Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.1 KiB

API Reference: Triaging Security Alerts in Splunk

splunklib (Splunk SDK for Python)

Installation

pip install splunk-sdk

Connection

import splunklib.client as client
service = client.connect(host="localhost", port=8089,
                         username="admin", password="password")

Running Searches

# Blocking search (wait for results)
job = service.jobs.create(query, exec_mode="blocking")

# Parse results
import splunklib.results as results
for result in results.JSONResultsReader(job.results(output_mode="json")):
    if isinstance(result, dict):
        print(result)

Search Parameters

Parameter Description
exec_mode blocking (wait) or normal (async)
earliest_time Search time range start (e.g., -24h)
latest_time Search time range end (e.g., now)
output_mode json, xml, or csv

Key SPL Commands for Triage

Command Purpose
`notable` Macro to access ES notable events
lookup asset_lookup_by_cidr Enrich with asset information
lookup identity_lookup_expanded Enrich with identity context
lookup threat_intel_by_ip Check IP against threat feeds
tstats Fast datamodel statistics
sendalert update_notable_event Update notable event status

Notable Event Status Values

Value Status
0 Unassigned
1 New
2 In Progress
3 Pending
4 Resolved
5 Closed

Disposition Categories

Disposition Criteria
True Positive Confirmed malicious activity
Benign True Positive Alert correct but activity authorized
False Positive Benign behavior matched detection logic
Undetermined Insufficient data to classify

References