Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.6 KiB

Workflows - Agentless Vulnerability Scanning

Workflow 1: Multi-Protocol Scanning Pipeline

┌──────────────────┐     ┌──────────────────┐     ┌──────────────────┐
│ Asset Discovery  │────>│ Classify by      │────>│ Select Scanning  │
│ (CMDB/Network)   │     │ OS / Platform    │     │ Protocol         │
└──────────────────┘     └──────────────────┘     └──────────────────┘
                                                          │
        ┌──────────────┬──────────────┬─────────────────┘
        v              v              v
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ SSH Scan     │ │ WinRM Scan   │ │ Cloud API    │
│ (Linux)      │ │ (Windows)    │ │ Snapshot Scan│
└──────────────┘ └──────────────┘ └──────────────┘
        │              │              │
        └──────────────┴──────────────┘
                       │
                       v
              ┌──────────────────┐
              │ Normalize &      │
              │ Correlate Results│
              └──────────────────┘

Workflow 2: Cloud Snapshot Scan Process

For each cloud VM:
    1. Identify attached volumes (root + data)
    2. Create snapshot of root volume via cloud API
    3. Mount snapshot in isolated analysis environment
    4. Extract OS metadata (packages, configs, users)
    5. Compare against vulnerability databases (NVD, vendor)
    6. Generate findings with CVE mappings
    7. Delete temporary snapshot
    8. Report findings to central dashboard

Workflow 3: Credential Validation Before Scan

Pre-Scan Credential Check:
    For each target:
        1. Test SSH/WinRM connectivity (TCP handshake)
        2. Authenticate with stored credentials
        3. Execute lightweight test command
        4. Verify sudo/admin privileges if required
        5. Log result: Success / Auth Failure / Network Error
        6. Only proceed with scan if credential test passes