First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
This commit is contained in:
@@ -0,0 +1,79 @@
|
||||
# ARTEX ATT&CK 커버리지
|
||||
|
||||
한국어 · [English](README.md)
|
||||
|
||||
이 저장소의 탐지 규칙이 태그하는 [MITRE ATT&CK](https://attack.mitre.org/)(Enterprise) 기법을
|
||||
Navigator 레이어로 정리한 것입니다. [Sigma 규칙](../sigma/)의 `attack.*` 태그에서 손으로 만들었고,
|
||||
모든 기법은 지표가 이 저장소 소스에서 확인한 문자열이나 행동인 규칙에 근거합니다. 추정으로 넣은
|
||||
항목은 없으며, [일관성 테스트](../tests/attack/run.sh)가 레이어와 규칙이 서로 어긋나지 않게 지킵니다.
|
||||
|
||||
- **`artex_navigator_layer.json`**: ATT&CK Navigator v4.5 형식의 레이어입니다.
|
||||
|
||||
## 점수의 의미
|
||||
|
||||
여기서 커버리지는 "이 저장소가 이 기법을 태그하는 탐지를 제공한다"는 뜻이지, "이 기법이 완전히
|
||||
덮인다"는 뜻이 아닙니다. 점수는 탐지 강도를 일부러 정직하게 매겼습니다.
|
||||
|
||||
- **100: ARTEX 고유 시그니처 또는 행동.** ARTEX 에만 있는 정적 지표(`artex-enrich/1.0`·
|
||||
`artex-selfupdate` User-Agent, 가드 감사 마커)이거나, 그 위에 세운 행동 규칙(보강 속도·팬아웃,
|
||||
가드 차단 묶음)입니다.
|
||||
- **50–65: 일반 헌팅 단서.** ARTEX 가드의 차단 목록을 반영한 파괴적 명령 헌팅입니다. 같은 명령은
|
||||
정당한 관리자도 실행하므로 양성(benign) 활동에서도 발화합니다. 적중은 단서로 다루고 단정의
|
||||
근거로 삼지 마십시오. 65 는 상관 규칙이 그 명령을 ARTEX 가드 마커와 결합해 특이도를 높인
|
||||
경우를 가리킵니다.
|
||||
|
||||
## 다루는 기법
|
||||
|
||||
여섯 전술에 걸친 여덟 기법입니다. 각 기법은 그것을 태그하는 규칙에 대응합니다.
|
||||
|
||||
- **정찰(Reconnaissance): T1595 (Active Scanning), T1592 (Gather Victim Host Information).**
|
||||
[`sigma/artex_enrich_user_agent.yml`](../sigma/artex_enrich_user_agent.yml),
|
||||
[`sigma/correlation/artex_enrich_scan_velocity.yml`](../sigma/correlation/artex_enrich_scan_velocity.yml),
|
||||
[`sigma/correlation/artex_enrich_fanout.yml`](../sigma/correlation/artex_enrich_fanout.yml), 그리고
|
||||
[Suricata 규칙](../suricata/artex.rules)(sid 1000001 / 1000002)입니다.
|
||||
- **명령·제어(Command and Control): T1105 (Ingress Tool Transfer).**
|
||||
[`sigma/artex_selfupdate_egress.yml`](../sigma/artex_selfupdate_egress.yml)입니다.
|
||||
- **실행(Execution): T1059 (Command and Scripting Interpreter).**
|
||||
[`sigma/artex_guard_audit_framing.yml`](../sigma/artex_guard_audit_framing.yml),
|
||||
[`sigma/correlation/artex_guard_block_burst.yml`](../sigma/correlation/artex_guard_block_burst.yml),
|
||||
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml)입니다.
|
||||
- **임팩트(Impact): T1485 (Data Destruction), T1561.002 (Disk Wipe: Disk Structure Wipe), T1489 (Service Stop).**
|
||||
[`sigma/destructive_command_hunting.yml`](../sigma/destructive_command_hunting.yml)이며, T1485 는
|
||||
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml)로도 보강됩니다.
|
||||
- **자격 증명 접근·수집(Credential Access / Collection): T1557 (Adversary-in-the-Middle).**
|
||||
[`sigma/artex_recording_proxy_ca.yml`](../sigma/artex_recording_proxy_ca.yml)이며, 워커 도구의 트래픽을
|
||||
복호화·기록하려고 ARTEX 내장 트래픽 기록기(`traffic/traffic.go`)가 설치하는 MITM 루트 CA 아티팩트를
|
||||
겨냥한 호스트·포렌식 헌팅 단서입니다.
