Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.5 KiB

API Reference: Investigating Phishing Email Incident

URLScan.io API

Endpoint Method Description
/api/v1/scan/ POST Submit URL for scanning (returns task UUID)
/api/v1/result/{uuid}/ GET Retrieve scan results including screenshot and DOM
/api/v1/search/?q=domain:example.com GET Search for previous scans of a domain

VirusTotal API v3

Endpoint Method Description
/api/v3/urls POST Submit URL for analysis
/api/v3/analyses/{id} GET Get URL analysis results with engine verdicts
/api/v3/files/{hash} GET Look up file hash (MD5/SHA-256) for reputation
/api/v3/files POST Upload file for scanning

MalwareBazaar API

Endpoint Method Description
https://mb-api.abuse.ch/api/v1/ POST Query by hash, tag, or signature name

Microsoft Graph (Email Operations)

Endpoint Method Description
/v1.0/users/{id}/messages GET Search mailbox for phishing message copies
/security/alerts_v2 GET Retrieve Defender for O365 phishing alerts
/security/incidents/{id} GET Get incident details with affected entities
Cmdlet Description
New-ComplianceSearch Create search across all mailboxes by subject/sender
Start-ComplianceSearch Execute the compliance search
New-ComplianceSearchAction -Purge Purge matched emails (SoftDelete or HardDelete)

Key Libraries

  • requests: HTTP client for URLScan.io, VirusTotal, and MalwareBazaar APIs
  • email (stdlib): Parse .eml files and extract headers, body, and attachments
  • hashlib (stdlib): Calculate MD5/SHA-256 hashes for attachment analysis
  • vt-py: Official VirusTotal Python SDK for enrichment queries

Configuration

Variable Description
VT_API_KEY VirusTotal API key for URL and file hash lookups
URLSCAN_API_KEY URLScan.io API key for URL submission
GRAPH_ACCESS_TOKEN Microsoft Graph bearer token for email search

References