frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: An open-source, air-gapped threat detector for Active Directory

https://github.com/Saeros-Security/Saeros
1•saeros•1h ago
Hey,

I built Saeros because I was frustrated with the current state of Active Directory security in secure/air-gapped environments.

As of today, solutions that detect live threats such as DCSync, Golden Tickets, or Kerberoasting require heavy agents that pipe gigabytes of logs to the cloud (Splunk, CrowdStrike, SentinelOne) or sync your AD to Azure (Defender for Identity). Other alternatives such as OSSEC, Wazuh or Elastic require heavy setup and are very time consuming. Chainsaw and Hayabusa do not support live detections.

For critical infrastructure or disconnected networks, that isn't an option.

What it does: Saeros is a single-binary agent written in C# that runs on domain controllers. It subscribes to Event Tracing for Windows (ETW), matches them against Sigma rules in real-time, and outputs alerts locally through a powerful console.

Key Takeaways:

- User-Mode Only: This does NOT use kernel drivers. It cannot BSOD your domain controller. - Performance Critical: The agent consumes minimal resources while handling tens of thousands events per second. - Read-Only: It does not attempt to block or terminate processes. - Air-Gap Native: It requires zero internet connection.

The code source is located here: https://github.com/Saeros-Security/Saeros. I released this under the AGPL-3.0 license so security teams can audit the code and verify that it only listens and never talks to the outside world.

I’m looking for your feedbacks.

Thanks!

Electron vs. Tauri

https://www.dolthub.com/blog/2025-11-13-electron-vs-tauri/
1•todsacerdoti•1m ago•0 comments

LaSuite Keynote

https://www.youtube.com/watch?v=X6c-mYOWrvA
1•maelito•2m ago•0 comments

Study: First Visualization of the Internal Structure Behind AI Decision-Making

https://news.kaist.ac.kr/site/newsen/html/news/?mode=V&mng_no=55090&skey=&sval=&list_s_date=&list...
1•giuliomagnifico•5m ago•0 comments

Desperately Seeking Squircles (2018)

https://www.figma.com/blog/desperately-seeking-squircles/
1•williamjsdavis•5m ago•0 comments

iOS games that work on iPads that can not be upgraded past iOS 9

https://cjstewart88.github.io/vintage/
2•walterbell•6m ago•0 comments

All your LLMs ranked by speed every minute

https://metrik-dashboard.vercel.app/
1•mbouassa•7m ago•0 comments

Firm pioneers 3D printing copper coolers directly onto processors

https://www.tomshardware.com/3d-printing/firm-pioneers-3d-printing-copper-coolers-directly-onto-p...
1•Teever•8m ago•0 comments

Join the Parasite Rebellion on T-day

https://usop.substack.com/
1•richardatlarge•9m ago•0 comments

Ask HN: Why do people say LLMs create bad code "quality"?

2•chaidhat•11m ago•1 comments

Comparing Obelisk with DBOS

https://obeli.sk/blog/comparing-dbos-part-1/
1•todsacerdoti•13m ago•0 comments

The Context Tax: Why AI-Assisted Coding Fails Without Flow

https://arif.sh/book
1•Arifcodes•15m ago•0 comments

Training Foundation Models on a Full-Stack AMD Platform

https://arxiv.org/abs/2511.17127
2•srameshc•16m ago•0 comments

Age of "Don't do it yourself"

https://blog.rybarix.com/2025/11/26/age-of-dont-diy.html
4•sandruso•20m ago•1 comments

Anomalous electronic state opens pathway to room-temperature superconductivity

https://phys.org/news/2025-11-anomalous-electronic-state-pathway-room.html
1•rbanffy•20m ago•0 comments

Reminder that HN Active exists and is arguably better

https://news.ycombinator.com/active
5•loteck•21m ago•1 comments

What's Hiding Inside Haribo's Power Bank and Headphones?

https://www.lumafield.com/first-article/posts/whats-hiding-inside-haribos-power-bank-and-headphones
1•rozenmd•21m ago•0 comments

Show HN: MXP – A2A-compatible agent protocol, 37x faster than JSON

1•ferasawady•22m ago•0 comments

China completes first emergency mission to Tiangong space station

https://www.reuters.com/business/media-telecom/china-launch-shenzhou-22-spaceship-0411-gmt-state-...
3•Teever•23m ago•1 comments

France to bring in form of military service

https://www.bbc.co.uk/news/articles/c0edw7g7z79o
1•AIBytes•25m ago•0 comments

Z-Image, free online image generator

https://zimage.net
2•BruceWok•27m ago•0 comments

Cooldown Myths for Runners

https://therundownbytherunningeffect.substack.com/p/cooldowns-are-overrated
1•RalphHavensPT•29m ago•1 comments

Google says hackers stole data from 200 companies following Gainsight breach

https://techcrunch.com/2025/11/21/google-says-hackers-stole-data-from-200-companies-following-gai...
1•SilverElfin•29m ago•1 comments

Blender facial animation tool. What else should it do?

https://github.com/shun126/livelinkface_arkit_receiver/wiki
1•happy-game-dev•31m ago•0 comments

Walrus – distributed message streaming in Rust

4•janicerk•31m ago•0 comments

The Last Programming Language, and the End of (A Bit of) History

https://davegriffith.substack.com/p/the-last-programming-language-and
1•dxs•37m ago•0 comments

When Life Gets Too Easy

https://woodypearson.substack.com/p/when-life-gets-too-easy
1•heywoods•40m ago•0 comments

Show HN: Save Trippy – A Thanksgiving Game

https://www.savetrippy.com/
4•nezaj•40m ago•2 comments

Build Your Ideas with Gemini

https://app.new
1•tzury•40m ago•0 comments

Show HN: The Participatory Interface Theory

1•bobsh•42m ago•0 comments

Tesla CEO Elon Musk admits tough realization about FSD

https://www.thestreet.com/automotive/tesla-ceo-elon-musk-admits-tough-realization-about-fsd
2•gochuks•44m ago•0 comments