> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Vanquish: The OSCP-Era Orchestrator That Chains Kali's Arsenal Into Attack Pipelines

★ 512 Python May 14, 2026
Cybersecurity

VHostScan: Finding Hidden Web Apps Behind Shared IP Addresses

★ 1.3k Python May 14, 2026
Cybersecurity

Weaponizing OGNL: How CVE-2017-5638 Turned HTTP Headers Into Remote Shells

★ 442 Python May 14, 2026
Cybersecurity

Inside j0bin/Pentest-Resources: A Pentester's Personal Arsenal Turned Public Repository

★ 123 Python May 14, 2026
Cybersecurity

Hacking Slack's UI: CSS Injection in Electron Apps

★ 1.7k CSS May 14, 2026
Cybersecurity

Bandit: How OpenStack's AST-Powered Security Scanner Catches Python Vulnerabilities Before Deployment

★ 1.2k May 14, 2026
Cybersecurity

Scanners-Box: The Community-Curated Arsenal of 338+ Security Tools You've Never Heard Of

★ 8.9k May 14, 2026
Cybersecurity

Inside struts-scan: A Python 2 Relic That Still Hunts 17 Struts2 Vulnerabilities

★ 1.4k Python May 14, 2026
Cybersecurity

webanalyze: Mass Technology Detection Without the Browser Overhead

★ 1.1k Go May 14, 2026
Cybersecurity

Inside a 211MB Wordlist: Engineering Efficient Content Discovery for Web Penetration Testing

★ 217 Python May 14, 2026
Cybersecurity

Striker: The Four-Phase Reconnaissance Scanner That Weaponizes Your Subdomain Enumeration

★ 2.3k Python May 14, 2026
Cybersecurity

Dracnmap: When Teaching Tools Reveal nmap's Accessibility Problem

★ 1.3k Shell May 14, 2026
Cybersecurity

RED_HAWK: The Last PHP-Based Security Scanner Before Everyone Switched to Python

★ 3.7k PHP May 14, 2026
Cybersecurity

Building a Web Directory Bruteforcer: A Case Study in Go Concurrency

★ 282 Go May 14, 2026
Cybersecurity

Tachikoma: Building Security Alerts on Diffs Instead of State

★ 22 Python May 14, 2026
Cybersecurity

Building Automated DNS Blocklists with Cisco Umbrella's API and Certificate Transparency Logs

★ 1 Perl May 14, 2026
Cybersecurity

Inside Awesome-Red-Teaming: A Time Capsule of Offensive Security's Golden Era

★ 7.9k May 14, 2026
Cybersecurity

MoistPetal: Dissecting a Go-Based Malware Framework for Red Team Infrastructure Automation

★ 386 Go May 13, 2026
Cybersecurity

Offensive-Dockerfiles: Containerizing Pentesting Tools for Ephemeral Cloud Attacks

★ 210 Python May 13, 2026
Cybersecurity

AutoSploit: When Metasploit Meets Mass Automation (And Why That's Terrifying)

★ 5.2k Python May 13, 2026
Cybersecurity

gowitness: How Chrome Headless Became a Recon Powerhouse for Security Teams

★ 4.3k Go May 13, 2026
Cybersecurity

gnmapper: Converting Nmap's Greppable Output to CSV with 50 Lines of Bash

★ 4 Shell May 13, 2026
Cybersecurity

SubOver: How Go Concurrency Revolutionized Subdomain Takeover Detection

★ 966 Go May 13, 2026
Cybersecurity

Metta: Building an Adversarial Simulation Framework That Actually Tests Your Defenses

★ 1.1k Python May 13, 2026