First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
This commit is contained in:
@@ -0,0 +1,105 @@
|
||||
# ARTEX 침해지표 (기계가 읽는)
|
||||
|
||||
한국어 · [English](README.md)
|
||||
|
||||
ARTEX 가 스스로 내보내는 고유 지문을 한 파일로 모은, 기계가 읽는 목록입니다. 탐지 로직이 아니라
|
||||
원자 지표 자체를 원하는 방어자를 위한 것입니다: [`artex_indicators.csv`](artex_indicators.csv)를
|
||||
위협 인텔리전스 플랫폼이나 SIEM 조회 테이블, 호스트 분류(triage) 체크리스트에 바로 넣으십시오.
|
||||
모든 값은 이 저장소 소스에서 확인한 문자열입니다. [탐지 규칙](../README.ko.md)과 방어 가이드
|
||||
([한국어](../../docs/defense-ko.md) · [English](../../docs/defense-en.md) 2절)가 근거로 삼는 바로
|
||||
그 문자열입니다. 각 행은 그 값이 어디서 오는지와 (있다면) 그 위에 세운 규칙을 적습니다.
|
||||
|
||||
## 열 구성
|
||||
|
||||
- **`id`**: 지표의 안정적인 슬러그입니다.
|
||||
- **`type`**: 지표의 종류입니다: `http.user-agent`, `string`(로그·파일에서 찾을 리터럴), `port`,
|
||||
`ip-dst|port`, `other`(위 범주에 들지 않는 호스트 아티팩트, 예: 데이터베이스 스키마 객체 이름).
|
||||
이들은 대응하는 MISP/STIX 속성 타입에 매핑됩니다.
|
||||
- **`value`**: 정확한 지표입니다. 비 ASCII 가드 마커를 포함해 원문 그대로 보존합니다.
|
||||
- **`perspective`**: `target`(ARTEX 가 탐침하는 시스템을 *향하는* 트래픽에서 관측) 또는
|
||||
`forensic`(ARTEX 가 실행됐거나 경유한 호스트 *위에서* 관측)입니다. 방어 가이드는 이 둘을 일부러
|
||||
구분합니다. 섞으면 틀린 결론이 나옵니다.
|
||||
- **`source`**: 그 값을 내보내는, 저장소 기준 상대 경로 소스 파일입니다(`;` 로 구분). 이것이
|
||||
근거입니다: 상류 재동기화가 내보내는 쪽을 바꾸면 여기 지표도 함께 바뀌어야 합니다.
|
||||
- **`rule`**: 그 정확한 값 위에 세운 탐지 규칙입니다(`;` 로 구분). (시끄러운) 규칙으로 내보내지
|
||||
않고 직접 분류하는 호스트 포렌식 지표는 비어 있습니다.
|
||||
- **`description`**: 한 줄 설명이며, 해당하는 경우 정직한 유의점을 함께 적습니다.
|
||||
|
||||
## MISP 이벤트 내보내기
|
||||
|
||||
같은 지표를 바로 가져올 수 있는 [MISP](https://www.misp-project.org/) 이벤트
|
||||
[`artex_indicators.misp.json`](artex_indicators.misp.json)로도 제공합니다. MISP 인스턴스를 운영하는
|
||||
(또는 MISP 형식을 적재하는 위협 인텔리전스 플랫폼을 쓰는) 방어자는 CSV 열을 손으로 매핑하지 않고
|
||||
지문을 바로 가져올 수 있습니다. STIX 2.1 은 MISP 자체 변환기로 한 번 내보내면 되므로, 저장소가
|
||||
손실 있는 두 번째 형식을 따로 만들지 않습니다.
|
||||
|
||||
- **타입 매핑.** 각 CSV `type` 은 대응하는 MISP 속성 타입이 됩니다: `http.user-agent` →
|
||||
`user-agent`, 가드 마커 `string` → `pattern-in-file`(카테고리 *Artifacts dropped*), `port` →
|
||||
`port`, `ip-dst|port` → `ip-dst|port`(합성 값은 MISP 의 `ip|port` 형식을 쓰므로 `127.0.0.1:8788`
|
||||
은 `127.0.0.1|8788` 로 저장됩니다), 탐색 그래프 스키마 지문 `other` → `other`(카테고리 *Other*).
|
||||
- **`to_ids` 는 `rule` 열을 정직하게 따릅니다.** 탐지 규칙이 세워진 행은 조치 가능한 지표이므로
|
||||
`to_ids: true` 로 표시합니다. 규칙이 없는 호스트 포렌식 행(기본 수신 포트와 루프백 프록시
|
||||
엔드포인트, 그리고 탐색 그래프 스키마 지문)은 차단용 IoC 가 아니라 분류 힌트이므로
|
||||
`to_ids: false` 에 `disable_correlation: true` 로 둡니다(흔한 포트나 `127.0.0.1`, 또는 범용 테이블
|
||||
이름이 MISP 상관을 오염시키면 안 됩니다). 이는 CSV 의 `rule` 열과 아래 유의점이 이미 담고
|
||||
있는 것과 같은 구분입니다.
