|
LR-Agent Counterfactual patches, causal evidence, repository aging. |
NightWatch Sequence correlation, beaconing, DNS signals, evidence-backed alerts. |
LR-SOC-Copilot Entity correlation, local runbooks, source-line citations. |
LR-Tablet Tablet-first reading practice, local progress, reproducible APK builds. |
⏳ LR-AgentWhat if a patch passes today but breaks after the repository evolves? A local coding-agent research lab for counterfactual patches, evidence-driven strategy validation and multi-generation repository aging. |
See what a detection threshold really costs. A reproducible blue-team experiment for beacon detection: labeled synthetic traffic, threshold sweeps, confusion matrices and per-flow evidence. |
最近主要在做两个问题:Agent 的长期可靠性,以及 Detection Engineering 里阈值、证据和误报之间的关系。
这里不只展示“做了什么”,也记录每个项目有没有 测试、固定评估集、CI Artifact、完整性/溯源信息,以及明确的限制条件。
→ Open the engineering health matrix · Project standards
| Track | Repositories | Focus |
|---|---|---|
| AI Agent | LR-Agent | counterfactual patches · evidence · long-horizon reliability |
| Detection | NightWatch · Threshold Lab | event correlation · beaconing · thresholds · evidence |
| Security × AI | SOC Copilot · Detector Resilience · PayloadLab | investigation · drift · telemetry validation |
| Tools | Android CI Doctor · CTF Tracebook | build diagnosis · reproducible notes |
| Android / Learning | LR-Tablet | local-first learning workflow |
平时主要折腾网络安全、AI Agent、Android 和各种自己真正会用到的小工具。
我喜欢把一个想法从“能跑”继续做到“能测、能复现、能解释为什么这样设计”。这里放着一些安全实验、Agent 原型、学习工具和日常工程项目,也会记录踩坑、重构和偶尔冒出来的新点子。
最近比较感兴趣的是 检测工程、Agent 可靠性、自动化和本地优先的软件体验。
| 项目 | 简介 | 入口 |
|---|---|---|
| NightWatch | 本地安全事件关联与检测实验:登录序列、端口扇出、周期外联、DNS 异常与证据输出 | README |
| LR-agent | 可操作工作区的 Agent 实验台:任务执行、工具调用、验证、策略对比与隔离工作区 | README |
| LR-Tablet | 面向横屏平板的阅读训练器:双栏阅读、导入、作答、批注与本地记录 | README |
| LR Lab | Android、本地工具、安全实验和一些奇怪想法的集合 | 项目索引 |
| 项目 | 在做什么 |
|---|---|
| LR-PayloadLab | 受限、可审计的端点遥测实验:行为声明、策略边界、回执与清理 |
| Detector Resilience Lab | 在不可执行数值特征上研究检测模型面对分布漂移时的退化、翻转样本与特征变化 |
| LR-SOC-Copilot | 按实体和时间关联告警,检索本地 Runbook,并为调查摘要保留源行证据 |
这几个项目互相有一点联系:从产生可观察行为,到检测、关联,再到分析检测为什么会失效。
| 工具 | 用途 |
|---|---|
| Android CI Doctor | 从 Gradle / Android CI 日志里快速找构建、签名、JDK、SDK 和产物问题 |
| CTF Tracebook | 把 CTF 终端记录整理成更容易回看的复盘草稿 |
| Detection Threshold Lab | 对检测阈值做可复现实验,观察误报和漏报的变化 |
- Security detection & telemetry
- Security telemetry & detection experiments
- AI Agent reliability
- Android / local-first tools
- Automation & reproducible experiments
⌁ Quick start
NightWatch:
git clone https://github.com/LLR6/Cybersecurity-Detection-Engineering-Android-Automation-Learning-by-Building.git
cd Cybersecurity-Detection-Engineering-Android-Automation-Learning-by-Building
python -m venv .venv
pip install -e ".[dev]"
pytest -q
nightwatch samples/demo.jsonl --format md --out report.mdLR-Tablet:
git clone https://github.com/LLR6/LR-Tablet.git
cd LR-Tablet
npm install
npm run devLR-agent 的模型配置、Docker 和测试命令见项目 README。
Detection Engineering Agent Reliability Adversary Emulation Android Automation
有想法就做,有问题就拆,能复现的东西才比较有意思。
— keep building things I want to use. —
