mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.6 KiB
2.6 KiB
Workflows - Metasploit Vulnerability Exploitation
Workflow 1: Vulnerability Validation Pipeline
┌───────────────┐ ┌───────────────┐ ┌───────────────┐
│ Import Scan │──>│ Filter Top │──>│ Search MSF │
│ Results to DB │ │ Priority CVEs │ │ Modules │
└───────────────┘ └───────────────┘ └───────────────┘
│
┌─────────────────────────────────────┘
v
┌───────────────┐ ┌───────────────┐ ┌───────────────┐
│ Run `check` │──>│ Exploit if │──>│ Document │
│ Command │ │ Authorized │ │ Evidence │
└───────────────┘ └───────────────┘ └───────────────┘
│
v
┌───────────────┐ ┌───────────────┐
│ Update Risk │──>│ Prioritize │
│ Assessment │ │ Remediation │
└───────────────┘ └───────────────┘
Workflow 2: Patch Verification
Patch Deployed
│
├──> Re-run `check` command against patched host
│ │
│ ├──> NOT VULNERABLE → Patch verified ✓
│ └──> STILL VULNERABLE → Patch failed ✗
│ │
│ └──> Escalate to remediation team
│
└──> Re-run auxiliary scanner
│
├──> No findings → Remediation confirmed
└──> Findings persist → Incomplete patch
Workflow 3: Metasploit Module Selection
CVE Identified
│
├──> search cve:CVE-YYYY-NNNNN
│ │
│ ├──> Exploit module found → Use for validation
│ ├──> Auxiliary scanner found → Use for bulk check
│ └──> No module found → Manual validation required
│
└──> Alternative: search for related modules
│
├──> search type:exploit platform:windows target:smb
└──> search type:auxiliary name:scanner