Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.9 KiB

API Reference: Insider Threat Investigation

Data Sources

Source Log Type Key Fields
DLP System File transfers, USB connections user, action, file_path, bytes, device_id
Email Gateway Sent/received/forwarded emails sender, recipient, subject, attachment_size
VPN / Auth Logs Authentication events user, timestamp, source_ip, result
Cloud Access Broker SaaS application activity user, app, action, data_volume
Badge Access Physical access events user, location, timestamp, direction

Microsoft Graph API (for Microsoft 365 environments)

Endpoint Method Description
/auditLogs/signIns GET User sign-in activity logs
/security/alerts GET Security alerts including DLP
/users/{id}/activities GET User activity feed
/users/{id}/mailFolders/{id}/messages GET Email messages (eDiscovery)

Exabeam UEBA API

Endpoint Description
/api/users/{user}/timeline User activity timeline with risk scores
/api/users/{user}/risk Current risk score and contributing factors

Python Libraries

Library Version Purpose
csv stdlib Parse exported log files
json stdlib Report generation and data exchange
datetime stdlib Timestamp parsing and time-window analysis
requests >=2.28 API access for UEBA and SIEM platforms

References