> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Watchtower: When HTML5 LocalStorage Became a Security Audit Database

★ 110 Ruby May 15, 2026
Cybersecurity

Building a Self-Documenting Security Remediation Pipeline: Lessons from AvP

★ 1 HTML May 15, 2026
Cybersecurity

Inside Cockatrice: Building a Cheat-Proof Virtual Tabletop with Qt and Server-Authoritative Design

★ 1.8k C++ May 15, 2026
Cybersecurity

PCC: The Two-Day Self-Destructing PHP Security Audit

★ 819 PHP May 14, 2026
Cybersecurity

XSS ChEF: The Chrome Extension Exploitation Framework That Revealed a Security Crisis

★ 572 JavaScript May 14, 2026
Cybersecurity

Netflix's Sleepy Puppy Docker: Why This Deprecated XSS Hunter Works Only Over HTTP

★ 44 Dockerfile May 14, 2026
Cybersecurity

Sleepy Puppy: How Netflix Built a Callback-Based XSS Detection System That Tracked Payloads Across Time and Applications

★ 1.0k JavaScript May 14, 2026
Cybersecurity

Wifiphisher: Building Convincing Rogue Access Points for Red Team Engagements

★ 14.6k Python May 14, 2026
Cybersecurity

Pupy: The Python C2 Framework That Lives Entirely in Memory

★ 9.0k Python May 14, 2026
Cybersecurity

IntruderPayloads: The Bug Bounty Hunter's Arsenal for Burp Suite

★ 3.9k BlitzBasic May 14, 2026
Cybersecurity

Evilarc: The 200-Line Python Script That Breaks Archive Extraction Everywhere

★ 1.0k Python May 14, 2026
Cybersecurity

SSVL: OWASP's Attempt to Solve the Vulnerability Data Babel Problem

★ 14 May 14, 2026
Cybersecurity

Inspeckage: The Xposed Module That Taught Android Security Engineers How to See Through Apps

★ 3.0k Java May 14, 2026
Cybersecurity

Mimikittenz: Memory Scraping for Post-Exploitation Without Admin Rights

★ 1.9k PowerShell May 14, 2026
Cybersecurity

Hound: How Trigram Indexing Delivers Sub-Second Code Search Without ElasticSearch

★ 5.8k JavaScript May 14, 2026
Cybersecurity

HackVault: A Security Researcher's Personal Arsenal of Web Exploitation Techniques

★ 2.0k JavaScript May 14, 2026
Cybersecurity

Chuckle: The Shell Script That Automates Multi-Tool SMB Relay Attacks

★ 153 Shell May 14, 2026
Cybersecurity

VisualCodeGrepper: The Legacy SAST Tool That Scans COBOL and Classic ASP When Nothing Else Will

★ 548 Visual Basic .NET May 14, 2026
Cybersecurity

WAVSEP: The Forgotten Benchmark That Exposed Security Scanner Snake Oil

★ 241 Java May 14, 2026
Cybersecurity

NoPE Proxy: Intercepting Non-HTTP Traffic Inside Burp Suite

★ 1.7k Java May 14, 2026
Cybersecurity

Inside GE's Predix Security Archives: What Industrial IoT Documentation Reveals About Enterprise Platform Governance

★ 3 May 14, 2026
Cybersecurity

Static Analysis Tools Repository: The Comprehensive Directory That Powers Developer Tool Discovery

★ 14.5k Rust May 14, 2026
Cybersecurity

How a Browser Userscript Bypassed Skype's Message Sanitization

★ 19 JavaScript May 14, 2026
Cybersecurity

Mastering Nmap's Greppable Output: A Field Guide to Unix Pipeline Wizardry

★ 406 May 14, 2026