First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s

This commit is contained in:
dela
2026-10-09 08:38:16 +08:00
commit 0335d572de
756 changed files with 201663 additions and 0 deletions
+79
View File
@@ -0,0 +1,79 @@
# ARTEX ATT&CK 커버리지
한국어 · [English](README.md)
이 저장소의 탐지 규칙이 태그하는 [MITRE ATT&CK](https://attack.mitre.org/)(Enterprise) 기법을
Navigator 레이어로 정리한 것입니다. [Sigma 규칙](../sigma/)의 `attack.*` 태그에서 손으로 만들었고,
모든 기법은 지표가 이 저장소 소스에서 확인한 문자열이나 행동인 규칙에 근거합니다. 추정으로 넣은
항목은 없으며, [일관성 테스트](../tests/attack/run.sh)가 레이어와 규칙이 서로 어긋나지 않게 지킵니다.
- **`artex_navigator_layer.json`**: ATT&CK Navigator v4.5 형식의 레이어입니다.
## 점수의 의미
여기서 커버리지는 "이 저장소가 이 기법을 태그하는 탐지를 제공한다"는 뜻이지, "이 기법이 완전히
덮인다"는 뜻이 아닙니다. 점수는 탐지 강도를 일부러 정직하게 매겼습니다.
- **100: ARTEX 고유 시그니처 또는 행동.** ARTEX 에만 있는 정적 지표(`artex-enrich/1.0`·
`artex-selfupdate` User-Agent, 가드 감사 마커)이거나, 그 위에 세운 행동 규칙(보강 속도·팬아웃,
가드 차단 묶음)입니다.
- **50–65: 일반 헌팅 단서.** ARTEX 가드의 차단 목록을 반영한 파괴적 명령 헌팅입니다. 같은 명령은
정당한 관리자도 실행하므로 양성(benign) 활동에서도 발화합니다. 적중은 단서로 다루고 단정의
근거로 삼지 마십시오. 65 는 상관 규칙이 그 명령을 ARTEX 가드 마커와 결합해 특이도를 높인
경우를 가리킵니다.
## 다루는 기법
여섯 전술에 걸친 여덟 기법입니다. 각 기법은 그것을 태그하는 규칙에 대응합니다.
- **정찰(Reconnaissance): T1595 (Active Scanning), T1592 (Gather Victim Host Information).**
[`sigma/artex_enrich_user_agent.yml`](../sigma/artex_enrich_user_agent.yml),
[`sigma/correlation/artex_enrich_scan_velocity.yml`](../sigma/correlation/artex_enrich_scan_velocity.yml),
[`sigma/correlation/artex_enrich_fanout.yml`](../sigma/correlation/artex_enrich_fanout.yml), 그리고
[Suricata 규칙](../suricata/artex.rules)(sid 1000001 / 1000002)입니다.
- **명령·제어(Command and Control): T1105 (Ingress Tool Transfer).**
[`sigma/artex_selfupdate_egress.yml`](../sigma/artex_selfupdate_egress.yml)입니다.
- **실행(Execution): T1059 (Command and Scripting Interpreter).**
[`sigma/artex_guard_audit_framing.yml`](../sigma/artex_guard_audit_framing.yml),
[`sigma/correlation/artex_guard_block_burst.yml`](../sigma/correlation/artex_guard_block_burst.yml),
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml)입니다.
- **임팩트(Impact): T1485 (Data Destruction), T1561.002 (Disk Wipe: Disk Structure Wipe), T1489 (Service Stop).**
[`sigma/destructive_command_hunting.yml`](../sigma/destructive_command_hunting.yml)이며, T1485 는
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml)로도 보강됩니다.
- **자격 증명 접근·수집(Credential Access / Collection): T1557 (Adversary-in-the-Middle).**
[`sigma/artex_recording_proxy_ca.yml`](../sigma/artex_recording_proxy_ca.yml)이며, 워커 도구의 트래픽을
복호화·기록하려고 ARTEX 내장 트래픽 기록기(`traffic/traffic.go`)가 설치하는 MITM 루트 CA 아티팩트를
겨냥한 호스트·포렌식 헌팅 단서입니다.
## 사용법
1. [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/)를 엽니다.
2. **Open Existing Layer → Upload from local** 을 골라 `artex_navigator_layer.json` 을 선택합니다
(또는 이 저장소의 raw 파일 URL 을 가리킵니다).
3. 점수를 매긴 기법이 탐지 강도에 따라 색으로 구분되어 나타나고, 각 기법에는 근거가 된 규칙 파일과
방어 가이드 절을 적은 주석이 붙어 있습니다.