|
||||
|
||||
## 사용법
|
||||
|
||||
1. [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/)를 엽니다.
|
||||
2. **Open Existing Layer → Upload from local** 을 골라 `artex_navigator_layer.json` 을 선택합니다
|
||||
(또는 이 저장소의 raw 파일 URL 을 가리킵니다).
|
||||
3. 점수를 매긴 기법이 탐지 강도에 따라 색으로 구분되어 나타나고, 각 기법에는 근거가 된 규칙 파일과
|
||||
방어 가이드 절을 적은 주석이 붙어 있습니다.
|
||||
|
||||
## 범위와 정직함
|
||||
|
||||
- **커버리지는 완전성이 아닙니다.** 여기서 점수를 받은 기법은 규칙이 그것을 태그한다는 뜻이지, 그
|
||||
기법의 모든 변형을 탐지한다는 뜻이 아닙니다. 네트워크 선에서 ARTEX 고유 User-Agent 로 잡히는 신호는
|
||||
정찰 단계의 보강 프로버(`artex-enrich/1.0`)와 공격 단계의 norma SDK WebFetch(`norma/0.4`) 둘뿐이고,
|
||||
그 밖의 공격 트래픽은 도구 기본 지문을 따릅니다. 오래가는 탐지는 행동 기반입니다
|
||||
(방어 가이드 [한국어](../../docs/defense-ko.md) · [English](../../docs/defense-en.md) 1~2절·4.1~4.2절 참조). 순수 웹 다단계 사례는 여전히
|
||||
환경별 기본 규칙이 필요합니다.
|
||||
- **정적 지표는 바꿀 수 있습니다.** 운영자가 User-Agent 를 다른 값으로 설정할 수 있으므로, 태그된
|
||||
지표가 없다고 해서 안전하다는 뜻은 아닙니다. 규칙 파일에도 같은 유의점을 달아 두었습니다.
|
||||
|
||||
## 검증과 기여
|
||||
|
||||
[일관성 테스트](../tests/attack/run.sh)를 돌리십시오. Docker 만 있으면 되며, 레이어가 점수를 매긴
|
||||
기법·전술이 정확히 규칙의 `attack.*` 태그와 같은지, 그리고 모든 기법이 실재하는 규칙 파일에
|
||||
근거하는지 단언합니다.
|
||||
|
||||
```sh
|
||||
detections/tests/attack/run.sh
|
||||
```
|
||||
|
||||
규칙을 추가하거나 다시 태그하면 이 레이어도 맞춰 갱신하십시오. 규칙의 기법이 레이어에 없거나
|
||||
레이어의 기법이 규칙에 없으면 테스트가 실패합니다. [`../README.ko.md`](../README.ko.md)와
|
||||
[`../../CONTRIBUTING.md`](../../CONTRIBUTING.md)를 참조하십시오.
|
||||
@@ -0,0 +1,90 @@
|
||||
# ARTEX ATT&CK coverage
|
||||
|
||||
English · [한국어](README.ko.md)
|
||||
|
||||
> 한국어: 이 디렉터리는 [`../`](../)의 ARTEX 탐지 규칙(Sigma·Suricata)이 다루는 공격 기법을
|
||||
> [MITRE ATT&CK](https://attack.mitre.org/) 전술·기법으로 정리한 **커버리지 레이어**입니다.
|
||||
> 각 기법은 저장소 소스에 근거가 있는 규칙의 `attack.*` 태그에서만 가져왔고, 추정으로 넣은 항목은
|
||||
> 없습니다. [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/)에 그대로 올려
|
||||
> 어떤 ARTEX 행위에 어떤 규칙이 걸리는지 한눈에 볼 수 있습니다. 이 레이어는 자신이 소유하거나 서면
|
||||
> 허가를 받은 시스템을 지키는 **방어·탐지 목적에만** 쓰십시오. 한국어 전체 문서는
|
||||
> **[README.ko.md](README.ko.md)** 를 보십시오.
