Cybersecurity
Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.
358 articles
Cybersecurity
Tachikoma: Building Security Alerts on Diffs Instead of State
Cybersecurity
Building Automated DNS Blocklists with Cisco Umbrella's API and Certificate Transparency Logs
Cybersecurity
Inside Awesome-Red-Teaming: A Time Capsule of Offensive Security's Golden Era
Cybersecurity
MoistPetal: Dissecting a Go-Based Malware Framework for Red Team Infrastructure Automation
Cybersecurity
Offensive-Dockerfiles: Containerizing Pentesting Tools for Ephemeral Cloud Attacks
Cybersecurity
AutoSploit: When Metasploit Meets Mass Automation (And Why That's Terrifying)
Cybersecurity
gowitness: How Chrome Headless Became a Recon Powerhouse for Security Teams
Cybersecurity
gnmapper: Converting Nmap's Greppable Output to CSV with 50 Lines of Bash
Cybersecurity
SubOver: How Go Concurrency Revolutionized Subdomain Takeover Detection
Cybersecurity
Metta: Building an Adversarial Simulation Framework That Actually Tests Your Defenses
Cybersecurity
Raven: A Cautionary Tale of LinkedIn Scraping and the Fragility of Reconnaissance Tools
Cybersecurity
Findsploit: A Single-Command Gateway to Every Exploit Database on Your System
Cybersecurity
megplus: When Bash Wrappers Attack (A Cautionary Tale in Reconnaissance Automation)
Cybersecurity
GetAltName: Direct SSL Certificate Inspection for Subdomain Discovery Beyond Certificate Transparency
Cybersecurity
TruffleHog: The Secret Scanner That Actually Verifies Your Leaked Credentials
Cybersecurity
Inside Java Deserialization Attacks: A Security Cheat Sheet Worth 3,000+ Stars
Cybersecurity
Weaponizing Apache's server-status: How Misconfigurations Leak Request Intelligence
Cybersecurity
Building a GCP Security Auditing Framework: Lessons from Spotify's Deprecated Tool
Cybersecurity
JexBoss: The Blunt Instrument for Testing Legacy JBoss Deserialization Flaws
Cybersecurity
Inside CVE-2017-5638: Dissecting a Python Exploit for Apache Struts2's Most Devastating Vulnerability
Cybersecurity
Snallygaster: The Single-File Security Scanner That Finds What Developers Leave Behind
Cybersecurity
Exploiting .DS_Store Leaks: How ds_store_exp Turns macOS Metadata Into a Security Goldmine
Cybersecurity
GitHack: Weaponizing Exposed .git Folders to Reconstruct Source Code
Cybersecurity