Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.6 KiB

Standards and Frameworks Reference

STIX 2.1 Infrastructure Object

{
  "type": "infrastructure",
  "name": "C2 Server",
  "infrastructure_types": ["command-and-control"],
  "description": "Cobalt Strike TeamServer at 198.51.100.1",
  "first_seen": "2025-01-01T00:00:00Z",
  "last_seen": "2025-06-01T00:00:00Z"
}

Diamond Model of Intrusion Analysis

  • Adversary: Threat actor or group
  • Capability: Tools, techniques, and malware
  • Infrastructure: C2 servers, domains, hosting
  • Victim: Targeted organization or individual

Infrastructure Types (STIX vocabulary)

  • command-and-control, botnet, exfiltration, hosting-malware
  • hosting-target-lists, phishing, staging, undefined

Network Fingerprinting Methods

Method Type Description
JARM Active TLS server fingerprint from 10 TLS handshakes
JA3S Passive Server Hello hash from TLS negotiation
JA3 Passive Client Hello hash for client fingerprinting
Favicon Hash Active HTTP favicon file hash
HTTP Headers Active/Passive Server banner and header fingerprinting
SSH Key Active SSH host key fingerprint

Passive DNS Record Types

  • A/AAAA: Domain to IP mapping
  • CNAME: Domain alias
  • MX: Mail server records
  • NS: Nameserver records
  • TXT: Text records (SPF, DKIM, verification)

References