> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Surf: Finding SSRF Candidates in Cloud Environments Where Traditional Filters Fail

★ 758 Go May 11, 2026
Cybersecurity

How jsluice Uses AST Parsing to Find URLs Hidden in JavaScript String Concatenation

★ 1.8k Go May 11, 2026
Cybersecurity

wsrepl: The Interactive WebSocket REPL Built for Security Testing

★ 236 Python May 11, 2026
Cybersecurity

Inside CVE-2023-3519: How a 104-Byte Shellcode Compromises Citrix NetScaler Gateway

★ 229 Python May 11, 2026
Cybersecurity

Inside the Adversarial Robustness Toolbox: Building ML Systems That Survive Attacks

★ 6.0k Python May 11, 2026
Cybersecurity

Promptfoo: The Open-Source LLM Security Scanner That OpenAI and Anthropic Actually Use

★ 21.1k TypeScript May 10, 2026
Cybersecurity

garak: The LLM Vulnerability Scanner That Tests What Your Prompts Won't Tell You

★ 7.8k Python May 10, 2026
Cybersecurity

Puncia: When Standard CVE Databases Miss What Nation-States Already Exploit

★ 664 Python May 10, 2026
Cybersecurity

ARPSyndicate/awesome-intelligence: Mapping the Hidden Layer of OSINT Resources

★ 2.3k May 10, 2026
Cybersecurity

Tenacity: Python's Composable Retry Library That Survived the Great Forking

★ 8.6k Python May 10, 2026
Cybersecurity

CVE-2016-1764: How a JavaScript URI Bypassed iMessage Encryption Without Breaking Crypto

★ 51 JavaScript May 10, 2026
Cybersecurity

Ghauri: SQL Injection Automation That Actually Resumes Your Work

★ 4.0k Python May 10, 2026
Cybersecurity

ELITEWOLF: How the NSA Detects Attacks on Power Grids and Water Systems

★ 624 May 10, 2026
Cybersecurity

Porch Pirate: Mining API Secrets from Postman's Public Workspace Graveyard

★ 457 Python May 10, 2026
Cybersecurity

CALDERA: Building Autonomous Adversary Emulation with MITRE's ATT&CK Framework

★ 7.0k Python May 10, 2026
Cybersecurity

Logsensor: Scanning Thousands of Subdomains for Login Panels and POST-Based SQL Injection

★ 517 Python May 10, 2026
Cybersecurity

From Bug Report to Security Test in 60 Seconds: Inside Nuclei AI's Template Generation Pipeline

★ 552 JavaScript May 10, 2026
Cybersecurity

Gsec: A Bug Bounty Hunter's Multi-Tool That Wraps Nuclei in Aggressive Automation

★ 382 Python May 10, 2026
Cybersecurity

A2P2V: Automated Attack Path Planning That Bridges Vulnerability Scanning and Exploitation

★ 68 Python May 10, 2026
Cybersecurity

Pentest Muse CLI: When AI Agents Meet Offensive Security Workflows

★ 234 Python May 10, 2026
Cybersecurity

Inside the Security Architect Interview: What 200+ Real Questions Reveal About Hiring at Scale

★ 204 May 10, 2026
Cybersecurity

LVE: Building a CVE Database for Language Models, One Prompt at a Time

★ 114 Python May 10, 2026
Cybersecurity

GodNS: A DNS Proxy That Lies for a Living

★ 38 Go May 10, 2026
Cybersecurity

FOSSA CLI: Why a Haskell-Powered Dependency Scanner Won the Enterprise

★ 1.5k Haskell May 10, 2026