mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 16:40:24 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.6 KiB
2.6 KiB
Workflows - Agentless Vulnerability Scanning
Workflow 1: Multi-Protocol Scanning Pipeline
┌──────────────────┐ ┌──────────────────┐ ┌──────────────────┐
│ Asset Discovery │────>│ Classify by │────>│ Select Scanning │
│ (CMDB/Network) │ │ OS / Platform │ │ Protocol │
└──────────────────┘ └──────────────────┘ └──────────────────┘
│
┌──────────────┬──────────────┬─────────────────┘
v v v
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ SSH Scan │ │ WinRM Scan │ │ Cloud API │
│ (Linux) │ │ (Windows) │ │ Snapshot Scan│
└──────────────┘ └──────────────┘ └──────────────┘
│ │ │
└──────────────┴──────────────┘
│
v
┌──────────────────┐
│ Normalize & │
│ Correlate Results│
└──────────────────┘
Workflow 2: Cloud Snapshot Scan Process
For each cloud VM:
1. Identify attached volumes (root + data)
2. Create snapshot of root volume via cloud API
3. Mount snapshot in isolated analysis environment
4. Extract OS metadata (packages, configs, users)
5. Compare against vulnerability databases (NVD, vendor)
6. Generate findings with CVE mappings
7. Delete temporary snapshot
8. Report findings to central dashboard
Workflow 3: Credential Validation Before Scan
Pre-Scan Credential Check:
For each target:
1. Test SSH/WinRM connectivity (TCP handshake)
2. Authenticate with stored credentials
3. Execute lightweight test command
4. Verify sudo/admin privileges if required
5. Log result: Success / Auth Failure / Network Error
6. Only proceed with scan if credential test passes