|
||||
|
||||
A [MITRE ATT&CK](https://attack.mitre.org/) Navigator layer that maps the detection rules in this
|
||||
repository to the ATT&CK (Enterprise) techniques they tag. It is built by hand from the `attack.*` tags on
|
||||
the [Sigma rules](../sigma/) — every technique is grounded in a rule whose indicator is a string or
|
||||
behaviour verified in this repository's source, and the [consistency test](../tests/attack/run.sh)
|
||||
keeps the layer and the rules from drifting apart.
|
||||
|
||||
- **`artex_navigator_layer.json`** — the layer, in ATT&CK Navigator v4.5 format.
|
||||
|
||||
## What the score means
|
||||
|
||||
Coverage here means "this repository ships a detection that tags this technique", not "this technique is
|
||||
fully covered". The score is deliberately honest about detection strength:
|
||||
|
||||
- **100 — ARTEX-specific signature or behaviour.** A static indicator unique to ARTEX (the
|
||||
`artex-enrich/1.0` / `artex-selfupdate` User-Agents, the guard audit marker) or a behaviour rule built
|
||||
on one (enrichment velocity / fan-out, guard-block burst).
|
||||
- **50–65 — generic hunting lead.** Destructive-command hunting mirrored from the ARTEX guard deny list.
|
||||
The same commands are run by legitimate administrators, so these fire on benign activity too; treat a
|
||||
hit as a lead, not an attribution. 65 marks the case where a correlation rule raises specificity by
|
||||
pairing the command with the ARTEX guard marker.
|
||||
|
||||
## Techniques covered
|
||||
|
||||
Eight techniques across six tactics. Each maps to the rule(s) that tag it:
|
||||
|
||||
- **Reconnaissance — T1595 (Active Scanning), T1592 (Gather Victim Host Information).**
|
||||
[`sigma/artex_enrich_user_agent.yml`](../sigma/artex_enrich_user_agent.yml),
|
||||
[`sigma/correlation/artex_enrich_scan_velocity.yml`](../sigma/correlation/artex_enrich_scan_velocity.yml),
|
||||
[`sigma/correlation/artex_enrich_fanout.yml`](../sigma/correlation/artex_enrich_fanout.yml), and the
|
||||
[Suricata rules](../suricata/artex.rules) (sid 1000001 / 1000002).
|
||||
- **Command and Control — T1105 (Ingress Tool Transfer).**
|
||||
[`sigma/artex_selfupdate_egress.yml`](../sigma/artex_selfupdate_egress.yml).
|
||||
- **Execution — T1059 (Command and Scripting Interpreter).**
|
||||
[`sigma/artex_guard_audit_framing.yml`](../sigma/artex_guard_audit_framing.yml),
|
||||
[`sigma/correlation/artex_guard_block_burst.yml`](../sigma/correlation/artex_guard_block_burst.yml),
|
||||
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml).
|
||||
- **Impact — T1485 (Data Destruction), T1561.002 (Disk Wipe: Disk Structure Wipe), T1489 (Service Stop).**
|
||||
[`sigma/destructive_command_hunting.yml`](../sigma/destructive_command_hunting.yml), with T1485 also
|
||||
reinforced by
|
||||
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml).
|
||||
- **Credential Access / Collection — T1557 (Adversary-in-the-Middle).**
|
||||
[`sigma/artex_recording_proxy_ca.yml`](../sigma/artex_recording_proxy_ca.yml) — the MITM root-CA artifact
|
||||
ARTEX's embedded traffic recorder installs (`traffic/traffic.go`) to decrypt and log the worker tools'
|
||||
traffic. A host/forensic hunting lead.
|
||||
|
||||
## How to use it
|
||||
|
||||
1. Open the [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/).
|
||||
2. Choose **Open Existing Layer → Upload from local**, and select `artex_navigator_layer.json` (or point
|
||||
it at the raw file URL from this repository).
|
||||
3. The scored techniques appear colour-graded by detection strength, each with a comment naming the rule
|
||||
file(s) and the defense-guide section behind it.
