Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.7 KiB

Palo Alto Prisma Access Zero Trust — API Reference

Authentication

Parameter Value
Token URL https://auth.apps.paloaltonetworks.com/oauth2/access_token
Grant Type client_credentials
Scope tsg_id:<tenant_service_group_id>

SASE Configuration API Endpoints

Method Endpoint Description
GET /sse/config/v1/remote-networks List remote network connections
GET /sse/config/v1/service-connections List service connections
GET /sse/config/v1/ike-gateways List IKE gateway configurations
GET /sse/config/v1/security-rules List security policy rules
GET /sse/config/v1/hip-profiles List Host Information Profiles
GET /sse/config/v1/mobile-agent/global-settings GlobalProtect mobile user config
POST /sse/config/v1/security-rules Create security rule
PUT /sse/config/v1/security-rules/{id} Update security rule

Base URL

https://api.sase.paloaltonetworks.com

Security Rule Actions

Action Description
allow Permit traffic matching rule
deny Block traffic matching rule
drop Silently drop traffic
reset-client Send TCP RST to client

HIP Match Criteria

Field Description
disk-encryption Require disk encryption enabled
firewall Require host firewall active
patch-management Require OS patches current
anti-malware Require AV/EDR running

External References