展示HN:Kexa.io – 开源IT安全与合规性验证
嗨,HN,
我们正在开发 Kexa.io([https://github.com/kexa-io/Kexa](https://github.com/kexa-io/Kexa)),这是一个在法国开发的开源工具(在 Euratech Cyber Campus 孵化),旨在帮助团队自动化验证 IT 安全和合规性这一常常繁琐的过程。手动跟踪不同资产(服务器、K8s、云资源)的配置,并确保它们符合安全基准(如 CIS 基准等)是具有挑战性且容易出错的。
我们开源核心的目标是提供一种简单的方法来定义检查、扫描您的资产,并获得关于安全态势的清晰报告。您可以定义自己的规则或使用常见标准。
我们目前正在积极开发我们的 SaaS 产品,计划在 2025 年 6 月左右发布测试版。其关键功能将是一个专为云环境设计的 AI 驱动的安全管理代理(最初针对 AWS、GCP、Azure)。该代理不仅仅是报告问题,还旨在提供主动的、可操作的建议,并可能自动化某些修复任务,以简化云安全管理和加固。
我们非常希望 HN 社区能在 GitHub 上查看这个开源项目。我们欢迎对概念或当前工具的反馈,如果您觉得有趣,给我们一个星标也能帮助其他人发现这个项目!如果即将推出的 AI 驱动云安全代理让您感兴趣,我们特别希望听到您的想法,或者您是否有兴趣加入测试版(大约在 2025 年 6 月)。
谢谢!!
查看原文
Hi HN,<p>We're building Kexa.io (<a href="https://github.com/kexa-io/Kexa">https://github.com/kexa-io/Kexa</a>), an open-source tool developed in France (incubated at Euratech Cyber Campus) to help teams automate the often tedious process of verifying IT security and compliance. Keeping track of configurations across diverse assets (servers, K8s, cloud resources) and ensuring they meet security baselines (like CIS benchmarks, etc.) manually is challenging and error-prone.<p>Our goal with the open-source core is to provide a straightforward way to define checks, scan your assets, and get clear reports on your security posture. You can define your own rules or use common standards.<p>We are now actively developing our SaaS offering, planned for a beta release around June 2025. The key feature will be an AI-powered security administration agent specifically designed for cloud environments (initially targeting AWS, GCP, Azure). Instead of just reporting issues, this agent will aim to provide proactive, actionable recommendations and potentially automate certain remediation tasks to simplify cloud security management and hardening.<p>We'd love for the HN community to check out the open-source project on GitHub. Feedback on the concept or the current tool is highly welcome, and a star if you find it interesting helps others discover the project! If the upcoming AI-powered cloud security agent sounds interesting, we'd be particularly keen to hear your thoughts or if you might be interested in joining the beta (~June 2025).<p>thank you !!