#Hermes Security β€” Autonomous Vulnerability Scanner

1 messages Β· Page 1 of 1 (latest)

split sphinx
#

🎬 https://youtu.be/SeVbVc8kos4
🌐 https://hermes-intel.duckdns.org
πŸ“Ž https://github.com/cemsid/hermes-security
🐦 https://x.com/EsedovCemsid/status/2033075343490433422

A quick note: the voiceover in the demo video was generated using AI text-to-speech. I added it without any cuts or edits. My English is not very good β€” I barely speak it. If the voice sounds unnatural or unclear at any point, I apologize for that. I did my best.

Hermes runs on a $10 server credit. Sometimes the API may be slow or return errors due to load. If you're testing with a higher-tier API (Claude, GPT-4, Gemini), scan speeds will be significantly better. Thank you for the credit that made this possible.

πŸ›‘οΈ HERMES SECURITY β€” Autonomous Vulnerability Scanner

Powered by Hermes-4-405B Β· Nous Research Hackathon 2025

My family was going through financial difficulties. When I saw this hackathon, I thought β€” maybe I can do something. Did I join for the money? Yes, I'll be honest. But I also genuinely saw a problem and wanted to solve it.

Site owners have no idea how exposed their websites are. Security audits are either too expensive or too technical. Why can't everyone learn about the security of their own site? That question is what built Hermes.

#

βš•οΈ What Hermes Does

Hermes-4-405B is active at every step β€” not just showing results, but reasoning, learning, and writing fixes.

πŸ” Full Scan β€” Real nmap port scan + SSL check + HTTP header analysis + DNS change detection + defacement detection + Google blacklist β€” unified Security Score 0 to 100

πŸ”¬ 38 Security Tests β€” SSL, HTTPS redirect, CSP, XSS, SQL injection, admin panel exposure, CORS, CSRF, CVE lookup β€” automated, no setup required

⚑ Multi-Scan β€” 3 domains scanned simultaneously in parallel threads, each with its own nmap + AI analysis

πŸ€– Autonomous Issue Hunter β€” Connects to GitHub repo, claims open issues, writes fixes, simulates CI, posts PR comments. Fully autonomous.

⏰ Nightly Cron β€” Fires every night at 02:00 UTC, sends Telegram report to your phone

πŸ“‘ Domain Intel β€” Subdomain discovery via crt.sh, DNS via Google DoH, SSL cert details, AI risk assessment

πŸ“„ ArXiv Integration β€” Every vulnerability linked to real academic papers from arXiv cs.CR

πŸ—ΊοΈ Excalidraw Diagram β€” Full attack surface diagram, exportable as .excalidraw or .svg

πŸ’Ž Wallet Guard β€” On-chain Ethereum wallet risk analysis

✈️ Telegram Bot β€” /scan, /findings, /domainintel, /arxiv + natural language chat

πŸ—οΈ Stack: Python / Flask / nmap / Hermes-4-405B / Ubuntu 24 / nginx
Security should be accessible to everyone. Hermes makes that possible.

πŸŒ‘ Dark Web Monitor β€” Checks HaveIBeenPwned database for domain breaches, exposed accounts analysis powered by Hermes AI (added)

πŸ“‘ CVE Live Ticker β€” Real-time scrolling feed of critical CVEs at the bottom of the dashboard (added)

worldly harness
#

Love this idea, super cool πŸ™‚