mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 16:40:24 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
35 lines
1.4 KiB
Markdown
35 lines
1.4 KiB
Markdown
# PowerShell Deobfuscation — API Reference
|
|
|
|
## Libraries
|
|
|
|
| Library | Install | Purpose |
|
|
|---------|---------|---------|
|
|
| re | stdlib | Regex pattern matching for obfuscation detection |
|
|
| base64 | stdlib | Base64 decoding of encoded commands |
|
|
| pySigma | `pip install pySigma` | Sigma rule generation for detections |
|
|
|
|
## Common Obfuscation Techniques
|
|
|
|
| Technique | Pattern | Example |
|
|
|-----------|---------|---------|
|
|
| Base64 Encoding | `-EncodedCommand <b64>` | `powershell -enc SQBFAFgA...` |
|
|
| String Concatenation | `'str1'+'str2'` | `'Inv'+'oke'+'-Exp'+'ression'` |
|
|
| Character Codes | `[char]73+[char]69` | `[char]73` = I, `[char]69` = E |
|
|
| Backtick Escape | `` `I`E`X `` | Backtick breaks keyword detection |
|
|
| Variable Substitution | `$env:COMSPEC` | Use env vars as execution paths |
|
|
| Compression | `IO.Compression.DeflateStream` | Compressed + Base64 payload |
|
|
|
|
## Detection Event IDs
|
|
|
|
| Source | Event ID | Description |
|
|
|--------|----------|-------------|
|
|
| PowerShell | 4104 | Script block logging (deobfuscated content) |
|
|
| Sysmon | 1 | Process creation with command line |
|
|
| Defender | 1116 | Malware detection |
|
|
|
|
## External References
|
|
|
|
- [Invoke-Obfuscation](https://github.com/danielbohannon/Invoke-Obfuscation)
|
|
- [PSDecode](https://github.com/R3MRUM/PSDecode)
|
|
- [PowerShell ScriptBlock Logging](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging)
|