|
||||
- **가져오기.** [pymisp](https://github.com/MISP/PyMISP)로
|
||||
`MISPEvent().load_file("artex_indicators.misp.json")`, 또는 *Add event → Populate from … → MISP
|
||||
format* UI, 또는 REST API 로 가져옵니다. 이벤트는 미발행 상태이고 `tlp:clear` 태그가 붙어
|
||||
있습니다. 가져올 때 인스턴스에 맞는 배포 범위와 발행 상태를 설정하십시오.
|
||||
|
||||
## 이 목록을 정직하게 읽는 법
|
||||
|
||||
- **이것들은 바뀔 수 있는 지문이지 안전의 증거가 아닙니다.** 운영자가 User-Agent 를 다른 값으로
|
||||
설정하거나 기본 포트를 바꿀 수 있으므로, 여기 있는 어떤 값이 *없다고* 해서 ARTEX 가 없다는 뜻은
|
||||
**아닙니다**. 오래가는 신호는 행동입니다. 상관 규칙과 방어 가이드 1·2·4.1~4.2절을 참조하십시오.
|
||||
- **일반 헌팅 단서는 의도적으로 뺐습니다.** 파괴적 셸·DB 명령(`rm -rf`, `DROP DATABASE`, …)은 ARTEX
|
||||
지문이 *아닙니다*. 정당한 관리자도 실행합니다. 가져오기용 지표가 아니라 헌팅 단서이므로, 이
|
||||
목록이 아니라 [`destructive_command_hunting.yml`](../sigma/destructive_command_hunting.yml)과 방어
|
||||
가이드에 둡니다. 이것들을 차단용 지표로 가져오면 오탐이 생깁니다.
|
||||
- **norma 의 WebFetch User-Agent 는 네트워크 서명이지 가져오기용 원자 지표가 아닙니다.** 워커의
|
||||
페이지 가져오기 도구는 공격 단계에서 `norma/0.4` 를 보내고 Suricata 규칙 sid 1000003 이 `norma/`
|
||||
접두사에 발화하지만, 그 문자열은 norma SDK 에 하드코딩된 자체 User-Agent(`github.com/Autumn-27/norma/tool/webfetch.go`)여서
|
||||
norma 위에 세운 모든 도구가 똑같이 내보내는 값이지 ARTEX 고유 지문이 아닙니다. 이 값을 차단용
|
||||
지표로 이 목록에 넣으면 모든 norma SDK 트래픽에 경보가 울리는데, 이는 파괴적 명령을 뺀 것과 같은
|
||||
오탐 함정입니다. 그래서 norma UA 는 이 목록에서 의도적으로 빼고 네트워크 규칙으로만 싣습니다
|
||||
([`../suricata/README.ko.md`](../suricata/README.ko.md), sid 1000003). 또한 이 값은 이 저장소의
|
||||
소스가 아니라 고정된 의존성(`github.com/Autumn-27/norma`)에 근거를 두므로, 아래의 근거 테스트가
|
||||
ARTEX 자신이 내보내는 문자열을 다시 읽듯이 이 값을 다시 읽을 수는 없습니다.
|
||||
- **호스트 포렌식 포트는 차단이 아니라 분류용입니다.** `:8787` 과 `127.0.0.1:8788` 은 ARTEX 를
|
||||
돌리고 있을 수 있는 호스트를 가리킵니다. `ss`·`netstat` 로 확인하고, 맹목적으로 방화벽을 걸지
|
||||
마십시오.
|
||||
- **탐색 그래프 스키마 지문은 네트워크·파일 IoC 가 아니라 DB 조사용입니다.** `exploration_nodes`
|
||||
테이블은 ARTEX 가 PostgreSQL 에 두는 탐색 그래프의 핵심 테이블입니다. 단독 적중으로 단정하지
|
||||
말고, 형제 테이블(`exploration_edges`·`exploration_anchors`·`assets`·`companies`·`activity`)과
|
||||
`agent_prompts` 시드가 같은 데이터베이스에 함께 있는지로 확인하십시오. 운영자가 테이블을 바꾸거나
|
||||
지울 수 있으므로 부재가 안전을 뜻하지는 않습니다.
|
||||
- **`rule` 이 비어 있는 호스트·DB 행에는 실행기가 있습니다.** Sigma 규칙으로 싣지 않고 직접 분류하는 세
|
||||
지표, 곧 리슨 포트·기록 프록시 엔드포인트·이 스키마 지문은 [호스트 분류 스크립트](../triage/)가 의심
|
||||
호스트에서 모두 점검합니다. 그래서 셸 접근은 있으나 SIEM 이 없는 대응자가 `ss`·`netstat`·`psql`
|
||||
을 손으로 돌리지 않아도 됩니다.
