> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Raven: A Cautionary Tale of LinkedIn Scraping and the Fragility of Reconnaissance Tools

★ 797 Go May 13, 2026
Cybersecurity

Findsploit: A Single-Command Gateway to Every Exploit Database on Your System

★ 1.8k Shell May 13, 2026
Cybersecurity

megplus: When Bash Wrappers Attack (A Cautionary Tale in Reconnaissance Automation)

★ 305 Shell May 13, 2026
Cybersecurity

GetAltName: Direct SSL Certificate Inspection for Subdomain Discovery Beyond Certificate Transparency

★ 390 Python May 13, 2026
Cybersecurity

TruffleHog: The Secret Scanner That Actually Verifies Your Leaked Credentials

★ 26.2k Go May 13, 2026
Cybersecurity

Inside Java Deserialization Attacks: A Security Cheat Sheet Worth 3,000+ Stars

★ 3.2k May 13, 2026
Cybersecurity

Weaponizing Apache's server-status: How Misconfigurations Leak Request Intelligence

★ 443 Python May 13, 2026
Cybersecurity

Building a GCP Security Auditing Framework: Lessons from Spotify's Deprecated Tool

★ 160 Python May 13, 2026
Cybersecurity

JexBoss: The Blunt Instrument for Testing Legacy JBoss Deserialization Flaws

★ 2.5k Python May 13, 2026
Cybersecurity

Inside CVE-2017-5638: Dissecting a Python Exploit for Apache Struts2's Most Devastating Vulnerability

★ 13 Python May 13, 2026
Cybersecurity

Snallygaster: The Single-File Security Scanner That Finds What Developers Leave Behind

★ 2.1k Python May 13, 2026
Cybersecurity

Exploiting .DS_Store Leaks: How ds_store_exp Turns macOS Metadata Into a Security Goldmine

★ 1.7k Python May 13, 2026
Cybersecurity

GitHack: Weaponizing Exposed .git Folders to Reconstruct Source Code

★ 3.5k Python May 13, 2026
Cybersecurity

Inside am0nsec/exploit: A Security Researcher's Personal Arsenal of Proof-of-Concept Exploits

★ 184 Python May 13, 2026
Cybersecurity

foospidy/payloads: The 13GB Security Payload Archive Every Pentester Should Know About

★ 3.9k Shell May 13, 2026
Cybersecurity

Statistically Likely Usernames: Why Horizontal Password Attacks Beat Vertical Every Time

★ 1.3k Python May 13, 2026
Cybersecurity

PwnGitManager: Surgical Git Repository Extraction for Security Researchers

★ 109 Python May 13, 2026
Cybersecurity

Inside can-i-take-over-xyz: The Crowdsourced Database Securing Subdomain Hygiene

★ 5.7k Python May 13, 2026
Cybersecurity

Red-Teaming-Toolkit: A MITRE ATT&CK-Mapped Arsenal for Offensive Security Operations

★ 10.3k May 13, 2026
Cybersecurity

Curate: Mining VirusTotal's URL Archive for Bug Bounty Reconnaissance

★ 41 Shell May 13, 2026
Cybersecurity

EdOverflow/hacks: The Art of Disposable Security Scripts in /usr/local/bin

★ 100 Shell May 13, 2026
Cybersecurity

LFISuite: Anatomy of an Automated Local File Inclusion Exploitation Framework

★ 1.9k Python May 13, 2026
Cybersecurity

Drupalgeddon2: Dissecting the RCE Exploit That Threatened Millions of CMS Installations

★ 597 Ruby May 13, 2026
Cybersecurity

Cr3dOv3r: Reverse-Engineering a Credential Reuse Attack Framework

★ 2.1k Python May 13, 2026