frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: DefendFlow Radar – An attacker-view recon engine for domains

1•riyao_lin•10m ago
Hi HN,

I’ve been working on a security tool called DefendFlow Radar, and I’d love to get feedback from the community.

The idea behind it is simple: What does your domain look like from the attacker’s point of view? A surprising amount of security exposure comes from misconfigured DNS, forgotten services, exposed subdomains, expired DMARC, and stale SaaS entries. We built tools to detect these issues quickly and automatically.

What Radar does • Enumerates domains/subdomains using multiple recon techniques • Checks DNS hygiene, DMARC/SPF/DKIM correctness • Identifies stale/exposed endpoints and unintended public surfaces • Maps attack surface across services & SaaS providers • Generates a digestible “risk snapshot” of the domain

Here you can give it a free trial: https://radar.defendflow.xyz/

Why we built it

My co-founder is a penetration tester, and we found ourselves repeatedly running 15–20 different tools to get a clear picture of an organization’s external footprint. We wanted something that: 1. Gives a single attacker-view perspective 2. Is fast enough to use during initial recon 3. Doesn’t require installing a big agent or pipeline 4. Shows useful misconfigurations non-security engineers can understand

So we built this as a side project. Over time it evolved into a more complete recon engine.

How it works (technical highlights) • Uses layered probing (DNS, HTTP metadata, MX checks, SSL, cloud service inference) • Performs domain validation • Incorporates passive and active signal collection • Surface mapping logic written mostly in Rust • No agent, crawler, or network access needed from the user side • Outputs everything as structured JSON behind the scenes

Happy to answer any questions about how it works internally.

Looking for feedback

I’m especially interested in feedback from: • security engineers • SRE/DevOps folks • people who maintain DNS/SPF/DMARC at work • anyone who’s had to clean up legacy SaaS footprint

If something is unclear or missing, I’d really appreciate the critique.

Thanks for taking a look!

Try out link again: https://radar.defendflow.xyz/

Comments

riyao_lin•9m ago
Author here: adding a bit more context. The scanning code is mostly written in Rust, and I’m slowly breaking pieces of it out so they can be used as standalone CLI utilities. If there’s interest, I can open-source some of the passive/active DNS probing modules.

Also happy to scan any domains you want to test — just share them (or DM if preferred).

Appreciate all feedback, including criticism.

Show HN: Logical (YC F25): a local-first proactive desktop AI copilot

https://trylogical.ai
1•samkaru•2m ago•0 comments

Generating Cloudflare Origin Certificate for Multiple Domains

https://www.albertyw.com/note/cloudflare-origin-multi-domain
1•speckx•3m ago•0 comments

Telescope in Chile captures new picture of a cosmic butterfly

https://apnews.com/article/butterfly-nebula-telescope-space-2810ed49f9f4ee3c9a9ab58e878b5b7c
1•us-merul•5m ago•0 comments

Show HN: Number Pyle – A simple number game to pass the time

https://jennabarbara.github.io/number-pyle/
1•JenBarb•6m ago•0 comments

State of Brain Emulation Report (2025)

https://arxiv.org/abs/2510.15745
1•Gooblebrai•8m ago•0 comments

Rudolf Steiner: The Last of the German Romantics

https://romanticon.substack.com/p/rudolf-steiner-the-last-of-the-german
1•paulpauper•10m ago•0 comments

The AI invasion of knitting and crochet?

https://www.plagiarismtoday.com/2025/11/24/the-ai-invasion-of-knitting-and-crochet/
1•paulpauper•10m ago•0 comments

Show HN: DefendFlow Radar – An attacker-view recon engine for domains

1•riyao_lin•10m ago•1 comments

Nouriel Roubini is optimistic about the economy

https://www.ft.com/content/3af620bb-6d5e-4281-879d-c3193e225803
1•paulpauper•10m ago•0 comments

They relied on marijuana to get through the day. But then days felt impossible

https://apnews.com/article/cannabis-disorder-marijuana-addiction-682ab2ff68586167448e2856fa2e5d09
1•nradov•10m ago•0 comments

The most male and female reasons to end up hospital

https://leobenedictus.substack.com/p/the-most-male-and-female-reasons
2•speckx•11m ago•0 comments

Show HN: A form generator that starts with "talk", not "drag and drop"

https://voice2form.progressguide.com/
1•kkxingh•12m ago•0 comments

Vague, but Exciting

https://thehistoryoftheweb.com/book/
1•ibobev•12m ago•0 comments

Time in C++: std:chrono:system_clock

https://www.sandordargo.com/blog/2025/11/26/clocks-part-2-system_clock
1•ibobev•13m ago•0 comments

Timbaland: Let's Talk about AI

https://www.instagram.com/p/DRhrbAukbk5/
1•nialse•14m ago•0 comments

S&box is now an open source game engine

https://sbox.game/news/update-25-11-26
2•MaximilianEmel•15m ago•0 comments

I built a 120-model mental models framework using the framework itself

https://github.com/hummbl-dev/mcp-server/blob/main/docs/case-study-01-framework-development.md
1•hummbl-dev•15m ago•1 comments

Show HN: Building WiFi MIDI Controller with ESP32, Elixir, and AtomVM

https://github.com/nanassound/midimesh_esp32
1•bepitulaz•15m ago•0 comments

F*ck Wispr Flow – Open-sourcing Jarvis: private, local, free

https://github.com/akshayaggarwal99/jarvis-ai-assistant
3•imaka•17m ago•1 comments

Delegated Coding Has a Bright Future

https://blog.jenkster.com/2025/06/delegated_coding/
1•saikatsg•18m ago•0 comments

Poland picks Sweden's Saab to supply it with three submarines (A26 Blekinge)

https://www.reuters.com/business/aerospace-defense/poland-chooses-sweden-supply-it-with-three-sub...
2•lysace•19m ago•1 comments

Don't Download Apps

https://blog.calebjay.com/posts/dont-download-apps/
2•speckx•21m ago•0 comments

Warner does a deal with Suno, Udio; what could possibly go wrong?

https://cdm.link/warner-does-a-deal-with-suno-udio/
2•glitcher•21m ago•0 comments

Why so many projects in the Neon free plan?

https://neon.com/blog/why-so-many-projects-in-the-neon-free-plan
1•bvanvugt•22m ago•0 comments

André and Simone Weil: Mathematics, social activism and Indian culture

https://arxiv.org/abs/2511.20063
1•bikenaga•23m ago•0 comments

Genetic study links impatience to broad mental and physical health risks

https://www.nature.com/articles/s41380-025-03356-8
2•domofutu•24m ago•0 comments

Plotnine: A Grammar of Graphics for Python

https://plotnine.org
2•nothrowaways•24m ago•0 comments

LLM Inference Beyond a Single Node: From Bottlenecks to Mitigations

https://arxiv.org/abs/2511.09557
1•matt_d•25m ago•0 comments

Enhanced Games to offer performance enhancers and stock to the public

https://apnews.com/article/enhanced-doping-olympics-drug-testing-342e417b316dbf22ef17a2b3e9a5694c
1•geox•25m ago•0 comments

Show HN: Database-replicator – Replicate any DB to PostgreSQL

https://github.com/serenorg/database-replicator
1•taariqserendb•31m ago•0 comments