mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
69 lines
2.1 KiB
Markdown
69 lines
2.1 KiB
Markdown
# Volatile Evidence Collection Report
|
|
|
|
## Case Information
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| Case ID | |
|
|
| System Hostname | |
|
|
| System IP Address | |
|
|
| System OS | |
|
|
| Collection Date/Time (UTC) | |
|
|
| Collector Name | |
|
|
| Authorization | [IR Plan / Legal Hold / HR Approval] |
|
|
|
|
## Collection Summary
|
|
| Evidence Category | Items Collected | Status |
|
|
|------------------|----------------|--------|
|
|
| Memory Dump | | Collected/Failed/Skipped |
|
|
| Network Connections | | Collected/Failed/Skipped |
|
|
| ARP Cache | | Collected/Failed/Skipped |
|
|
| DNS Cache | | Collected/Failed/Skipped |
|
|
| Routing Table | | Collected/Failed/Skipped |
|
|
| Running Processes | | Collected/Failed/Skipped |
|
|
| Open File Handles | | Collected/Failed/Skipped |
|
|
| Logged-in Users | | Collected/Failed/Skipped |
|
|
| System Configuration | | Collected/Failed/Skipped |
|
|
| Services | | Collected/Failed/Skipped |
|
|
| Scheduled Tasks | | Collected/Failed/Skipped |
|
|
| Registry/Config | | Collected/Failed/Skipped |
|
|
|
|
## Evidence Manifest
|
|
| Filename | SHA256 Hash | Size | Category |
|
|
|----------|------------|------|----------|
|
|
| | | | |
|
|
|
|
## Chain of Custody
|
|
| Date/Time (UTC) | Action | Person | Notes |
|
|
|-----------------|--------|--------|-------|
|
|
| | Evidence collected from live system | | |
|
|
| | Evidence transferred to forensic storage | | |
|
|
| | Evidence hash verified | | |
|
|
| | Evidence accessed for analysis | | |
|
|
|
|
## System Time Verification
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| System Clock (UTC) | |
|
|
| Reference Time (UTC) | |
|
|
| Time Offset | |
|
|
| NTP Synchronized | Yes/No |
|
|
| NTP Server | |
|
|
|
|
## Notable Findings During Collection
|
|
[Any suspicious processes, connections, or artifacts noted during collection]
|
|
|
|
## Collection Tool Information
|
|
| Tool | Version | Source | SHA256 Hash |
|
|
|------|---------|--------|-------------|
|
|
| | | | |
|
|
|
|
## Collector Certification
|
|
I certify that the evidence described above was collected using forensically sound methods, from external trusted tools, and that all evidence was hashed immediately upon collection.
|
|
|
|
| Field | Value |
|
|
|-------|-------|
|
|
| Collector Name | |
|
|
| Collector Title | |
|
|
| Date | |
|
|
| Signature | |
|