> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Spring Boot Actuator Exploitation: A Security Researcher's Arsenal

★ 424 May 12, 2026
Cybersecurity

PowerZure: When Your Azure Credentials Become Someone Else's Attack Surface

★ 1.3k PowerShell May 12, 2026
Cybersecurity

The macOS Security Arsenal: A Critical Review of kai5263499/osx-security-awesome

★ 775 May 12, 2026
Cybersecurity

VulnX: The Aggressive CMS Scanner That Automates What Penetration Testers Do Manually

★ 2.1k Python May 12, 2026
Cybersecurity

badPods: The Kubernetes Security Testing Toolkit That Maps Every Pod Privilege Escalation Path

★ 698 Shell May 12, 2026
Cybersecurity

BruteShark: Automating Credential Extraction from Network Captures with .NET Core

★ 3.4k C# May 12, 2026
Cybersecurity

KingOfBugBountyTips: A Weaponized Command Reference for Security Reconnaissance

★ 5.3k Python May 12, 2026
Cybersecurity

h2cSmuggler: Exploiting HTTP/2 Cleartext Upgrades to Bypass Reverse Proxies

★ 793 Python May 12, 2026
Cybersecurity

Bento Toolkit: Running GUI Pentesting Tools in Fedora Containers with X11 Forwarding

★ 76 Dockerfile May 12, 2026
Cybersecurity

Cloudlist: Multi-Cloud Asset Discovery for Attack Surface Management

★ 1.0k Go May 12, 2026
Cybersecurity

Axiom: Distributing Security Scans Across Hundreds of Cloud Instances With Shell Scripts

★ 4.4k Shell May 12, 2026
Cybersecurity

Crossfeed: How CISA Built a Serverless Attack Surface Monitor on AWS

★ 422 TypeScript May 12, 2026
Cybersecurity

Arsenal: A Command Injection Framework for Pentesting (That Literally Injects Your Shell)

★ 3.7k Python May 12, 2026
Cybersecurity

Intrigue-ident: Multi-Protocol Fingerprinting with Built-in CVE Mapping

★ 134 Ruby May 12, 2026
Cybersecurity

Inside CVE-Exploits: Dissecting Real-World Memory Corruption Techniques in C

★ 687 C May 12, 2026
Cybersecurity

ConsoleMe: How Netflix Built a Self-Service AWS IAM Control Plane (Before Archiving It)

★ 3.2k Python May 12, 2026
Cybersecurity

Secretz: How a Go Tool Exposed the Dark Side of Travis CI Build Logs

★ 326 Go May 12, 2026
Cybersecurity

Confused: Detecting Dependency Confusion Before Attackers Exploit Your Private Packages

★ 782 Go May 12, 2026
Cybersecurity

Hacking the Cloud: The Crowdsourced Encyclopedia That Red and Blue Teams Actually Use

★ 2.7k Dockerfile May 12, 2026
Cybersecurity

Hetty: Building a Modern HTTP Security Proxy with Go and GraphQL

★ 10.2k Go May 12, 2026
Cybersecurity

Mosint: Building a Speed-Layer Email OSINT Tool with Go Concurrency

★ 5.8k Go May 12, 2026
Cybersecurity

diodb: The Open Database Solving Security Research's Legal Gray Area

★ 1.1k Python May 12, 2026
Cybersecurity

ksubdomain: How Stateless DNS Brute-Forcing Achieves 1.6 Million Packets Per Second

★ 2.4k Go May 12, 2026
Cybersecurity

Puredns: How Two-Stage DNS Resolution Solves the Wildcard Subdomain Problem

★ 2.2k Go May 12, 2026