegabevictoire01-sys/cs50-cybersecurity-final-project

CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094

vulnerability-analysismalware-analysisthreat-intelligence+2
19 days ago
xz-utils-backdoor-case-study preview

xz-utils-backdoor-case-study

GitHubmichel-dv/xz-utils-backdoor-case-study

Technical case study of the XZ Utils backdoor (CVE-2024-3094), covering supply-chain trust abuse, malicious release artifacts, build-stage injection,…

vulnerability-analysisreverse-engineeringmalware-analysis+6
9 days ago
ApplicationInspector preview

ApplicationInspector

GitHubmicrosoft/applicationinspector

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

static-analysisstatic-code-analysisvulnerability-analysis+3
4.4k9 days ago
TriSuElla-AIDLCA-Framework preview

TriSuElla-AIDLCA-Framework

GitHubowasp/trisuella-aidlca-framework

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

static-code-analysisvulnerability-analysiscode-analysis+7
210 days ago
guardskill preview

guardskill

GitHubsoemoescode/guardskill

Read-only scanner for what lets a repository run code in a coding agent (Claude Code, Codex, Cursor, Copilot): git settings, hooks, and committed MCP…

static-analysisvulnerability-scannerscode-analysis+4
110 days ago
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

static-code-analysisvulnerability-analysiscode-analysis+4
10 days ago
spring-cvss-check preview

spring-cvss-check

GitHubxiaoqimikko/spring-cvss-check

Scans Java artifacts and source for Spring/Tomcat CVEs, compares vendor vs NVD CVSS scores, verifies exploitability conditions, and checks if fix…

vulnerability-scannersvulnerability-analysisconfiguration-auditing+2
10 days ago
smart-tree preview

smart-tree

GitHub8b-is/smart-tree

Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…

general-purpose-utilitiesvulnerability-scannersmalware-analysis+3
26613 days ago
owasp-aibom preview

owasp-aibom

GitHubowasp/owasp-aibom

OWASP project defining an AI Bill of Materials (AIBOM) standard to document AI/ML components, dependencies, and supply chain risks for AI security…

vulnerability-analysisdevsecopssupply-chain-security+3
1213 days ago
netty-resolver-dns-check preview

netty-resolver-dns-check

GitHubxiaoqimikko/netty-resolver-dns-check

Offline static checker that inspects packaged Java jars for vulnerable netty-resolver-dns versions and detects whether Spring WebClient actually uses…

defensive-toolsstatic-analysisvulnerability-scanners+5
13 days ago
creadur-rat-gradle preview

creadur-rat-gradle

GitHubeskatos/creadur-rat-gradle

Apache RAT (Release Audit Tool) Gradle Plugin

static-analysiscode-analysisconfiguration-auditing+2
1113 days ago
reproducer-okio-cve-2023-3635 preview

reproducer-okio-cve-2023-3635

GitHubjoshuaasmith/reproducer-okio-cve-2023-3635

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

android-securityvulnerability-analysismobile-security+2
14 days ago
CVE-2026-0303 preview

CVE-2026-0303

GitHubyonliud/cve-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

static-analysisvulnerability-analysiscode-analysis+5
14 days ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

web-application-exploitationweb-securitypenetration-testing+7
1814 days ago
pip-audit preview

pip-audit

GitHubpypa/pip-audit

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

vulnerability-scannersdevsecopssecret-detection+1
1.3k15 days ago
tomcat-line-check preview

tomcat-line-check

GitHubxiaoqimikko/tomcat-line-check

CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers…

vulnerability-scannersconfiguration-auditingweb-security+1
15 days ago
thymeleaf-check preview

thymeleaf-check

GitHubxiaoqimikko/thymeleaf-check

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

static-analysisvulnerability-scannersconfiguration-auditing+2
15 days ago
Previous1…678…44Next