|
||||
|
||||
## Scope and honesty
|
||||
|
||||
- **Coverage is not completeness.** A technique scored here means a rule tags it, not that every variant
|
||||
of the technique is detected. Only two ARTEX-unique User-Agents are visible on the wire — the enrichment
|
||||
prober (`artex-enrich/1.0`) in the reconnaissance phase and the norma SDK WebFetch tool (`norma/0.4`) in
|
||||
the attack phase — while the rest of the attack traffic follows tool-default fingerprints; the durable
|
||||
detection is behavioural
|
||||
(see the defense guide, [Korean](../../docs/defense-ko.md) · [English](../../docs/defense-en.md), sections 1–2 and 4.1–4.2). The pure web multi-stage
|
||||
case still needs base rules specific to your environment.
|
||||
- **Static indicators can be changed.** An operator can set a different User-Agent, so the absence of a
|
||||
tagged indicator does not imply safety. This is the same caveat the rule files carry.
|
||||
|
||||
## Validate and contribute
|
||||
|
||||
Run the [consistency test](../tests/attack/run.sh) — it needs only Docker and asserts that the layer's
|
||||
scored techniques and tactics are exactly the `attack.*` tags on the rules, with every technique grounded
|
||||
in a rule file that exists:
|
||||
|
||||
```sh
|
||||
detections/tests/attack/run.sh
|
||||
```
|
||||
|
||||
When you add or retag a rule, update this layer to match — the test fails if a rule technique is missing
|
||||
from the layer or a layer technique is absent from the rules. See [`../README.md`](../README.md) and
|
||||
[`../../CONTRIBUTING.en.md`](../../CONTRIBUTING.en.md).
|
||||
@@ -0,0 +1,149 @@
|
||||
{
|
||||
"name": "ARTEX detection coverage",
|
||||
"versions": {
|
||||
"attack": "16",
|
||||
"navigator": "5.1.0",
|
||||
"layer": "4.5"
|
||||
},
|
||||
"domain": "enterprise-attack",
|
||||
"description": "MITRE ATT&CK (Enterprise) coverage of the ARTEX detection rules in this repository (detections/sigma, detections/suricata). Every technique below is drawn from the attack.* tags of a rule whose indicator is grounded in this repository's source; nothing is inferred. Score reflects detection strength: 100 = ARTEX-specific signature or behaviour, 50-65 = generic hunting lead that also catches legitimate administration. Maintained by hand from those tags and checked for rule<->layer consistency by detections/tests/attack/run.sh.",
|
||||
"filters": {
|
||||
"platforms": [
|
||||
"PRE",
|
||||
"Windows",
|
||||
"Linux",
|
||||
"macOS",
|
||||
"Network",
|
||||
"Containers"
|
||||
]
|
||||
},
|
||||
"sorting": 0,
|
||||
"layout": {
|
||||
"layout": "side",
|
||||
"aggregateFunction": "average",
|
||||
"showID": true,
|
||||
"showName": true,
|
||||
"showAggregateScores": false,
|
||||
"countUnscored": false,
|
||||
"expandedSubtechniques": "annotated"
|
||||
},
|
||||
"hideDisabled": false,
|
||||
"techniques": [
|
||||
{
|
||||
"techniqueID": "T1595",
|
||||
"tactic": "reconnaissance",
|
||||
"score": 100,
|
||||
"comment": "ARTEX asset-enrichment probe (User-Agent artex-enrich/1.0). sigma/artex_enrich_user_agent.yml; behaviour via sigma/correlation/artex_enrich_scan_velocity.yml and artex_enrich_fanout.yml; network via suricata sid 1000001/1000002. Defense guide section 2 (target view), 4.1, 4.4.",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1592",
|
||||
"tactic": "reconnaissance",
|
||||
"score": 100,
|
||||
"comment": "ARTEX auto-enrichment gathers victim host info (DNS/HTTP, reads <title>) under User-Agent artex-enrich/1.0. sigma/artex_enrich_user_agent.yml; behaviour via sigma/correlation/artex_enrich_scan_velocity.yml and artex_enrich_fanout.yml; network via suricata sid 1000001/1000002. Defense guide section 2 (target view), 4.4.",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1105",
|
||||
"tactic": "command-and-control",
|
||||
"score": 100,
|
||||
"comment": "ARTEX self-update egress (User-Agent artex-selfupdate) fetching a newer binary from a code-hosting host. sigma/artex_selfupdate_egress.yml. Operator/forensic, not target-side. Defense guide section 2 (operator view), 4.4.",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1059",
