Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.3 KiB

API Reference: Implementing AWS Security Hub Compliance

Libraries

boto3 -- Security Hub + S3 Remediation

Key Security Hub Methods

Method Description
enable_security_hub() Enable Security Hub with standards
batch_enable_standards() Enable CIS, FSBP, PCI DSS, NIST
get_findings() Query findings with compliance filters
batch_update_findings() Update workflow status and add notes
create_insight() Custom compliance aggregation views
create_finding_aggregator() Cross-region consolidation
enable_organization_admin_account() Org-wide admin delegation
update_organization_configuration() Auto-enable for new accounts

Key S3 Remediation Methods

Method Description
put_public_access_block() Block all public access on bucket
get_bucket_encryption() Check encryption configuration
put_bucket_encryption() Enable default SSE-S3 or SSE-KMS

Finding Filters

Filter Field Values
ComplianceStatus PASSED, FAILED, WARNING, NOT_AVAILABLE
SeverityLabel CRITICAL, HIGH, MEDIUM, LOW, INFORMATIONAL
WorkflowStatus NEW, NOTIFIED, RESOLVED, SUPPRESSED
RecordState ACTIVE, ARCHIVED
GeneratorId Standard-specific prefix for filtering

Compliance Standards

Standard Generator ID Prefix
AWS FSBP aws-foundational-security-best-practices
CIS AWS cis-aws-foundations-benchmark
PCI DSS pci-dss
NIST 800-53 nist-800-53

EventBridge Auto-Remediation Pattern

  • Source: aws.securityhub
  • Detail type: Security Hub Findings - Imported
  • Target: Lambda function for automated fix
  • Best practice: Only auto-remediate safe controls (S3 public access, encryption)

External References