mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.0 KiB
2.0 KiB
API Reference: Threat Modeling with OWASP Threat Dragon
Threat Dragon JSON Model Structure
| Field | Description |
|---|---|
version |
Threat Dragon version (e.g., "2.2.0") |
summary.title |
Threat model name |
summary.owner |
Model owner |
detail.diagrams[] |
Array of DFD diagrams |
detail.diagrams[].cells[] |
DFD elements within a diagram |
detail.diagrams[].diagramType |
Methodology (STRIDE, LINDDUN, CIA) |
DFD Element Types
| Type | Threat Dragon Class | STRIDE Categories |
|---|---|---|
| Process | tm.Process |
S, T, R, I, D, E |
| Data Store | tm.Store |
T, I, D |
| Data Flow | tm.Flow |
T, I, D |
| External Entity | tm.Actor |
S, R |
| Trust Boundary | tm.Boundary |
N/A |
STRIDE Categories
| Letter | Threat | Mitigation |
|---|---|---|
| S | Spoofing | Strong authentication, MFA |
| T | Tampering | Integrity checks, HMAC |
| R | Repudiation | Audit logging |
| I | Information Disclosure | Encryption, least privilege |
| D | Denial of Service | Rate limiting, auto-scaling |
| E | Elevation of Privilege | RBAC, authorization checks |
Threat Status Values
| Status | Description |
|---|---|
| Open | Threat needs mitigation |
| Mitigated | Controls address the threat |
| Not Applicable | Threat does not apply |
Docker Deployment
docker run -p 3000:3000 \
-e ENCRYPTION_JWT_SIGNING_KEY=$(openssl rand -hex 32) \
-e ENCRYPTION_JWT_REFRESH_SIGNING_KEY=$(openssl rand -hex 32) \
owasp/threat-dragon:latest
Python Libraries
| Library | Version | Purpose |
|---|---|---|
json |
stdlib | Threat Dragon model serialization |
uuid |
stdlib | Generate unique element IDs |
References
- OWASP Threat Dragon: https://owasp.org/www-project-threat-dragon/
- Threat Dragon GitHub: https://github.com/OWASP/threat-dragon
- STRIDE Model: https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats
- LINDDUN: https://www.linddun.org/