Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.9 KiB

API Enumeration Attack Detection — API Reference

Libraries

Library Install Purpose
requests pip install requests WAF and SIEM API queries

Detection Techniques

Technique Indicator Severity
Sequential ID enumeration /api/users/1, /api/users/2, ... HIGH
Endpoint fuzzing High 404 rate on /api/* paths HIGH
Rate abuse >50 API requests/minute from single IP MEDIUM
Path discovery Requests to /swagger, /api-docs, /graphql HIGH
BOLA/IDOR probing Access to other users' resource IDs CRITICAL

NGINX Combined Log Format

$remote_addr - $remote_user [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent"

Common Enumeration Paths

Pattern Description
/api/v1/users/{id} User ID enumeration
/api/v1/accounts/{uuid} Account UUID guessing
/graphql?query={__schema} GraphQL introspection
/swagger/v1/swagger.json API documentation discovery
/api-docs, /.well-known Endpoint discovery

WAF Rule Categories

Category Description
rate-limit Request rate exceeds threshold
api-abuse Automated API enumeration
bola Broken Object Level Authorization
scanner Known scanner/fuzzer user-agent

OWASP API Security Top 10

ID Risk
API1 Broken Object Level Authorization
API2 Broken Authentication
API3 Broken Object Property Level Auth
API4 Unrestricted Resource Consumption
API5 Broken Function Level Authorization

External References