> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Cyber Riposte: When Your Security Team Wants to Code-Review the Firewall

★ 2 Python Jun 10, 2026
Cybersecurity

Building Reproducible Penetration Testing Environments with NixOS: nixos-pentest

★ 3 Shell May 30, 2026
Cybersecurity

RedAI: When Your Security Scanner Needs to Actually Prove the Exploit Works

★ 317 TypeScript May 26, 2026
Cybersecurity

Caldera: Building Adversary Emulation with Fact-Based Planning Engines

★ 7.0k Python May 24, 2026
Cybersecurity

Caldera: When Your Red Team Needs a Planning Algorithm, Not Just Another C2

★ 7.0k Python May 24, 2026
Cybersecurity

Joro: The Web Exploitation Framework That Finally Bridges Proxy, C2, and Team Collaboration

★ 12 Go May 24, 2026
Cybersecurity

JSPrime: The 2013 Browser-Based JavaScript Security Scanner That Pioneered Framework-Aware Static Analysis

★ 591 JavaScript May 15, 2026
Cybersecurity

Nogotofail: Google's On-Path Blackbox Security Testing Framework for Mobile Apps

★ 2.9k Python May 15, 2026
Cybersecurity

WS-Attacker: The Academic Framework That Exploits SOAP's Hidden Attack Surface

★ 494 Java May 15, 2026
Cybersecurity

PayloadsAllTheThings: The 77,000-Star Security Knowledge Base That Changed How Pentesters Work

★ 77.7k Python May 15, 2026
Cybersecurity

Acamar: When Less Is More in Subdomain Enumeration

★ 90 Python May 15, 2026
Cybersecurity

Glow: Why Rendering Markdown in the Terminal Shouldn't Require a Browser

★ 25.2k Go May 15, 2026
Cybersecurity

Security APIs: The Curated Directory That Maps the Threat Intelligence Landscape

★ 980 May 15, 2026
Cybersecurity

Inside Mathias Bynens' Dotfiles: The Blueprint for 30,000 macOS Developer Environments

★ 31.3k Shell May 15, 2026
Cybersecurity

Prompt Engineering for Red Teams: How ChatGPT Became an Offensive Security Multiplier

★ 54 May 15, 2026
Cybersecurity

Responder: Weaponizing Windows Name Resolution to Harvest Domain Credentials

★ 4.9k Python May 15, 2026
Cybersecurity

PowerTools: The Deprecated PowerShell Arsenal That Shaped Modern Red Team Operations

★ 2.2k PowerShell May 15, 2026
Cybersecurity

IIS-ShortName-Scanner: Exploiting a 13-Year-Old Vulnerability Microsoft Won't Fix

★ 1.7k Java May 15, 2026
Cybersecurity

Inside mubix/post-exploitation: A Time Capsule of Red Team Command-Line Tradecraft

★ 1.6k C May 15, 2026
Cybersecurity

PowerSploit: The PowerShell Framework That Taught Defenders What to Fear

★ 13.0k PowerShell May 15, 2026
Cybersecurity

GetHead: The Browser-Based HTTP Header Security Scanner That Fits in Your Bookmarks Bar

★ 116 CSS May 15, 2026
Cybersecurity

Python Pentest Tools: A Curated Gateway to Security Testing's Hidden Arsenal

★ 2.9k May 15, 2026
Cybersecurity

Commix: Automating Command Injection Exploitation with Polymorphic Payloads

★ 5.7k Python May 15, 2026
Cybersecurity

dirsearch: How Smart Wordlist Handling Makes or Breaks Web Path Discovery

★ 14.3k Python May 15, 2026