Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.1 KiB

API Reference: Detecting RDP Brute Force Attacks

Windows Security Event IDs

Event ID Description Key Fields
4625 Failed logon attempt TargetUserName, IpAddress, SubStatus, LogonType
4624 Successful logon TargetUserName, IpAddress, LogonType
4776 NTLM credential validation TargetUserName, Workstation, Status
4771 Kerberos pre-auth failed TargetUserName, IpAddress, Status

Logon Types for RDP

Type Name Context
3 Network RDP with NLA enabled (pre-auth)
10 RemoteInteractive RDP session after NLA

Failure Sub-Status Codes

Sub-Status Meaning
0xC0000064 User does not exist
0xC000006A Wrong password
0xC0000234 Account locked out
0xC0000072 Account disabled
0xC0000193 Account expired
0xC0000071 Password expired

python-evtx Library Usage

import Evtx.Evtx as evtx

with evtx.Evtx("Security.evtx") as log:
    for record in log.records():
        xml_str = record.xml()

Install: pip install python-evtx lxml

wevtutil Export Commands

# Export Security log to EVTX
wevtutil epl Security C:\logs\security.evtx

# Query failed RDP logons
wevtutil qe Security /q:"*[System[(EventID=4625)] and EventData[Data[@Name='LogonType']='10']]" /f:text

# Count recent failed logons
wevtutil qe Security /q:"*[System[(EventID=4625)]]" /c:100 /rd:true /f:text

Detection Thresholds

Pattern Threshold Indicator
Brute force >10 failures/IP in 15 min Single-target credential guessing
Password spray >5 unique users/IP Multi-user single-password attack
Compromise 4625 followed by 4624 from same IP Successful brute force

References