mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 16:40:24 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
1.7 KiB
1.7 KiB
Palo Alto Prisma Access Zero Trust — API Reference
Authentication
| Parameter | Value |
|---|---|
| Token URL | https://auth.apps.paloaltonetworks.com/oauth2/access_token |
| Grant Type | client_credentials |
| Scope | tsg_id:<tenant_service_group_id> |
SASE Configuration API Endpoints
| Method | Endpoint | Description |
|---|---|---|
| GET | /sse/config/v1/remote-networks |
List remote network connections |
| GET | /sse/config/v1/service-connections |
List service connections |
| GET | /sse/config/v1/ike-gateways |
List IKE gateway configurations |
| GET | /sse/config/v1/security-rules |
List security policy rules |
| GET | /sse/config/v1/hip-profiles |
List Host Information Profiles |
| GET | /sse/config/v1/mobile-agent/global-settings |
GlobalProtect mobile user config |
| POST | /sse/config/v1/security-rules |
Create security rule |
| PUT | /sse/config/v1/security-rules/{id} |
Update security rule |
Base URL
https://api.sase.paloaltonetworks.com
Security Rule Actions
| Action | Description |
|---|---|
allow |
Permit traffic matching rule |
deny |
Block traffic matching rule |
drop |
Silently drop traffic |
reset-client |
Send TCP RST to client |
HIP Match Criteria
| Field | Description |
|---|---|
disk-encryption |
Require disk encryption enabled |
firewall |
Require host firewall active |
patch-management |
Require OS patches current |
anti-malware |
Require AV/EDR running |