> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗

All articles

Cybersecurity

Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.

358 articles

Cybersecurity

gau: Mining Web Archives for Security Reconnaissance Without Touching the Target

★ 4.9k Go May 12, 2026
Cybersecurity

OneForAll: The Subdomain Enumeration Framework That Aggregates 100+ Data Sources

★ 9.8k Python May 12, 2026
Cybersecurity

httpx: The Swiss Army Knife of HTTP Reconnaissance That Actually Scales

★ 9.9k Go May 12, 2026
Cybersecurity

GitHub as an Attack Surface: Automating Reconnaissance with github-search

★ 1.5k Python May 12, 2026
Cybersecurity

o365spray: How Endpoint Diversity Beats Microsoft's Authentication Rate Limiting

★ 1.0k Python May 12, 2026
Cybersecurity

Xray: China's Most Popular Closed-Source Vulnerability Scanner

★ 11.6k Vue May 12, 2026
Cybersecurity

Building a Custom HTTP Fingerprinting Engine with GoFingerprint

★ 209 Go May 12, 2026
Cybersecurity

Inside the Vault: What 9,500 Stars Worth of Real Penetration Testing Reports Teach Us About Security

★ 9.5k HTML May 12, 2026
Cybersecurity

The GitHub Exploit Aggregator That Security Teams Don't Talk About Publicly

★ 7.7k May 12, 2026
Cybersecurity

Inside Azure/Azure-Network-Security: Microsoft's Hidden Automation Arsenal for Cloud Perimeter Defense

★ 925 Python May 12, 2026
Cybersecurity

Spring Boot Actuator Exploitation: A Security Researcher's Arsenal

★ 424 May 12, 2026
Cybersecurity

PowerZure: When Your Azure Credentials Become Someone Else's Attack Surface

★ 1.3k PowerShell May 12, 2026
Cybersecurity

The macOS Security Arsenal: A Critical Review of kai5263499/osx-security-awesome

★ 775 May 12, 2026
Cybersecurity

VulnX: The Aggressive CMS Scanner That Automates What Penetration Testers Do Manually

★ 2.1k Python May 12, 2026
Cybersecurity

badPods: The Kubernetes Security Testing Toolkit That Maps Every Pod Privilege Escalation Path

★ 698 Shell May 12, 2026
Cybersecurity

BruteShark: Automating Credential Extraction from Network Captures with .NET Core

★ 3.4k C# May 12, 2026
Cybersecurity

KingOfBugBountyTips: A Weaponized Command Reference for Security Reconnaissance

★ 5.3k Python May 12, 2026
Cybersecurity

h2cSmuggler: Exploiting HTTP/2 Cleartext Upgrades to Bypass Reverse Proxies

★ 793 Python May 12, 2026
Cybersecurity

Bento Toolkit: Running GUI Pentesting Tools in Fedora Containers with X11 Forwarding

★ 76 Dockerfile May 12, 2026
Cybersecurity

Cloudlist: Multi-Cloud Asset Discovery for Attack Surface Management

★ 1.0k Go May 12, 2026
Cybersecurity

Axiom: Distributing Security Scans Across Hundreds of Cloud Instances With Shell Scripts

★ 4.4k Shell May 12, 2026
Cybersecurity

Crossfeed: How CISA Built a Serverless Attack Surface Monitor on AWS

★ 422 TypeScript May 12, 2026
Cybersecurity

Arsenal: A Command Injection Framework for Pentesting (That Literally Injects Your Shell)

★ 3.7k Python May 12, 2026
Cybersecurity

Intrigue-ident: Multi-Protocol Fingerprinting with Built-in CVE Mapping

★ 134 Ruby May 12, 2026