Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k0 days ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k20h 43m ago
grype preview#3

grype

GitHubanchore/grype
12.7k5 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k10h 37m ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k15 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k1 day ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
541 day ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k16h 5m ago
NewestRelevanceMost popularRecently updated
778 results
cplt preview

cplt

GitHubnavikt/cplt

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

defensive-toolsdynamic-analysis-sandboxingconfiguration-auditing+7
1211 day ago
ndaal_public_SBOM_Auditor preview

ndaal_public_SBOM_Auditor

GitLabvpierre/ndaal_public_sbom_auditor

Offline single-binary web app that ingests CycloneDX, SPDX and syft SBOMs, runs an ensemble of CVE scanners, enriches findings with EPSS, CISA-KEV…

defensive-toolsioc-managementstatic-analysis+7
1 day ago
cryptoptic preview

cryptoptic

GitHubnationwide-group-oss/cryptoptic

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

defensive-toolsstatic-code-analysisvulnerability-analysis+6
1 day ago
ai-ctf preview

ai-ctf

GitHubmubix/ai-ctf

Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.

osintinformation-gatheringweb-security+6
183 days ago
hol-guard preview

hol-guard

GitHubhashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

defensive-toolsstatic-analysisvulnerability-scanners+7
6343 days ago
async-http-client-check preview

async-http-client-check

GitHubxiaoqimikko/async-http-client-check

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

defensive-toolsstatic-analysisvulnerability-scanners+4
4 days ago
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

defensive-toolsstatic-analysisvulnerability-scanners+4
91 year ago
bigint-buffer-js preview

bigint-buffer-js

GitHubdisley15-collab/bigint-buffer-js

Pure-JS drop-in for [email protected] without the vulnerable native binding (CVE-2025-3194)

defensive-toolsvulnerability-analysiscryptography+2
6 days ago
GoCD_PoC_Supply_Chain_Attack preview

GoCD_PoC_Supply_Chain_Attack

GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

payload-generationvulnerability-analysisexploitation+7
7 days ago
stylesmuggler-adobe-patches-mageos preview
Archived

stylesmuggler-adobe-patches-mageos

GitHubdisrex-group/stylesmuggler-adobe-patches-mageos

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to…

vulnerability-analysisconfiguration-auditingdevsecops+1
15 days ago
local-log4j-vuln-scanner preview
Archived

local-log4j-vuln-scanner

GitHubhillu/local-log4j-vuln-scanner

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

static-analysisvulnerability-scannersvulnerability-analysis+3
3714 years ago
anchore-engine preview
Archived

anchore-engine

GitHubanchore/anchore-engine

A service that analyzes docker images and scans for vulnerabilities

static-analysisvulnerability-scannerscontainer-security+3
1.6k3 years ago
openclarity preview
Archived

openclarity

GitHubopenclarity/openclarity

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

cloud-infrastructure-securityvulnerability-scannerscontainer-security+7
1.5k4 months ago
gitoops preview
Archived

gitoops

GitHubovotech/gitoops

all paths lead to clouds

privilege-escalationreconnaissancelateral-movement+6
6402 years ago
whispers preview
Archived

whispers

GitHubskyscanner/whispers

Identify hardcoded secrets in static structured text

static-analysisvulnerability-analysiscode-analysis+4
5062 years ago
makes preview
Archived

makes

GitHubfluidattacks/makes

A software supply chain framework powered by Nix.

cloud-infrastructure-securitygeneral-purpose-utilitiescontainer-security+3
4901 year ago
CVE-2021-44228_scanner preview
Archived

CVE-2021-44228_scanner

GitHubcertcc/cve-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

static-analysisvulnerability-scannersvulnerability-analysis+3
3504 years ago
reposaur preview
Archived

reposaur

GitHubreposaur/reposaur

Open source compliance tool for development platforms.

vulnerability-analysiscode-analysisconfiguration-auditing+5
2862 years ago
Previous1…41424344Next