Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k0 days ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k13h 47m ago
grype preview#3

grype

GitHubanchore/grype
12.7k7h 27m ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k17 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k2 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k29 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k3 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
543 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k14h 41m ago
NewestRelevanceMost popularRecently updated
781 results
shim-review preview

shim-review

GitHubrhboot/shim-review

Reviews of shim

vulnerability-analysiscode-analysissupply-chain-security+3
895 days ago
hijagger preview

hijagger

GitHubfirefart/hijagger

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

osintreconnaissancevulnerability-scanners+3
3056h 51m ago
confused preview

confused

GitHubvisma-prodsec/confused

Tool to check for dependency confusion vulnerabilities in multiple package management systems

vulnerability-analysissupply-chain-security
7873 years ago
ws4-secure-design-agentic-systems preview

ws4-secure-design-agentic-systems

GitHubcosai-oasis/ws4-secure-design-agentic-systems

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

cloud-securitythreat-intelligenceidentity-access-management+6
1261 day ago
clawdstrike preview

clawdstrike

GitHubbackbay-labs/clawdstrike

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

container-securityforensicscloud-security+5
2861 month ago
chain-bench preview

chain-bench

GitHubaquasecurity/chain-bench

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

vulnerability-scannersconfiguration-auditingdevsecops+1
7742 years ago
smokedmeat preview

smokedmeat

GitHubboostsecurityio/smokedmeat

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

penetration-testing-frameworksprivilege-escalationexploit-frameworks+9
3738 days ago
js-x-ray preview

js-x-ray

GitHubnodesecure/js-x-ray

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

static-analysisvulnerability-analysiscode-analysis+2
2858h 58m ago
aura preview

aura

GitHubsourcecode-ai/aura

Python source code auditing and static analysis on a large scale

static-analysisvulnerability-analysiscode-analysis+4
4932 years ago
bomber preview

bomber

GitHubdevops-kung-fu/bomber

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

vulnerability-scannersdevsecopssupply-chain-security
6247 months ago
sage preview

sage

GitHubgendigitalinc/sage

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

defensive-toolsphishing-toolsvulnerability-analysis+6
2629 days ago
raven preview

raven

GitHubcycodelabs/raven

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

vulnerability-scannerscode-analysisdevsecops+3
7461 year ago
terrier preview

terrier

GitHubheroku/terrier

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

container-securityvulnerability-analysishash-analysis+1
2273 months ago
proxy preview

proxy

GitHubgit-pkgs/proxy

A lightweight caching proxy for package registries.

vulnerability-analysiscloud-securitydevsecops+2
1551 day ago
bromure preview

bromure

GitHubrderaison/bromure

Proper sandboxing for agentic coding and web browsing

vulnerability-scannerscontainer-securitydynamic-analysis-sandboxing+6
2751 day ago
quantum-security-project preview

quantum-security-project

GitHubowasp/quantum-security-project

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

threat-feeds-aggregatorsvulnerability-analysiscryptography+8
5818 days ago
hotpatch-for-apache-log4j2 preview

hotpatch-for-apache-log4j2

GitHubcorretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

defensive-toolsvulnerability-analysisexploitation+2
4973 years ago
agentseal preview

agentseal

GitHubgetagentseal/agentseal

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

vulnerability-scannersdata-exfiltrationinformation-gathering+7
3413 months ago
Previous1…567…44Next