Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.7 KiB

API Reference — Performing Network Traffic Analysis with Zeek

Libraries Used

  • pathlib: Read Zeek TSV log files
  • subprocess: Execute Zeek on PCAP files
  • collections.Counter: Traffic pattern aggregation

CLI Interface

python agent.py conn --log conn.log
python agent.py dns --log dns.log
python agent.py http --log http.log
python agent.py notice --log notice.log
python agent.py run --pcap capture.pcap [--output-dir /tmp/zeek_output]

Core Functions

parse_zeek_log(log_file) — Generic Zeek TSV parser

Parses #fields header and data rows. Returns headers and record list.

analyze_conn_log(conn_log) — Connection analysis

Statistics: protocols, services, top IPs/ports, total bytes, long connections (>1hr).

analyze_dns_log(dns_log) — DNS query analysis

Detects: long queries (>50 chars), TXT queries, NXDOMAIN responses. Flags potential DNS tunneling indicators.

analyze_http_log(http_log) — Web traffic analysis

Tracks: methods, status codes, top hosts, user agents. Flags suspicious UAs: curl, wget, python, powershell, certutil, bitsadmin.

analyze_notice_log(notice_log) — Security alert review

Parses Zeek notice.log for detected security events.

run_zeek_on_pcap(pcap_file, output_dir) — Generate Zeek logs from PCAP

Executes Zeek against PCAP to produce conn.log, dns.log, http.log, etc.

Zeek Log Fields

Log Key Fields
conn.log id.orig_h, id.resp_h, id.resp_p, proto, service, duration, orig_bytes
dns.log query, qtype_name, rcode_name
http.log method, host, uri, status_code, user_agent
notice.log note, msg, src, dst

Dependencies

System: zeek (for PCAP processing) No Python packages required.