> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

372 articles

Cybersecurity

Interlace: The Thread Pool Hack That Parallelizes Your Single-Threaded Security Tools

★ 1.3k Python May 13, 2026
Cybersecurity

Reconnoitre: The Reconnaissance Automation Tool That Teaches You Not To Need It

★ 2.2k Python May 13, 2026
Cybersecurity

How Selenium Grid Becomes an SSRF Gateway to Cloud Credentials

★ 7 Python May 13, 2026
Cybersecurity

How a Groovy Annotation Bypassed Jenkins' Security Sandbox: Dissecting CVE-2019-1003000

★ 317 JavaScript May 13, 2026
Cybersecurity

Building Network Scanners in Go: How Ullaakut/nmap Wraps a 25-Year-Old Binary

★ 1.0k Go May 13, 2026
Cybersecurity

KeyHacks: The Bug Bounty Hunter's Cookbook for Validating Leaked API Credentials

★ 6.2k May 13, 2026
Cybersecurity

Inside BlueKeep: Dissecting CVE-2019-0708's RDP Exploit Architecture

★ 113 Python May 13, 2026
Cybersecurity

K8tools: Inside China's Most Popular Offensive Security Arsenal

★ 6.2k PowerShell May 13, 2026
Cybersecurity

ffuf: How Go's Concurrency Model Makes It the Fastest Web Fuzzer for Security Testing

★ 16.0k Go May 13, 2026
Cybersecurity

GourdScanV2: Building a Passive Vulnerability Scanner with Redis-Backed Traffic Interception

★ 868 Python May 13, 2026
Cybersecurity

Sliver: The Open-Source C2 Framework That Generates Cryptographically Unique Implants

★ 11.2k Go May 13, 2026
Cybersecurity

Building a Reverse Proxy to Patch AWS's Metadata Security Hole (Before IMDSv2 Fixed It)

★ 31 Go May 13, 2026
Cybersecurity

Inside pwn-pulse: A Surgical Shell Script for Pulse Secure VPN Exploitation

★ 135 Shell May 13, 2026
Cybersecurity

shhgit: Real-Time Secrets Detection Through Repository Stream Surveillance

★ 4.0k JavaScript May 13, 2026
Cybersecurity

DNSGen: Cloud-Aware Subdomain Permutation for Modern Infrastructure Reconnaissance

★ 1.1k Python May 13, 2026
Cybersecurity

Inside the Most Comprehensive AWS Security Tool Arsenal: A Curated Intelligence Repository

★ 9.4k Shell May 13, 2026
Cybersecurity

Faraday: The Open-Source Vulnerability Aggregator That Parses 80+ Security Tools

★ 6.5k Python May 13, 2026
Cybersecurity

Eyeballer: Training Neural Networks to Triage Thousands of Pentest Screenshots

★ 1.3k Python May 13, 2026
Cybersecurity

Credcheck: A Modular Framework for Validating Stolen Credentials in Security Testing

★ 53 Python May 13, 2026
Cybersecurity

Scraping GitHub Trending: How go-trending Fills the Gap in GitHub's API

★ 147 Go May 13, 2026
Cybersecurity

GadgetProbe: Mapping Remote Java Classpaths Through Deserialization Side Channels

★ 615 Java May 13, 2026
Cybersecurity

WeirdAAL: The AWS Attack Library That Shows You What Compromised Credentials Can Really Do

★ 842 Python May 13, 2026
Cybersecurity

Dufflebag: How Bishop Fox Built a Distributed Secret Scanner for Public AWS Snapshots

★ 304 Go May 13, 2026
Cybersecurity

Sudomy: When Bash Orchestration Beats Microservices for Bug Bounty Recon

★ 2.4k Shell May 13, 2026