## 범위와 정직함
- **커버리지는 완전성이 아닙니다.** 여기서 점수를 받은 기법은 규칙이 그것을 태그한다는 뜻이지, 그
기법의 모든 변형을 탐지한다는 뜻이 아닙니다. 네트워크 선에서 ARTEX 고유 User-Agent 로 잡히는 신호는
정찰 단계의 보강 프로버(`artex-enrich/1.0`)와 공격 단계의 norma SDK WebFetch(`norma/0.4`) 둘뿐이고,
그 밖의 공격 트래픽은 도구 기본 지문을 따릅니다. 오래가는 탐지는 행동 기반입니다
(방어 가이드 [한국어](../../docs/defense-ko.md) · [English](../../docs/defense-en.md) 1~2절·4.1~4.2절 참조). 순수 웹 다단계 사례는 여전히
환경별 기본 규칙이 필요합니다.
- **정적 지표는 바꿀 수 있습니다.** 운영자가 User-Agent 를 다른 값으로 설정할 수 있으므로, 태그된
지표가 없다고 해서 안전하다는 뜻은 아닙니다. 규칙 파일에도 같은 유의점을 달아 두었습니다.
## 검증과 기여
[일관성 테스트](../tests/attack/run.sh)를 돌리십시오. Docker 만 있으면 되며, 레이어가 점수를 매긴
기법·전술이 정확히 규칙의 `attack.*` 태그와 같은지, 그리고 모든 기법이 실재하는 규칙 파일에
근거하는지 단언합니다.
```sh
detections/tests/attack/run.sh
```
규칙을 추가하거나 다시 태그하면 이 레이어도 맞춰 갱신하십시오. 규칙의 기법이 레이어에 없거나
레이어의 기법이 규칙에 없으면 테스트가 실패합니다. [`../README.ko.md`](../README.ko.md)와
[`../../CONTRIBUTING.md`](../../CONTRIBUTING.md)를 참조하십시오.
+90
View File
@@ -0,0 +1,90 @@
# ARTEX ATT&CK coverage
English · [한국어](README.ko.md)
> 한국어: 이 디렉터리는 [`../`](../)의 ARTEX 탐지 규칙(Sigma·Suricata)이 다루는 공격 기법을
> [MITRE ATT&CK](https://attack.mitre.org/) 전술·기법으로 정리한 **커버리지 레이어**입니다.
> 각 기법은 저장소 소스에 근거가 있는 규칙의 `attack.*` 태그에서만 가져왔고, 추정으로 넣은 항목은
> 없습니다. [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/)에 그대로 올려
> 어떤 ARTEX 행위에 어떤 규칙이 걸리는지 한눈에 볼 수 있습니다. 이 레이어는 자신이 소유하거나 서면
> 허가를 받은 시스템을 지키는 **방어·탐지 목적에만** 쓰십시오. 한국어 전체 문서는
> **[README.ko.md](README.ko.md)** 를 보십시오.
A [MITRE ATT&CK](https://attack.mitre.org/) Navigator layer that maps the detection rules in this
repository to the ATT&CK (Enterprise) techniques they tag. It is built by hand from the `attack.*` tags on
the [Sigma rules](../sigma/) — every technique is grounded in a rule whose indicator is a string or
behaviour verified in this repository's source, and the [consistency test](../tests/attack/run.sh)
keeps the layer and the rules from drifting apart.
- **`artex_navigator_layer.json`** — the layer, in ATT&CK Navigator v4.5 format.
## What the score means
Coverage here means "this repository ships a detection that tags this technique", not "this technique is
fully covered". The score is deliberately honest about detection strength:
- **100 — ARTEX-specific signature or behaviour.** A static indicator unique to ARTEX (the
`artex-enrich/1.0` / `artex-selfupdate` User-Agents, the guard audit marker) or a behaviour rule built
on one (enrichment velocity / fan-out, guard-block burst).
- **50–65 — generic hunting lead.** Destructive-command hunting mirrored from the ARTEX guard deny list.
The same commands are run by legitimate administrators, so these fire on benign activity too; treat a
hit as a lead, not an attribution. 65 marks the case where a correlation rule raises specificity by
pairing the command with the ARTEX guard marker.
## Techniques covered
Eight techniques across six tactics. Each maps to the rule(s) that tag it:
- **Reconnaissance — T1595 (Active Scanning), T1592 (Gather Victim Host Information).**
[`sigma/artex_enrich_user_agent.yml`](../sigma/artex_enrich_user_agent.yml),
[`sigma/correlation/artex_enrich_scan_velocity.yml`](../sigma/correlation/artex_enrich_scan_velocity.yml),
[`sigma/correlation/artex_enrich_fanout.yml`](../sigma/correlation/artex_enrich_fanout.yml), and the
[Suricata rules](../suricata/artex.rules) (sid 1000001 / 1000002).
