Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.0 KiB

API Reference: Analyzing Windows Amcache Artifacts

Amcache.hve Location

C:\Windows\AppCompat\Programs\Amcache.hve

Registry Keys

Key Path Contents
Root\InventoryApplicationFile File execution evidence with SHA-1
Root\InventoryApplication Installed application metadata
Root\InventoryDevicePnp PnP device connection history
Root\InventoryDriverBinary Driver binary metadata

regipy Python Library

pip install regipy
from regipy.registry import RegistryHive

reg = RegistryHive('/path/to/Amcache.hve')
for subkey in reg.get_key('Root\\InventoryApplicationFile').iter_subkeys():
    values = {v.name: v.value for v in subkey.iter_values()}
    print(values.get('Name'), values.get('LowerCaseLongPath'))

AmcacheParser (Eric Zimmerman)

# Parse Amcache.hve to CSV
AmcacheParser.exe -f C:\evidence\Amcache.hve --csv C:\output\

# Include device and driver entries
AmcacheParser.exe -f Amcache.hve --csv output\ -i

Output CSV Columns

Column Description
Name Application/file name
LowerCaseLongPath Full lowercase path
Publisher Software publisher
FileId SHA-1 hash (prefixed with 0000)
Size File size in bytes
LinkDate PE compilation timestamp
Version File version string
ProgramId Associated program GUID

Forensic Value

Artifact Evidence
SHA-1 hash File identification even after deletion
LowerCaseLongPath Execution path including USB/temp
LinkDate PE compile time (timestomping detection)
Publisher Legitimacy verification
Last Modified Registry key update timestamp

Suspicious Indicators

Pattern Concern
Path contains \Temp\ Execution from temp directory
Path contains \Downloads\ User-downloaded execution
Missing Publisher Unsigned/unknown binary
LinkDate far from file date Possible timestomping
Known tool names (mimikatz, psexec) Attacker tooling