Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k2 days ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k1 day ago
syft preview#4

syft

GitHubanchore/syft
9.6k1 day ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k18 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k3 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k1 month ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k4 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
544 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k3h 37m ago
NewestRelevanceMost popularRecently updated
781 results
smart-tree preview

smart-tree

GitHub8b-is/smart-tree

Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…

general-purpose-utilitiesvulnerability-scannersmalware-analysis+3
26615 days ago
depsguard preview

depsguard

GitHubarnica/depsguard

Harden your package manager configs against supply chain attacks.

vulnerability-analysisconfiguration-auditingcloud-security+3
3822 months ago
foxguard preview

foxguard

GitHub0sec-labs/foxguard

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

static-analysisvulnerability-scannersencryption-decryption-tools+8
2806 days ago
vulnerable-mcp-servers-lab preview

vulnerable-mcp-servers-lab

GitHubappsecco/vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

privilege-escalationvulnerability-analysiscode-analysis+7
2749 months ago
sec-af preview

sec-af

GitHubagent-field/sec-af

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

static-analysisvulnerability-scannerscode-analysis+7
1941 month ago
tools-python preview

tools-python

GitHubspdx/tools-python

A Python library to parse, validate and create SPDX documents.

general-purpose-utilitiesdevsecopssupply-chain-security
2566 months ago
SupplyChainAttacks preview

SupplyChainAttacks

GitHubbinarly-io/supplychainattacks

Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

ioc-managementthreat-intelligencesupply-chain-security+4
2811 year ago
fix-react2shell-next preview

fix-react2shell-next

GitHubvercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

vulnerability-scannerscode-analysisscripting-automation+3
4019 months ago
depx preview

depx

GitHubprojectdiscovery/depx

Malicious package & supply-chain intelligence

vulnerability-analysisdevsecopssecret-detection+2
1821 month ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

vulnerability-scannerscontainer-securitycloud-security+7
21015h 37m ago
advisories preview

advisories

GitHubjustinsteven/advisories

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

vulnerability-analysisweb-securitycloud-security+3
2713 years ago
trajan preview

trajan

GitHubpraetorian-inc/trajan

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

static-analysisvulnerability-scannerscode-analysis+7
17610 days ago
opentaint preview

opentaint

GitHubseqra/opentaint

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

static-analysisvulnerability-scannersvulnerability-analysis+7
1273 days ago
TPMGenie preview

TPMGenie

GitHubnccgroup/tpmgenie

TPM Genie is an I2C bus interposer for discrete Trusted Platform Modules

embedded-systems-securityvulnerability-analysisexploitation+8
2295 years ago
GitHound preview

GitHound

GitHubspecterops/githound

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

reconnaissancevulnerability-analysisinformation-gathering+4
1431 month ago
safe-npm preview

safe-npm

GitHubkevinslin/safe-npm

Safely install NPM packages

general-purpose-utilitiesvulnerability-analysisscripting-automation+2
19310 months ago
enject preview

enject

GitHubgreatscott/enject

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

encryption-decryption-toolscloud-securitydevsecops+3
5007 months ago
cloud-middleware-dataset preview

cloud-middleware-dataset

GitHubwiz-sec-public/cloud-middleware-dataset

Curated dataset of cloud middleware agents installed by AWS, Azure, and GCP, documenting past vulnerabilities, privileges, and attack-surface risks…

cloud-infrastructure-securityvulnerability-analysiscloud-security+2
2492 years ago
Previous1…678…44Next