> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗

All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

358 articles

Cybersecurity

Tachikoma: Building Security Alerts on Diffs Instead of State

★ 22 Python May 14, 2026
Cybersecurity

Building Automated DNS Blocklists with Cisco Umbrella's API and Certificate Transparency Logs

★ 1 Perl May 14, 2026
Cybersecurity

Inside Awesome-Red-Teaming: A Time Capsule of Offensive Security's Golden Era

★ 7.9k May 14, 2026
Cybersecurity

MoistPetal: Dissecting a Go-Based Malware Framework for Red Team Infrastructure Automation

★ 386 Go May 13, 2026
Cybersecurity

Offensive-Dockerfiles: Containerizing Pentesting Tools for Ephemeral Cloud Attacks

★ 210 Python May 13, 2026
Cybersecurity

AutoSploit: When Metasploit Meets Mass Automation (And Why That's Terrifying)

★ 5.2k Python May 13, 2026
Cybersecurity

gowitness: How Chrome Headless Became a Recon Powerhouse for Security Teams

★ 4.3k Go May 13, 2026
Cybersecurity

gnmapper: Converting Nmap's Greppable Output to CSV with 50 Lines of Bash

★ 4 Shell May 13, 2026
Cybersecurity

SubOver: How Go Concurrency Revolutionized Subdomain Takeover Detection

★ 966 Go May 13, 2026
Cybersecurity

Metta: Building an Adversarial Simulation Framework That Actually Tests Your Defenses

★ 1.1k Python May 13, 2026
Cybersecurity

Raven: A Cautionary Tale of LinkedIn Scraping and the Fragility of Reconnaissance Tools

★ 797 Go May 13, 2026
Cybersecurity

Findsploit: A Single-Command Gateway to Every Exploit Database on Your System

★ 1.8k Shell May 13, 2026
Cybersecurity

megplus: When Bash Wrappers Attack (A Cautionary Tale in Reconnaissance Automation)

★ 305 Shell May 13, 2026
Cybersecurity

GetAltName: Direct SSL Certificate Inspection for Subdomain Discovery Beyond Certificate Transparency

★ 390 Python May 13, 2026
Cybersecurity

TruffleHog: The Secret Scanner That Actually Verifies Your Leaked Credentials

★ 26.2k Go May 13, 2026
Cybersecurity

Inside Java Deserialization Attacks: A Security Cheat Sheet Worth 3,000+ Stars

★ 3.2k May 13, 2026
Cybersecurity

Weaponizing Apache's server-status: How Misconfigurations Leak Request Intelligence

★ 443 Python May 13, 2026
Cybersecurity

Building a GCP Security Auditing Framework: Lessons from Spotify's Deprecated Tool

★ 160 Python May 13, 2026
Cybersecurity

JexBoss: The Blunt Instrument for Testing Legacy JBoss Deserialization Flaws

★ 2.5k Python May 13, 2026
Cybersecurity

Inside CVE-2017-5638: Dissecting a Python Exploit for Apache Struts2's Most Devastating Vulnerability

★ 13 Python May 13, 2026
Cybersecurity

Snallygaster: The Single-File Security Scanner That Finds What Developers Leave Behind

★ 2.1k Python May 13, 2026
Cybersecurity

Exploiting .DS_Store Leaks: How ds_store_exp Turns macOS Metadata Into a Security Goldmine

★ 1.7k Python May 13, 2026
Cybersecurity

GitHack: Weaponizing Exposed .git Folders to Reconstruct Source Code

★ 3.5k Python May 13, 2026
Cybersecurity

Inside am0nsec/exploit: A Security Researcher's Personal Arsenal of Proof-of-Concept Exploits

★ 184 Python May 13, 2026