Skip to content
View LLR6's full-sized avatar

Block or report LLR6

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
LLR6/README.md
日系动漫女孩与蓝色雪夜咖啡店

◈ LR / LLR6

把好奇心写进代码,把工程结果留给复现。

Security · AI Agent · Android · Automation

NightWatch LR Agent LR Tablet

◉ SYSTEM ONLINE | build · break · learn · repeat


⌁ Now Building

⏳ Agent Reliability

LR-Agent

Counterfactual patches, causal evidence, repository aging.

Open →

📡 Detection

NightWatch

Sequence correlation, beaconing, DNS signals, evidence-backed alerts.

Open →

🧭 SOC / IR

LR-SOC-Copilot

Entity correlation, local runbooks, source-line citations.

Open →

📱 Android

LR-Tablet

Tablet-first reading practice, local progress, reproducible APK builds.

Open →

LR-Agent last commit NightWatch last commit SOC Copilot last commit LR-Tablet last commit

✦ Featured

What if a patch passes today but breaks after the repository evolves?

A local coding-agent research lab for counterfactual patches, evidence-driven strategy validation and multi-generation repository aging.

Stars CI

→ See the demo

See what a detection threshold really costs.

A reproducible blue-team experiment for beacon detection: labeled synthetic traffic, threshold sweeps, confusion matrices and per-flow evidence.

Stars Test

→ Run the 1-minute demo

最近主要在做两个问题:Agent 的长期可靠性,以及 Detection Engineering 里阈值、证据和误报之间的关系。

◫ Engineering Health

Engineering health

这里不只展示“做了什么”,也记录每个项目有没有 测试、固定评估集、CI Artifact、完整性/溯源信息,以及明确的限制条件。

→ Open the engineering health matrix · Project standards

◇ Project Constellation

LR Lab project constellation

LR-Agent NightWatch SOC Copilot LR Tablet

Track Repositories Focus
AI Agent LR-Agent counterfactual patches · evidence · long-horizon reliability
Detection NightWatch · Threshold Lab event correlation · beaconing · thresholds · evidence
Security × AI SOC Copilot · Detector Resilience · PayloadLab investigation · drift · telemetry validation
Tools Android CI Doctor · CTF Tracebook build diagnosis · reproducible notes
Android / Learning LR-Tablet local-first learning workflow

LR-Agent stars NightWatch stars Detection Lab stars

你好,我是 LR 👋

平时主要折腾网络安全、AI Agent、Android 和各种自己真正会用到的小工具。

我喜欢把一个想法从“能跑”继续做到“能测、能复现、能解释为什么这样设计”。这里放着一些安全实验、Agent 原型、学习工具和日常工程项目,也会记录踩坑、重构和偶尔冒出来的新点子。

最近比较感兴趣的是 检测工程、Agent 可靠性、自动化和本地优先的软件体验。

🛰️ Projects

项目 简介 入口
NightWatch 本地安全事件关联与检测实验:登录序列、端口扇出、周期外联、DNS 异常与证据输出 README
LR-agent 可操作工作区的 Agent 实验台:任务执行、工具调用、验证、策略对比与隔离工作区 README
LR-Tablet 面向横屏平板的阅读训练器:双栏阅读、导入、作答、批注与本地记录 README
LR Lab Android、本地工具、安全实验和一些奇怪想法的集合 项目索引

🛡️ Security × AI

项目 在做什么
LR-PayloadLab 受限、可审计的端点遥测实验:行为声明、策略边界、回执与清理
Detector Resilience Lab 在不可执行数值特征上研究检测模型面对分布漂移时的退化、翻转样本与特征变化
LR-SOC-Copilot 按实体和时间关联告警,检索本地 Runbook,并为调查摘要保留源行证据

这几个项目互相有一点联系:从产生可观察行为,到检测、关联,再到分析检测为什么会失效。

🧰 Small Tools

工具 用途
Android CI Doctor 从 Gradle / Android CI 日志里快速找构建、签名、JDK、SDK 和产物问题
CTF Tracebook 把 CTF 终端记录整理成更容易回看的复盘草稿
Detection Threshold Lab 对检测阈值做可复现实验,观察误报和漏报的变化

🔬 What I'm exploring

  • Security detection & telemetry
  • Security telemetry & detection experiments
  • AI Agent reliability
  • Android / local-first tools
  • Automation & reproducible experiments
⌁ Quick start

NightWatch:

git clone https://github.com/LLR6/Cybersecurity-Detection-Engineering-Android-Automation-Learning-by-Building.git
cd Cybersecurity-Detection-Engineering-Android-Automation-Learning-by-Building
python -m venv .venv
pip install -e ".[dev]"
pytest -q
nightwatch samples/demo.jsonl --format md --out report.md

LR-Tablet:

git clone https://github.com/LLR6/LR-Tablet.git
cd LR-Tablet
npm install
npm run dev

LR-agent 的模型配置、Docker 和测试命令见项目 README。

🌙 Now

Detection Engineering Agent Reliability Adversary Emulation Android Automation

有想法就做,有问题就拆,能复现的东西才比较有意思。

— keep building things I want to use. —

Pinned Loading

  1. Cybersecurity-Detection-Engineering-Android-Automation-Learning-by-Building Cybersecurity-Detection-Engineering-Android-Automation-Learning-by-Building Public

    Cybersecurity · Detection Engineering · Android · Automation · Learning by Building

    Python

  2. LR-agent LR-agent Public

    可验证的本地 AI Agent 实验台:隔离候选、工具执行、策略消融与未来演化压力测试。

    Python

  3. LR-Tablet LR-Tablet Public

    面向 Android 平板的本地优先英语阅读训练器:双栏阅读、批注、作答、统计与 APK 构建。

    JavaScript

  4. LR-Detector-Resilience-Lab LR-Detector-Resilience-Lab Public

    Safe feature-space experiments for measuring defensive model robustness under adversarial drift.

    Python

  5. LR-PayloadLab LR-PayloadLab Public

    Bounded, auditable benign payloads for endpoint telemetry, detection validation and reproducible security research.

    Python

  6. LR-SOC-Copilot LR-SOC-Copilot Public

    Evidence-grounded alert correlation and local runbook retrieval for practical SOC investigations.

    Python