
Continuous SSL & Website Security Monitoring | QuietLS
监控 SSL 证书和网站安全,包含自动续期检测、安全头部监控和 DNS 健康检查。
@di_spivak · X
完整作品展
技术栈
60 projects

监控 SSL 证书和网站安全,包含自动续期检测、安全头部监控和 DNS 健康检查。
@di_spivak · X

免费的AI代码安全扫描器,扫描代码中的漏洞和凭证泄露。
kahlilashanti · HN
My tool scanned 256 AI-built apps and most had exposed credentials

监控和控制AI代理操作,设置权限边界和自动回滚。
samoladji · HN
Vaultak – Security for AI agents (built before the breaches started)

为网络设备自动备份配置并用E2EE端到端加密保护。
Willdom1986 · V2EX
多年前考过 CCNP 网络工程师,以前有一个很头疼的地方就是网络设备配置丢失引发的各种故障。后来越发觉得,网络设备的配置实际上是一个非常关键的数字资产。 为此,我利用周末时间开发了 XConf ( https://xconf.ai) 来解决这个问题。 产品主要就是想解决两个问题:**自动化的灾备高可用**,以及**端到端的安全**。 * **自动备份与灾备**:支持将配置定时备份到云端。如果网络断连了,探针会自动在本地离线队列里暂存配置,等连接恢复后自动重传。 * **端到端加密**:本地的 Go 探针是完全开源的,会自动在内存中对密码进行流式脱敏,并在上传前通过 AES-256-GCM 在本地加密。SaaS 后台拿到的只有密文,解密和版本比对( Diff )都完全在你的浏览器本地沙盒里通过 WebCrypto API 进行。 * **打磨版的配置对比 Diff**:我花了一些功夫打磨了浏览器端的配置版本对比功能,力求让日常比对的交互体验足够丝滑。 * **AI 安全基线审查**:系统集成了 AI 辅助的安全基线审查,可以一键检查和分析配置中的潜在风险。 因为目前完全是我利用业余时间(主要在周末)维护,所以确实没精力提供工作日的在线即时客服。大家使用过程中遇到任何 Bug ,欢迎随时去 GitHub 提 Issue ,我会在周末集中修复和跟进。 目前公测已开放,不需要邀请码即可注册,欢迎大家体验吐槽。 探针 agent 开源地址: https://github.com/willdom-lee/xconf-agent 官方网站: https://xconf.ai

Play Grok Tower Defense (GTD) free at groktowerdefense.com. Deploy SpaceXAI towers—Grok Sentinel, Falcon Battery, Starlink Array, Starship Mortar—across 8 unique maps with 50 waves
@davidtsolheim · X
Here’s mine I built with grok

SecureEnv - 零知识加密的团队密钥存储和共享工具
@kkworld · X
Introducing SecureEnv. A secure, developer-first platform for managing environment variables and secrets. Simple. Secure. Built for developers. 🌐 #SecureEnv #BuildInPublic #Programming

10级提示词注入谜题,尝试操纵AI代理的行为。
Getchowned · HN
The AI Lethal Trifecta

用对抗测试检查LLM端点安全,获取OWASP审计报告。
@aryaan_sheth · X
- LLM security for small teams

SecNav为安全专业人士提供对抗模拟环境来验证法医和战术安全能力。
@SecNavPro · X
Hey, SecNav is the simulation-first skill verification platform for cybersecurity, physical security, and GRC. We replace self-assessed resumes with KMS-signed proof of practical skill. 🛡️

使用硬件认证和OTP保护GitHub拉取请求。
jallmann · HN
> want without a PR process that requires hardware authentication or proof of presence Just curious, what do you use for this? I built OTP Guard [1] a few years ago for exactly this problem, although I haven't seen any alternatives in the space. Does GitHub have something built-in now? The original framing was more "local malware compromising your GitHub account" ... it never occurred to me that the malware could be a LLM. I really should update the page. [1] https://otpguard.com

检测 AI 构建应用的安全问题:暴露的表格、泄露的密钥和客户端身份验证。
@Sentrint · X
Made Sentrint after seeing how many vibe-coded apps ship with RLS switched off. Point it at a GitHub repo and it finds open user tables, exposed keys and auth checks that only run in the browser. Free scan is the whole scan, no card.
