Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.8 KiB

API Reference: Patch Tuesday Response Process

MSRC Security Update API

GET https://api.msrc.microsoft.com/cvrf/v3.0/Updates('{yyyy-Mon}')
api-key: YOUR_MSRC_KEY
Accept: application/json

CVRF Vulnerability Fields

Field Description
CVE CVE identifier
Title.Value Vulnerability title
Threats[].Description.Value Severity, exploitation status
CVSSScoreSets[].BaseScore CVSS v3 base score
ProductStatuses[].ProductID Affected product IDs
Remediations[].URL KB article / patch URL

CISA Known Exploited Vulnerabilities (KEV)

GET https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

KEV Entry Fields

Field Description
cveID CVE identifier
vendorProject Vendor name
product Product name
dateAdded Date added to KEV
dueDate Remediation due date

Patch Priority Matrix

Priority Criteria SLA
Emergency Exploited + KEV + CVSS >= 9.0 24 hours
Critical Exploited OR KEV + CVSS >= 7.0 72 hours
Standard CVSS >= 7.0, no exploitation 7 days
Routine CVSS < 7.0, no exploitation 30 days

NVD API v2

GET https://services.nvd.nist.gov/rest/json/cves/2.0?cveId={CVE-ID}
apiKey: YOUR_NVD_KEY

WSUS Deployment API (PowerShell)

$wsus = Get-WsusServer
$update = $wsus.SearchUpdates("KB5034441")
$group = $wsus.GetComputerTargetGroup("Production")
$update.Approve("Install", $group)

Deployment Phase Timeline

Phase Window Targets
Emergency 0-24h Critical servers, exploited CVEs
Pilot 24-72h Test group (5% of fleet)
Broad 3-7d All production systems
Cleanup 7-30d Exceptions, rollback monitoring