Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.0 KiB

API Reference: Managing Intelligence Lifecycle

MITRE ATT&CK STIX/TAXII

Endpoint Description
cti-taxii.mitre.org/stix/collections/ TAXII server for ATT&CK STIX bundles
attack.mitre.org/versions/ ATT&CK version history and changelogs

Recorded Future API

Endpoint Method Description
/v2/alert/search GET Search intelligence alerts by rule and priority
/v2/entity/search GET Search threat actors, malware, and vulnerabilities
/v2/indicator/search GET Search IOCs with risk scores

MISP REST API

Endpoint Method Description
/events GET/POST List or create threat intelligence events
/attributes/restSearch POST Search for IOCs across all events
/feeds GET List configured intelligence feeds

OpenCTI GraphQL API

Query Description
stixCoreObjects Query threat actors, malware, and campaigns
reports List intelligence reports with confidence scores
indicators Query IOCs with STIX pattern matching

Key Libraries

  • stix2: Create and parse STIX 2.1 threat intelligence objects
  • taxii2-client: Connect to TAXII 2.1 servers for ATT&CK data
  • pymisp: Python client for MISP threat intelligence platform
  • requests: HTTP client for Recorded Future and custom feed APIs

Configuration

Variable Description
MISP_URL MISP instance URL
MISP_API_KEY MISP API authentication key
RF_API_TOKEN Recorded Future API token
OPENCTI_URL OpenCTI platform URL
OPENCTI_TOKEN OpenCTI API bearer token

References