Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.8 KiB

API Reference: Memory Forensics with Volatility 3

Volatility 3 CLI

Plugin Description
windows.info OS version, kernel base, system time
windows.pslist List processes via EPROCESS linked list
windows.pstree Process tree with parent-child relationships
windows.psscan Pool scan for processes (finds hidden)
windows.malfind Detect injected code in process memory
windows.netscan Active network connections and listening ports
windows.cmdline Command line arguments for all processes
windows.dlllist DLLs loaded per process
windows.hashdump Extract cached NTLM password hashes
windows.lsadump LSA secrets from memory
windows.svcscan Windows services enumeration
windows.modules Loaded kernel modules
windows.modscan Pool scan for kernel modules (finds hidden)
windows.registry.hivelist List registry hives in memory
windows.registry.printkey Print specific registry key values
yarascan Scan memory with YARA rules
windows.memmap Dump process memory to disk

Common Flags

Flag Description
-f <file> Memory dump file path
--pid <pid> Filter by process ID
--dump Dump matched content to files
-o <dir> Output directory for dumps
--yara-file <file> YARA rules file for scanning

Python Libraries

Library Version Purpose
subprocess stdlib Execute Volatility 3 CLI commands
re stdlib Parse plugin output

References