Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.6 KiB

Standards and Frameworks for AD Compromise Investigation

NIST SP 800-61 Rev 2 - Computer Security Incident Handling Guide

  • Provides incident response lifecycle: Preparation, Detection & Analysis, Containment, Eradication & Recovery, Post-Incident Activity
  • AD compromise investigations follow all four phases with emphasis on scoping the identity compromise

CISA Alert: Detecting and Mitigating Active Directory Compromises

MITRE ATT&CK Framework - Credential Access Tactics

  • T1003.006: OS Credential Dumping - DCSync
  • T1558.001: Steal or Forge Kerberos Tickets - Golden Ticket
  • T1558.002: Steal or Forge Kerberos Tickets - Silver Ticket
  • T1558.003: Steal or Forge Kerberos Tickets - Kerberoasting
  • T1550.002: Use Alternate Authentication Material - Pass the Hash
  • T1484.001: Domain Policy Modification - Group Policy Modification
  • T1098: Account Manipulation

Microsoft Security Best Practices

CIS Benchmarks for Active Directory

  • CIS Microsoft Windows Server Benchmark for DC hardening
  • Password policy requirements (minimum 14 characters)
  • Account lockout policy configuration
  • Audit policy settings for security event logging
  • GPO security baseline configurations

SANS FOR500 - Windows Forensic Analysis

  • Windows artifact analysis methodology
  • Registry analysis for persistence detection
  • Event log forensics for authentication tracking
  • Timeline analysis techniques for AD compromise

Semperis Identity Forensics and Incident Response (IFIR)

Key Windows Security Event IDs for AD Monitoring

  • Microsoft documentation on security auditing events
  • Advanced Audit Policy Configuration for DCs
  • Kerberos event logging requirements
  • Directory Service Access auditing