- **Command and Control — T1105 (Ingress Tool Transfer).**
[`sigma/artex_selfupdate_egress.yml`](../sigma/artex_selfupdate_egress.yml).
- **Execution — T1059 (Command and Scripting Interpreter).**
[`sigma/artex_guard_audit_framing.yml`](../sigma/artex_guard_audit_framing.yml),
[`sigma/correlation/artex_guard_block_burst.yml`](../sigma/correlation/artex_guard_block_burst.yml),
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml).
- **Impact — T1485 (Data Destruction), T1561.002 (Disk Wipe: Disk Structure Wipe), T1489 (Service Stop).**
[`sigma/destructive_command_hunting.yml`](../sigma/destructive_command_hunting.yml), with T1485 also
reinforced by
[`sigma/correlation/artex_guard_marker_then_destructive.yml`](../sigma/correlation/artex_guard_marker_then_destructive.yml).
- **Credential Access / Collection — T1557 (Adversary-in-the-Middle).**
[`sigma/artex_recording_proxy_ca.yml`](../sigma/artex_recording_proxy_ca.yml) — the MITM root-CA artifact
ARTEX's embedded traffic recorder installs (`traffic/traffic.go`) to decrypt and log the worker tools'
traffic. A host/forensic hunting lead.
## How to use it
1. Open the [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/).
2. Choose **Open Existing Layer → Upload from local**, and select `artex_navigator_layer.json` (or point
it at the raw file URL from this repository).
3. The scored techniques appear colour-graded by detection strength, each with a comment naming the rule
file(s) and the defense-guide section behind it.
## Scope and honesty
- **Coverage is not completeness.** A technique scored here means a rule tags it, not that every variant
of the technique is detected. Only two ARTEX-unique User-Agents are visible on the wire — the enrichment
prober (`artex-enrich/1.0`) in the reconnaissance phase and the norma SDK WebFetch tool (`norma/0.4`) in
the attack phase — while the rest of the attack traffic follows tool-default fingerprints; the durable
detection is behavioural
(see the defense guide, [Korean](../../docs/defense-ko.md) · [English](../../docs/defense-en.md), sections 1–2 and 4.1–4.2). The pure web multi-stage
case still needs base rules specific to your environment.
- **Static indicators can be changed.** An operator can set a different User-Agent, so the absence of a
tagged indicator does not imply safety. This is the same caveat the rule files carry.
## Validate and contribute
Run the [consistency test](../tests/attack/run.sh) — it needs only Docker and asserts that the layer's
scored techniques and tactics are exactly the `attack.*` tags on the rules, with every technique grounded
in a rule file that exists:
```sh
detections/tests/attack/run.sh
```
When you add or retag a rule, update this layer to match — the test fails if a rule technique is missing
from the layer or a layer technique is absent from the rules. See [`../README.md`](../README.md) and
[`../../CONTRIBUTING.en.md`](../../CONTRIBUTING.en.md).
@@ -0,0 +1,149 @@
{
"name": "ARTEX detection coverage",
"versions": {
"attack": "16",
"navigator": "5.1.0",
"layer": "4.5"
},
"domain": "enterprise-attack",
"description": "MITRE ATT&CK (Enterprise) coverage of the ARTEX detection rules in this repository (detections/sigma, detections/suricata). Every technique below is drawn from the attack.* tags of a rule whose indicator is grounded in this repository's source; nothing is inferred. Score reflects detection strength: 100 = ARTEX-specific signature or behaviour, 50-65 = generic hunting lead that also catches legitimate administration. Maintained by hand from those tags and checked for rule<->layer consistency by detections/tests/attack/run.sh.",
"filters": {
"platforms": [
"PRE",
"Windows",
"Linux",
"macOS",
"Network",
"Containers"
]
},
"sorting": 0,
"layout": {
"layout": "side",
"aggregateFunction": "average",
"showID": true,
"showName": true,
"showAggregateScores": false,
"countUnscored": false,
"expandedSubtechniques": "annotated"
},
"hideDisabled": false,
"techniques": [
{
"techniqueID": "T1595",
"tactic": "reconnaissance",
"score": 100,
"comment": "ARTEX asset-enrichment probe (User-Agent artex-enrich/1.0). sigma/artex_enrich_user_agent.yml; behaviour via sigma/correlation/artex_enrich_scan_velocity.yml and artex_enrich_fanout.yml; network via suricata sid 1000001/1000002. Defense guide section 2 (target view), 4.1, 4.4.",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1592",
