Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k16h 46m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k3h 25m ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k16 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k1 day ago
NewestRelevanceMost popularRecently updated
778 results
weave-gitops preview

weave-gitops

GitHubweaveworks/weave-gitops

Weave GitOps is transitioning to a community driven project! It provides insights into your application deployments, and makes continuous delivery…

cloud-infrastructure-securitycontainer-securityconfiguration-auditing+3
1.1k8 months ago
Docker-Security preview

Docker-Security

GitHubowasp/docker-security

Getting a handle on container security

cloud-infrastructure-securitycontainer-securityvulnerability-analysis+6
6842 years ago
packj preview

packj

GitHubossillate-inc/packj

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+3
6917 days ago
log4j-detector preview

log4j-detector

GitHubmergebase/log4j-detector

File-system scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046) by analyzing compiled Java classes, including nested…

static-analysisvulnerability-scannersvulnerability-analysis+1
6404 years ago
DockSec preview

DockSec

GitHubowasp/docksec

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

static-analysisvulnerability-scannerscontainer-security+5
4651 day ago
medusa preview

medusa

GitHubpantheon-security/medusa

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

vulnerability-scannerscontainer-securitystatic-code-analysis+8
9573 months ago
minimal preview

minimal

GitHubrtvkiz/minimal

Minimal CVE Hardened container image collection

vulnerability-scannerscontainer-securityconfiguration-auditing+3
51317h 41m ago
renovate-operator preview

renovate-operator

GitHubmogenius/renovate-operator

Operator to streamline renovate executions in Kubernetes

vulnerability-scannerscontainer-securityconfiguration-auditing+4
5396 days ago
pmg preview

pmg

GitHubsafedep/pmg

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

vulnerability-scannerscontainer-securitydynamic-analysis-sandboxing+6
4665 days ago
CVE-2021-44228-Scanner preview

CVE-2021-44228-Scanner

GitHublogpresso/cve-2021-44228-scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

vulnerability-scannersvulnerability-analysisconfiguration-auditing+3
8614 years ago
cyclonedx-cli preview

cyclonedx-cli

GitHubcyclonedx/cyclonedx-cli

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

defensive-toolscryptographydevsecops+2
5452 months ago
puncia preview

puncia

GitHubarpsyndicate/puncia

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

osintreconnaissancevulnerability-scanners+6
66122 days ago
modelscan preview

modelscan

GitHubprotectai/modelscan

Protection against Model Serialization Attacks

defensive-toolsstatic-analysisvulnerability-scanners+5
7747 months ago
supply-chain-monitor preview

supply-chain-monitor

GitHubelastic/supply-chain-monitor

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

vulnerability-analysiscode-analysismalware-analysis+3
5295 months ago
secureboot_objects preview

secureboot_objects

GitHubmicrosoft/secureboot_objects

Microsoft's curated repository of secure boot objects (KeK, Db, Dbx) for firmware and runtime, enabling transparent revocation updates and…

embedded-systems-securityconfiguration-auditingsecurity-virtualization+3
28115 days ago
log4j-finder preview

log4j-finder

GitHubfox-it/log4j-finder

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

static-analysisvulnerability-scannersvulnerability-analysis+3
4393 years ago
prismor preview

prismor

GitHubprismorsec/prismor

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

defensive-toolscontainer-securitydevsecops+5
28313h 59m ago
legitify preview

legitify

GitHublegit-labs/legitify

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

vulnerability-scannersconfiguration-auditingcloud-security+3
8801 year ago
Previous1…456…44Next