candle micro
A localized intelligence workbench for vulnerability intelligence, product impact analysis and security operations.
Zhuwei Zhuwei is a localized vulnerability intelligence workbench for security operations, product security and vulnerability intelligence tracking scenarios. It can help you collect multi-source vulnerability information, screen high-value alerts, maintain a library of focused products, upload source packages as local evidence, and assist in determining the impact of vulnerabilities on your own products through model analysis and map relationships. #Who is suitable for use - Security operations personnel: Continuously check for new vulnerabilities, track high-risk alarms, and process read and confirmed status. - Product security team: Maintain attention to products and determine whether vulnerabilities affect their own products or components. - R & D/security researcher: Upload the source code package and let the system conduct vulnerability analysis based on the local source code. - Vulnerability intelligence analysts: Integrate data sources such as NVD, GitHub Advisory, CNVD, and AVD to precipitate evidence and analysis results. #First use 1. Open the lazy cat application portal and enter the candle micro console. 2. First go to the "Configuration" page at the top navigation. 3. Fill in the model service information in the "Model Source": - Model URL, such as `https://api.deepseek.com/anthropic` - API Key - Flash model name - Pro model name 4. After saving, you can click "Refresh Balance" to confirm whether the model interface is available. 5. Return to "Kanban" and click on "30-minute source" or "low-frequency source" at the top to start collecting data. When models are not configured, vulnerability collection, kanban, alerts, and product libraries can still be used, but the ability to "analyze" will be limited. ##Daily usage process ### 1. View data signage After entering "Kanban", you can quickly understand the current system's vulnerabilities, alarms, product and data source operation status. It is recommended to read here first in daily life: - Whether the number of new vulnerabilities has increased abnormally. - Whether high-risk/critical vulnerabilities have increased. - Whether the data source has consecutive failures. - Analyze whether there is a backlog in the queue. ### 2. Running data source There are two collection entrances at the top of the page: - `30-minute source`: Suitable for pulling and updating data sources with high frequency. - `Low-frequency source`: Suitable for pulling low-frequency updates or data sources that take a long time. After clicking, the system will perform the collection task in the background. The collection results will enter the vulnerability database, alarm center, product database and evidence database. Some sites may require cookies or sessions to stably crawl, and can be maintained in the "Site Sessions" area of "Configuration". ### 3. Handle alarms After entering the "Alerts" page, you can view the alarms by severity, source, keywords and status. Recommended handling method: 1. Priority is given to viewing severe and high-risk alerts. 2. Open the alarm details and view the vulnerability title, CVE/GHSA, source and associated products. 3. Alerts that are acknowledged to have been processed or do not need attention are marked as read/acknowledged. 4. Enter the "Analysis" or vulnerability details page to initiate model analysis for vulnerabilities that need to be researched and judged. ### 4. Maintain product library The "Products" page is used to manage the software, components, and vendor information you really care about.



