> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Inside EQGRP: A Historical Deep-Dive into the NSA's Leaked Offensive Cyber Arsenal

★ 4.2k Perl May 14, 2026
Cybersecurity

MimiPenguin: Harvesting Linux Credentials from Process Memory Like It's 2007

★ 4.1k C May 14, 2026
Cybersecurity

RedSnarf: The Post-Exploitation Credential Harvester That Time (Almost) Forgot

★ 1.2k PowerShell May 14, 2026
Cybersecurity

The Red Team Infrastructure Wiki: A Blueprint for Resilient Offensive Operations

★ 4.5k May 14, 2026
Cybersecurity

DNSChain: The Blockchain DNS Server That Tried to Kill Certificate Authorities

★ 1.7k CoffeeScript May 14, 2026
Cybersecurity

GoFetch: The Self-Replicating PowerShell Worm That Turns BloodHound Graphs Into Automated AD Attacks

★ 636 PowerShell May 14, 2026
Cybersecurity

Security Regression Testing in Django: Testing Your Way Out of Vulnerabilities

★ 19 Python May 14, 2026
Cybersecurity

Building a Serverless Honeytoken System with AWS Lambda: Inside honeyλ

★ 525 Python May 14, 2026
Cybersecurity

hslatman/awesome-threat-intelligence: The Security Analyst's Map to the Threat Intelligence Ecosystem

★ 10.2k May 14, 2026
Cybersecurity

How Netflix Automatically Strips AWS Permissions at Scale with Repokid

★ 1.1k Python May 14, 2026
Cybersecurity

S3Cruze: The Pentester's Swiss Army Knife for AWS Bucket Security Testing

★ 74 Python May 14, 2026
Cybersecurity

Kubebot: The Slack Security Scanner That Weaponizes Kubernetes Ephemeral Containers

★ 165 Python May 14, 2026
Cybersecurity

Second Order: Finding Subdomain Takeovers Hidden in Your Application Logic

★ 403 Go May 14, 2026
Cybersecurity

Backslash-Powered Scanner: Finding Zero-Day Injections Through Differential Analysis

★ 711 Java May 14, 2026
Cybersecurity

GitHub Dorks: Mining Public Repositories for Accidentally Leaked Secrets

★ 3.2k Python May 14, 2026
Cybersecurity

Inside X41's 2017 Browser Security Arsenal: A Historical Deep-Dive into Sandbox Escape Techniques

★ 184 C# May 14, 2026
Cybersecurity

Fuzzapi: A Rails Web Interface for REST API Penetration Testing That Time Forgot

★ 666 Ruby May 14, 2026
Cybersecurity

aiodnsbrute: How Asyncio Turns DNS Enumeration Into a Concurrency Masterclass

★ 671 Python May 14, 2026
Cybersecurity

Retrace: The LD_PRELOAD Interceptor That Turns Binaries Into Security Playgrounds

★ 62 C May 14, 2026
Cybersecurity

TheFatRat: Why This 11K-Star Exploit Generator is Both Popular and Problematic

★ 11.2k C May 14, 2026
Cybersecurity

XRay: Building a Reconnaissance Pipeline That Bridges Passive OSINT and Active Enumeration

★ 2.3k Go May 14, 2026
Cybersecurity

Gobuster: Why Go's Concurrency Model Makes It the Fastest Directory Brute-Forcer

★ 13.7k Go May 14, 2026
Cybersecurity

SecLists: The 57,000-File Repository That Changed Security Testing Forever

★ 70.9k PHP May 14, 2026
Cybersecurity

PMD: Building a Multi-Language Static Analyzer on AST Parsing and Rule Engines

★ 5.4k Java May 14, 2026