mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 16:40:24 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
1.1 KiB
1.1 KiB
Workflows — Active Directory Penetration Testing
AD Attack Flow
Domain User Credentials
│
├── Enumeration
│ ├── BloodHound (attack paths)
│ ├── LDAP queries (users, groups, GPOs)
│ └── Service account discovery (SPNs)
│
├── Kerberos Attacks
│ ├── Kerberoasting → Hash cracking
│ ├── AS-REP Roasting → Hash cracking
│ └── Delegation abuse (unconstrained/constrained/RBCD)
│
├── ADCS Attacks
│ ├── ESC1-ESC8 template exploitation
│ └── Certificate-based auth to DA
│
├── Credential Harvesting
│ ├── LSASS dump (Mimikatz)
│ ├── SAM/SYSTEM extraction
│ └── DPAPI credential decryption
│
├── Domain Escalation
│ ├── DCSync (krbtgt + all hashes)
│ ├── Golden Ticket
│ └── AdminSDHolder persistence
│
└── Impact Demonstration
├── Full domain hash extraction
├── Access to sensitive resources
└── Cross-forest trust abuse