mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 00:23:15 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.2 KiB
2.2 KiB
API Reference: Analyzing Windows LNK Files for Artifacts
LnkParse3
Parse a Single LNK File
import LnkParse3
with open("shortcut.lnk", "rb") as f:
lnk = LnkParse3.lnk_file(f)
info = lnk.get_json()
# Access header timestamps
header = info["header"]
print(header["creation_time"], header["modified_time"], header["accessed_time"])
# Access target path
link_info = info.get("link_info", {})
print(link_info.get("local_base_path"))
# Access volume info
vol = link_info.get("volume_id", {})
print(vol.get("drive_type"), vol.get("drive_serial_number"))
# Access tracker data (machine ID, MAC)
extra = info.get("extra", {})
tracker = extra.get("DISTRIBUTED_LINK_TRACKER_BLOCK", {})
print(tracker.get("machine_id"), tracker.get("mac_address"))
LNK JSON Structure
{
"header": {
"creation_time": "2024-01-15 14:32:00",
"modified_time": "2024-01-15 14:32:00",
"accessed_time": "2024-01-15 14:32:00",
"file_size": 45056
},
"link_info": {
"local_base_path": "E:\\Documents\\report.xlsx",
"volume_id": {
"drive_type": "DRIVE_REMOVABLE",
"drive_serial_number": "1234-ABCD",
"volume_label": "KINGSTON"
}
},
"string_data": {
"working_dir": "E:\\Documents",
"command_line_arguments": ""
},
"extra": {
"DISTRIBUTED_LINK_TRACKER_BLOCK": {
"machine_id": "DESKTOP-ABC123",
"mac_address": "AA:BB:CC:DD:EE:FF"
}
}
}
Key LNK File Locations
| Location | Description |
|---|---|
%APPDATA%\Microsoft\Windows\Recent\ |
Recently accessed files |
%APPDATA%\...\Recent\AutomaticDestinations\ |
Jump Lists |
%APPDATA%\...\Recent\CustomDestinations\ |
Pinned Jump List items |
%USERPROFILE%\Desktop\ |
Desktop shortcuts |
%APPDATA%\...\Startup\ |
User startup (persistence) |
%PROGRAMDATA%\...\Startup\ |
System startup (persistence) |
Drive Types
| Value | Meaning |
|---|---|
| DRIVE_REMOVABLE | USB, SD card |
| DRIVE_FIXED | Internal HDD/SSD |
| DRIVE_REMOTE | Network share |
| DRIVE_CDROM | Optical media |
References
- LnkParse3: https://pypi.org/project/LnkParse3/
- Shell Link Binary Format: https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-shllink/
- LECmd: https://github.com/EricZimmerman/LECmd