Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.8 KiB

API Reference: Autopsy and The Sleuth Kit (TSK)

mmls - Partition Layout

Syntax

mmls <image_file>
mmls -t dos <image_file>    # Force DOS partition table
mmls -t gpt <image_file>    # Force GPT partition table

Output Format

DOS Partition Table
Offset Sector: 0
     Slot    Start        End          Length       Description
     00:  00:00   0000002048   0001026047   0001024000   NTFS (0x07)

fls - File Listing

Syntax

fls -o <offset> <image>              # List root directory
fls -r -o <offset> <image>           # Recursive listing
fls -rd -o <offset> <image>          # Deleted files only, recursive
fls -m "/" -r -o <offset> <image>    # Bodyfile format for mactime

Flags

Flag Description
-r Recursive listing
-d Deleted entries only
-D Directories only
-m "/" Output in bodyfile format with mount point
-o Partition sector offset

icat - File Extraction by Inode

Syntax

icat -o <offset> <image> <inode> > recovered_file
icat -r -o <offset> <image> <inode> > file   # Recover slack space

istat - File Metadata

Syntax

istat -o <offset> <image> <inode>

Output Includes

  • MFT entry number and sequence
  • File creation, modification, access, MFT change timestamps
  • File size and data run locations
  • Attribute list (NTFS: $STANDARD_INFORMATION, $FILE_NAME, $DATA)

mactime - Timeline Generation

Syntax

mactime -b <bodyfile> -d > timeline.csv
mactime -b <bodyfile> -d 2024-01-15..2024-01-20 > filtered.csv
mactime -b <bodyfile> -z UTC -d > timeline_utc.csv

Output Columns

Date,Size,Type,Mode,UID,GID,Meta,File Name

img_stat - Image Information

Syntax

img_stat <image_file>

Syntax

sigfind -o <offset> <image> <hex_signature>
sigfind -o 2048 evidence.dd 25504446    # Find %PDF headers
sigfind -o 2048 evidence.dd 504B0304    # Find ZIP/DOCX headers

Common Signatures

Hex File Type
FFD8FF JPEG
89504E47 PNG
25504446 PDF
504B0304 ZIP/DOCX/XLSX
D0CF11E0 OLE (DOC/XLS)

Syntax

srch_strings -a -o <offset> <image> | grep -i "keyword"
srch_strings -t d <image>    # Print offset in decimal

Autopsy GUI Ingest Modules

Module Function
Recent Activity Browser history, downloads, cookies
Hash Lookup NSRL and known-bad hash matching
File Type Identification Signature-based file type detection
Keyword Search Full-text content indexing
Email Parser PST/MBOX/EML extraction
Extension Mismatch Wrong file extension detection
Embedded File Extractor ZIP, Office, PDF extraction
Encryption Detection Encrypted container identification