> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

24 Hard-Learned Lessons from Smart Contract Hacking Challenges

★ 9 May 12, 2026
Cybersecurity

Gorilla: A Rust-Powered Wordlist Generator That Replaces Your Entire Password-Cracking Toolkit

★ 391 Rust May 12, 2026
Cybersecurity

Learning Smart Contract Exploits by Running Them: Inside Web3-Graveyard

★ 21 Solidity May 12, 2026
Cybersecurity

Modernizing Black Hat Python: Converting Offensive Security Code from Python 2 to 3

★ 2.3k Python May 12, 2026
Cybersecurity

Metlo: The Open-Source API Security Platform That Watches Your Traffic

★ 1.8k TypeScript May 12, 2026
Cybersecurity

OffensiveNotion: How Rust and Notion's API Create Undetectable Command and Control

★ 1.2k Rust May 12, 2026
Cybersecurity

lsd: Why 16,000 Developers Replaced ls With a Rust Rewrite

★ 16.0k Rust May 12, 2026
Cybersecurity

RedEye: How CISA Built a Time Machine for Red Team Operations

★ 2.7k TypeScript May 11, 2026
Cybersecurity

Teaching GPT-3 to Crack Your Password: A Research Case Study in Targeted Password Guessing

★ 74 Jupyter Notebook May 11, 2026
Cybersecurity

Smap: Why This Nmap Clone Doesn't Touch Your Target

★ 3.2k Go May 11, 2026
Cybersecurity

CloudProxy: Self-Hosting Your Way Past Cloudflare's Bot Detection

★ 569 TypeScript May 11, 2026
Cybersecurity

Open-CVDB: The Missing CVE Database for Cloud Provider Vulnerabilities

★ 393 May 11, 2026
Cybersecurity

Recog: The XML Fingerprint Database Powering Metasploit's Service Detection

★ 773 Ruby May 11, 2026
Cybersecurity

Akto: The API Security Platform That Learns From Your Production Traffic

★ 1.5k Java May 11, 2026
Cybersecurity

Mining 63,000+ Unmapped CVEs: How missing-cve-nuclei-templates Finds Bug Bounty Gold

★ 433 Shell May 11, 2026
Cybersecurity

Bearer: The Open-Source SAST Tool That Actually Cares About Your Users' Privacy

★ 2.6k Go May 11, 2026
Cybersecurity

Omnispray: Building a Lockout-Aware Password Spraying Framework with Python Asyncio

★ 131 Python May 11, 2026
Cybersecurity

BurpGPT: Teaching Your Security Scanner to Think With LLMs

★ 2.3k Java May 11, 2026
Cybersecurity

CloudGPT: When ChatGPT Audits Your AWS IAM Policies (And Why That's Fascinating)

★ 165 Python May 11, 2026
Cybersecurity

Inside the Offensive AI Compilation: A Taxonomy of Machine Learning Weaponization

★ 1.4k HTML May 11, 2026
Cybersecurity

When Your LLM Reads Malicious Instructions: Understanding Indirect Prompt Injection

★ 2.1k Jupyter Notebook May 11, 2026
Cybersecurity

Scanning 74,000 WordPress Vulnerabilities in One Command: Inside nuclei-wordfence-cve

★ 1.2k Python May 11, 2026
Cybersecurity

DefaultCreds-cheat-sheet: Mining 3,711 Default Credentials for Security Testing

★ 6.5k Python May 11, 2026
Cybersecurity

Afuzz: Language-Aware Web Path Fuzzing for Bug Bounty Hunters

★ 311 Python May 11, 2026