> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Smith: The Bug Bounty Wrapper That Makes Meg Actually Useful

★ 59 Shell May 13, 2026
Cybersecurity

AWSBucketDump: Weaponizing S3 Misconfigurations With Wordlists and Grep

★ 1.5k Python May 13, 2026
Cybersecurity

CloudGoat: Learning Cloud Penetration Testing by Breaking Things on Purpose

★ 3.6k Python May 13, 2026
Cybersecurity

WhatWeb: Ruby-Powered Web Fingerprinting with 1800+ Plugins for Security Reconnaissance

★ 6.6k Ruby May 13, 2026
Cybersecurity

RecurseBuster: Why HEAD-First Requests Make Recursive Content Discovery Faster

★ 250 Go May 13, 2026
Cybersecurity

Mining Bug Bounty Scopes at Scale: Inside bounty-targets-data's Automated Intelligence Pipeline

★ 3.7k May 13, 2026
Cybersecurity

Sn1per: The Shell-Script Orchestrator That Weaponized 90+ Security Tools

★ 9.8k Shell May 13, 2026
Cybersecurity

Learning Go for Security Work: A Deep Dive into parsiya/Hacking-with-Go

★ 1.8k Go May 13, 2026
Cybersecurity

SpiderFoot: How 200+ OSINT Modules Communicate in a Publisher/Subscriber Pipeline

★ 17.7k Python May 13, 2026
Cybersecurity

Inside gwen001's pentest-tools: A Bug Bounty Hunter's Arsenal of Single-Purpose Security Scripts

★ 3.3k Python May 13, 2026
Cybersecurity

Gurp: Automating Burp Suite Professional from the Command Line with Go

★ 56 Go May 13, 2026
Cybersecurity

ORTBOT: A Red Teamer's Command Reference That Fits in Your Terminal

★ 97 May 13, 2026
Cybersecurity

Running Burp Suite in CI/CD: How Headless-Burp Brings DAST to Your Build Pipeline

★ 234 Java May 13, 2026
Cybersecurity

Automating Burp Suite Pro at Scale: How Carbonator Turns Manual Scans into CI/CD Pipelines

★ 74 Python May 13, 2026
Cybersecurity

Transfer.sh: Building a Command-Line File Sharing Service That Scales to Multiple Cloud Backends

★ 15.8k Go May 13, 2026
Cybersecurity

Loubia: Weaponizing WebLogic's T3 Protocol Through Java Deserialization

★ 60 Python May 13, 2026
Cybersecurity

Changeme: How Default Credentials Are Hiding in Plain Sight Across Your Infrastructure

★ 1.5k Python May 13, 2026
Cybersecurity

Inside lcashdol/Exploits: A Shell-First Approach to CVE Proof-of-Concepts

★ 212 Shell May 13, 2026
Cybersecurity

WPSploit: Metasploit's Unofficial WordPress Arsenal

★ 232 Ruby May 13, 2026
Cybersecurity

Vulhub: The Docker-Compose Library That Makes CVE Reproduction Deterministic

★ 20.7k Dockerfile May 13, 2026
Cybersecurity

Building a Private Cloud Proxy Botnet: Inside ProxyCannon-NG's Architecture

★ 640 Shell May 13, 2026
Cybersecurity

AD-Attack-Defense: The MITRE ATT&CK Navigation System for Active Directory Security

★ 4.8k May 13, 2026
Cybersecurity

kube-hunter: The Deprecated Kubernetes Penetration Tool That Still Teaches Security

★ 5.0k Python May 13, 2026
Cybersecurity

Security Best Practices for Developers: Lessons from Sqreen's Open-Source Guide

★ 77 CSS May 13, 2026