mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.9 KiB
2.9 KiB
Incident Triage Report
Alert Information
| Field | Value |
|---|---|
| Alert ID | |
| Alert Source | [SIEM/EDR/IDS/Email Gateway] |
| Alert Name/Rule | |
| Alert Time | YYYY-MM-DD HH:MM UTC |
| Triage Analyst | |
| Triage Start Time | YYYY-MM-DD HH:MM UTC |
| Triage End Time | YYYY-MM-DD HH:MM UTC |
Alert Details
| Field | Value |
|---|---|
| Source IP | |
| Source Hostname | |
| Destination IP | |
| Destination Hostname | |
| Protocol/Port | |
| User Account | |
| File Hash (SHA256) | |
| Domain/URL |
IOC Enrichment Results
IP Reputation
| Source | Score | Details |
|---|---|---|
| VirusTotal | /100 | malicious detections |
| AbuseIPDB | % confidence | reports |
| Shodan | Open ports/services | |
| Internal Intel | Previous incidents |
File Hash Reputation
| Source | Score | Details |
|---|---|---|
| VirusTotal | /70+ engines | Family: |
| MalwareBazaar | Tags: | |
| Internal IOC DB |
Domain Reputation
| Source | Score | Details |
|---|---|---|
| VirusTotal | /100 | |
| URLScan.io | ||
| PassiveTotal |
Classification
Incident Type
- Malware
- Ransomware
- Phishing
- Unauthorized Access
- Data Exfiltration
- DDoS
- Insider Threat
- Account Compromise
- Web Application Attack
- Privilege Escalation
- Other: ___________
MITRE ATT&CK Mapping
| Tactic | Technique ID | Technique Name |
|---|---|---|
Severity Assessment
Scoring Factors
| Factor | Rating | Score |
|---|---|---|
| Asset Criticality | [Critical/High/Medium/Low] | /4 |
| Data Sensitivity | [PII-PHI/PCI/Confidential/Public] | /4 |
| Threat Status | [Active/Confirmed/Attempted/Recon] | /4 |
| Scope | [Enterprise/Department/System/User] | /4 |
| Total | /16 |
Severity Determination
| Field | Value |
|---|---|
| Severity | [Critical/High/Medium/Low] |
| Priority | [P1/P2/P3/P4] |
| Response SLA | [15 min/30 min/2 hours/24 hours] |
| Justification |
Triage Decision
- Escalate - Confirmed incident requiring immediate response
- Investigate - Needs further analysis before confirmation
- Monitor - Suspicious but insufficient evidence; enhanced monitoring
- Close - False Positive - Benign activity; rule tuning recommended
- Close - Informational - Expected/authorized activity
Playbook Assignment
| Field | Value |
|---|---|
| Selected Playbook | |
| Playbook Version | |
| Assigned Team | |
| Primary Analyst | |
| Backup Analyst |
Initial Actions Taken
- Alert acknowledged in SIEM
- IOCs enriched with threat intel
- Incident ticket created (ID: ___)
- Playbook initiated
- Response team notified
- Stakeholders informed (if P1/P2)
Notes
[Additional context, observations, or concerns from triage]