Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

35 lines
1.4 KiB
Markdown

# PowerShell Deobfuscation — API Reference
## Libraries
| Library | Install | Purpose |
|---------|---------|---------|
| re | stdlib | Regex pattern matching for obfuscation detection |
| base64 | stdlib | Base64 decoding of encoded commands |
| pySigma | `pip install pySigma` | Sigma rule generation for detections |
## Common Obfuscation Techniques
| Technique | Pattern | Example |
|-----------|---------|---------|
| Base64 Encoding | `-EncodedCommand <b64>` | `powershell -enc SQBFAFgA...` |
| String Concatenation | `'str1'+'str2'` | `'Inv'+'oke'+'-Exp'+'ression'` |
| Character Codes | `[char]73+[char]69` | `[char]73` = I, `[char]69` = E |
| Backtick Escape | `` `I`E`X `` | Backtick breaks keyword detection |
| Variable Substitution | `$env:COMSPEC` | Use env vars as execution paths |
| Compression | `IO.Compression.DeflateStream` | Compressed + Base64 payload |
## Detection Event IDs
| Source | Event ID | Description |
|--------|----------|-------------|
| PowerShell | 4104 | Script block logging (deobfuscated content) |
| Sysmon | 1 | Process creation with command line |
| Defender | 1116 | Malware detection |
## External References
- [Invoke-Obfuscation](https://github.com/danielbohannon/Invoke-Obfuscation)
- [PSDecode](https://github.com/R3MRUM/PSDecode)
- [PowerShell ScriptBlock Logging](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging)