Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.4 KiB

API Reference: Implementing Ticketing System for Incidents

Libraries

requests (HTTP Client)

  • Install: pip install requests
  • Used for ServiceNow REST API and TheHive API

ServiceNow REST API

Incident Table (/api/now/table/incident)

Method Endpoint Description
GET /table/incident List/query incidents
POST /table/incident Create new incident
PATCH /table/incident/{sys_id} Update incident
DELETE /table/incident/{sys_id} Delete incident

Key Incident Fields

Field Description
short_description Incident title
description Full description
urgency 1 (High), 2 (Medium), 3 (Low)
impact 1 (High), 2 (Medium), 3 (Low)
priority Auto-calculated from urgency + impact
state 1 (New) through 7 (Closed)
assignment_group Team assigned
work_notes Internal analyst notes
close_code Resolution classification
close_notes Resolution description

Query Parameters

  • sysparm_query -- Encoded query string
  • sysparm_limit -- Max results
  • sysparm_fields -- Comma-separated fields to return
  • sysparm_display_value -- Return display values

TheHive API (v4/v5)

Cases

Method Endpoint Description
POST /api/case Create case
GET /api/case/{id} Get case details
PATCH /api/case/{id} Update case
POST /api/case/_search Search cases

Tasks and Observables

Method Endpoint Description
POST /api/case/{id}/task Add task to case
POST /api/case/{id}/artifact Add observable/IOC

Severity Levels

  • 1: Low, 2: Medium, 3: High, 4: Critical

TLP Levels

  • 0: WHITE, 1: GREEN, 2: AMBER, 3: RED

SLA Target Reference

  • P1 (Critical): Response 15 min, Resolve 4 hours
  • P2 (High): Response 30 min, Resolve 8 hours
  • P3 (Medium): Response 4 hours, Resolve 24 hours
  • P4 (Low): Response 8 hours, Resolve 72 hours

External References