|
||||
"tactic": "execution",
|
||||
"score": 100,
|
||||
"comment": "ARTEX platform-guard control marker written to the audit log on a blocked tool call. sigma/artex_guard_audit_framing.yml; behaviour via sigma/correlation/artex_guard_block_burst.yml and artex_guard_marker_then_destructive.yml. Forensic/host-side. Defense guide section 2 (operator view), 4.2.",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1485",
|
||||
"tactic": "impact",
|
||||
"score": 65,
|
||||
"comment": "Destructive data commands (rm -rf, DROP DATABASE, FLUSHALL, ...) mirrored from the ARTEX guard deny list. Generic hunting via sigma/destructive_command_hunting.yml; specificity raised when co-occurring with the guard marker in sigma/correlation/artex_guard_marker_then_destructive.yml. Expect legitimate-admin false positives. Defense guide section 2 (operator view), 4.2.",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1561",
|
||||
"tactic": "impact",
|
||||
"comment": "Parent shown only to surface the scored subtechnique below.",
|
||||
"enabled": true,
|
||||
"showSubtechniques": true
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1561.002",
|
||||
"tactic": "impact",
|
||||
"score": 50,
|
||||
"comment": "Disk-structure wipe commands (mkfs, dd of=/dev/, shred) from the ARTEX guard deny list. Generic hunting lead, not an ARTEX-specific signature. sigma/destructive_command_hunting.yml. Defense guide section 2 (operator view).",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1489",
|
||||
"tactic": "impact",
|
||||
"score": 50,
|
||||
"comment": "Service/availability stop commands (kill -9 -1, killall -9, iptables -F, nft flush ruleset) from the ARTEX guard deny list. Generic hunting lead. sigma/destructive_command_hunting.yml. Defense guide section 2 (operator view).",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1557",
|
||||
"tactic": "credential-access",
|
||||
"score": 50,
|
||||
"comment": "ARTEX embedded recording proxy is an adversary-in-the-middle: it installs a MITM root CA (_ca/mitmproxy-ca-cert.pem) to decrypt and log its worker tools' HTTP(S) traffic, including any credentials in transit. The CA file on a host evidences the recorder having run. sigma/artex_recording_proxy_ca.yml. Forensic/host-side; the bare CA filename is shared with standalone mitmproxy, so it is a hunting lead. Defense guide section 2 (operator view).",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
},
|
||||
{
|
||||
"techniqueID": "T1557",
|
||||
"tactic": "collection",
|
||||
"score": 50,
|
||||
"comment": "ARTEX embedded recording proxy is an adversary-in-the-middle: it installs a MITM root CA (_ca/mitmproxy-ca-cert.pem) to decrypt and log (collect) all of its worker tools' HTTP(S) traffic. The CA file on a host evidences the recorder having run. sigma/artex_recording_proxy_ca.yml. Forensic/host-side; the bare CA filename is shared with standalone mitmproxy, so it is a hunting lead. Defense guide section 2 (operator view).",
|
||||
"enabled": true,
|
||||
"showSubtechniques": false
|
||||
}
|
||||
],
|
||||
"gradient": {
|
||||
"colors": [
|
||||
"#f0f0f0",
|
||||
"#ffe766",
|
||||
"#1a9850"
|
||||
],
|
||||
"minValue": 0,
|
||||
"maxValue": 100
|
||||
},
|
||||
"legendItems": [
|
||||
{
|
||||
"label": "ARTEX-specific signature or behaviour (high)",
|
||||
"color": "#1a9850"
|
||||
},
|
||||
{
|
||||
"label": "Generic hunting lead, also catches legit admin (medium)",
|
||||
"color": "#ffe766"
|
||||
}
|
||||
],
|
||||
"metadata": [
|
||||
{
|
||||
"name": "repository",
|
||||
"value": "https://github.com/jiwoochris/artex-ko"
|
||||
},
|
||||
{
|
||||
"name": "rules",
|
||||
"value": "detections/sigma (9), detections/suricata (2)"
|
||||
},
|
||||
{
|
||||
"name": "consistency-test",
|
||||
"value": "detections/tests/attack/run.sh"
|
||||
}
|
||||
],
|
||||
"showTacticRowBackground": true,
|
||||
"tacticRowBackground": "#205b8f",
|
||||
"selectTechniquesAcrossTactics": true,
|
||||
"selectSubtechniquesWithParent": false
|
||||
}
|
||||
Reference in New Issue
Block a user