01 — Sections
从哪里开始
按目标选择入口。全部免费,无需注册。
02 — Field notes
重大安全事故与漏洞
Capital One、Log4Shell、MOVEit 等等——把公开披露的入侵与漏洞,转化为你可用的防御方法。
03 — Our stance
本站的立场
一个安全产品,首先得管好自己的一亩三分地。
We don't hold secrets
We never store your real API keys — only metadata. The safest secret is the one we can't leak.
Scan only what you own
Diagnostics run on verified domains only. Internal IPs and metadata endpoints are blocked — SSRF defense is built in.
Minimal blast radius
Isolation so one breach can't cascade. This site itself runs on a dedicated, isolated host.
We test on ourselves
This site watches its own dependencies for CVEs. The incident that started this never gets missed by a human again.