"tactic": "reconnaissance",
"score": 100,
"comment": "ARTEX auto-enrichment gathers victim host info (DNS/HTTP, reads <title>) under User-Agent artex-enrich/1.0. sigma/artex_enrich_user_agent.yml; behaviour via sigma/correlation/artex_enrich_scan_velocity.yml and artex_enrich_fanout.yml; network via suricata sid 1000001/1000002. Defense guide section 2 (target view), 4.4.",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1105",
"tactic": "command-and-control",
"score": 100,
"comment": "ARTEX self-update egress (User-Agent artex-selfupdate) fetching a newer binary from a code-hosting host. sigma/artex_selfupdate_egress.yml. Operator/forensic, not target-side. Defense guide section 2 (operator view), 4.4.",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1059",
"tactic": "execution",
"score": 100,
"comment": "ARTEX platform-guard control marker written to the audit log on a blocked tool call. sigma/artex_guard_audit_framing.yml; behaviour via sigma/correlation/artex_guard_block_burst.yml and artex_guard_marker_then_destructive.yml. Forensic/host-side. Defense guide section 2 (operator view), 4.2.",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1485",
"tactic": "impact",
"score": 65,
"comment": "Destructive data commands (rm -rf, DROP DATABASE, FLUSHALL, ...) mirrored from the ARTEX guard deny list. Generic hunting via sigma/destructive_command_hunting.yml; specificity raised when co-occurring with the guard marker in sigma/correlation/artex_guard_marker_then_destructive.yml. Expect legitimate-admin false positives. Defense guide section 2 (operator view), 4.2.",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1561",
"tactic": "impact",
"comment": "Parent shown only to surface the scored subtechnique below.",
"enabled": true,
"showSubtechniques": true
},
{
"techniqueID": "T1561.002",
"tactic": "impact",
"score": 50,
"comment": "Disk-structure wipe commands (mkfs, dd of=/dev/, shred) from the ARTEX guard deny list. Generic hunting lead, not an ARTEX-specific signature. sigma/destructive_command_hunting.yml. Defense guide section 2 (operator view).",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1489",
"tactic": "impact",
"score": 50,
"comment": "Service/availability stop commands (kill -9 -1, killall -9, iptables -F, nft flush ruleset) from the ARTEX guard deny list. Generic hunting lead. sigma/destructive_command_hunting.yml. Defense guide section 2 (operator view).",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1557",
"tactic": "credential-access",
"score": 50,
"comment": "ARTEX embedded recording proxy is an adversary-in-the-middle: it installs a MITM root CA (_ca/mitmproxy-ca-cert.pem) to decrypt and log its worker tools' HTTP(S) traffic, including any credentials in transit. The CA file on a host evidences the recorder having run. sigma/artex_recording_proxy_ca.yml. Forensic/host-side; the bare CA filename is shared with standalone mitmproxy, so it is a hunting lead. Defense guide section 2 (operator view).",
"enabled": true,
"showSubtechniques": false
},
{
"techniqueID": "T1557",
"tactic": "collection",
"score": 50,
"comment": "ARTEX embedded recording proxy is an adversary-in-the-middle: it installs a MITM root CA (_ca/mitmproxy-ca-cert.pem) to decrypt and log (collect) all of its worker tools' HTTP(S) traffic. The CA file on a host evidences the recorder having run. sigma/artex_recording_proxy_ca.yml. Forensic/host-side; the bare CA filename is shared with standalone mitmproxy, so it is a hunting lead. Defense guide section 2 (operator view).",
"enabled": true,
"showSubtechniques": false
}
],
"gradient": {
"colors": [
"#f0f0f0",
"#ffe766",
"#1a9850"
],
"minValue": 0,
"maxValue": 100
},
"legendItems": [
{
"label": "ARTEX-specific signature or behaviour (high)",
"color": "#1a9850"
},
{
"label": "Generic hunting lead, also catches legit admin (medium)",
"color": "#ffe766"
}
],
"metadata": [
{
"name": "repository",
"value": "https://github.com/jiwoochris/artex-ko"
},
{
"name": "rules",
"value": "detections/sigma (9), detections/suricata (2)"
},
{
"name": "consistency-test",
"value": "detections/tests/attack/run.sh"
}
],
"showTacticRowBackground": true,
"tacticRowBackground": "#205b8f",
"selectTechniquesAcrossTactics": true,
"selectSubtechniquesWithParent": false
}