|
||||
|
||||
## 검증
|
||||
|
||||
이 목록은 [지표 근거(source-of-truth) 테스트](../tests/indicators/run.sh)가 덮습니다. 이 CSV 를 다시
|
||||
읽어 모든 행에 대해, 그 값이 인용한 소스 파일에 여전히 있고 인용한 규칙에 고정돼 있는지, 그리고
|
||||
테스트가 근거로 삼는 모든 지표가 목록에 나타나는지 단언합니다. 소스에서 어긋난 행이나 목록에서 빠진
|
||||
알려진 지문이 있으면 테스트가 실패합니다. 다음으로 돌리십시오.
|
||||
|
||||
```sh
|
||||
detections/tests/indicators/run.sh
|
||||
```
|
||||
|
||||
MISP 이벤트는 자체 [MISP 내보내기 일관성 테스트](../tests/misp/run.sh)가 덮습니다. 이벤트를 pymisp
|
||||
로 적재해(모든 속성 타입이 서버가 받아들이는 실재 MISP 타입이 되도록) 이 CSV 와 행 단위로
|
||||
동기화됨을 단언합니다. 곧 같은 값, 의도한 타입·카테고리, 그리고 `rule` 열에 맞춘 `to_ids` 플래그입니다.
|
||||
이벤트는 CSV 와 나란히 손으로 관리합니다. CSV 가 지니지 않는, 속성별로 정리한 주석·안정적인
|
||||
UUID·이벤트 수준 태그도 함께 지니므로, 손실 있는 기본값으로 이것들을 덮어쓸 생성기가 없습니다.
|
||||
CSV 행을 더하거나 빼거나 타입을 바꿀 때는 같은 커밋에서
|
||||
[`artex_indicators.misp.json`](artex_indicators.misp.json)도 맞춰 고치십시오(새 속성에는 새 `uuid` 와
|
||||
근거가 되는 `comment` 를 주십시오). 둘이 일치할 때까지 이 테스트가 실패하므로, 갱신을 조용히 잊을
|
||||
수 없습니다. 다음으로 돌리십시오.
|
||||
|
||||
```sh
|
||||
detections/tests/misp/run.sh
|
||||
```
|
||||
@@ -0,0 +1,116 @@
|
||||
# ARTEX indicators (machine-readable)
|
||||
|
||||
English · [한국어](README.ko.md)
|
||||
|
||||
> 한국어: [`artex_indicators.csv`](artex_indicators.csv) 는 ARTEX 가 실제로 내보내는 고유 지문(침해지표,
|
||||
> IoC)을 한 파일로 모은 것입니다. 위협 인텔리전스 플랫폼·SIEM 조회 테이블·호스트 분류 작업에 바로
|
||||
> 넣을 수 있게 기계가 읽는 CSV 로 둡니다. 모든 값은 이 저장소 소스에서 확인한 문자열이며, 각 행의
|
||||
> 출처 파일과 탐지 규칙을 함께 적습니다. 배경 설명은 [방어·탐지 가이드(docs/defense-ko.md)](../../docs/defense-ko.md)
|
||||
> 2절 "방어자가 관측할 수 있는 지문"에 있습니다. 자신이 소유하거나 서면 허가를 받은 시스템을 지키는
|
||||
> **방어·탐지 목적에만** 사용하십시오. 한국어 전체 문서는 **[README.ko.md](README.ko.md)** 를
|
||||
> 보십시오.
|
||||
|
||||
A single, machine-readable list of the unique fingerprints ARTEX itself emits, for defenders who want the
|
||||
atomic indicators rather than the detection logic: drop [`artex_indicators.csv`](artex_indicators.csv)
|
||||
into a threat-intelligence platform, a SIEM lookup table, or a host-triage checklist. Every value is a
|
||||
string verified in this repository's source — the same grounding the
|
||||
[detection rules](../README.md) and the defense guide
|
||||
([Korean](../../docs/defense-ko.md) · [English](../../docs/defense-en.md), section 2) rely on — and each
|
||||
row records where it comes from and which rule (if any) is built on it.
|
||||
|
||||
## Columns
|
||||
|
||||
- **`id`** — a stable slug for the indicator.
|
||||
- **`type`** — the kind of indicator: `http.user-agent`, `string` (a literal to hunt for in logs/files),
|
||||
`port`, `ip-dst|port`, or `other` (a host artifact that fits none of the above, e.g. a database schema
|
||||
object name). These map onto the equivalent MISP/STIX attribute types.
|
||||
- **`value`** — the exact indicator. Preserved verbatim, including the non-ASCII guard marker.
|
||||
- **`perspective`** — `target` (observable in traffic *toward* a system ARTEX probes) or `forensic`
|
||||
(observable *on* a host where ARTEX ran or was relayed through). The defense guide keeps these apart on
|
||||
purpose; mixing them produces false conclusions.
|
||||
- **`source`** — the repository-relative source file(s) that emit the value, `;`-separated. This is the
|
||||
grounding: if an upstream re-sync changes the emitter, the indicator here must change with it.
|
||||
- **`rule`** — the detection rule(s) built on the exact value, `;`-separated, or empty for host-forensic
|
||||
indicators that are triaged directly rather than shipped as a (noisy) rule.
|
||||
- **`description`** — a one-line note, including the honest caveat where one applies.
|
||||
|
||||
## MISP event export
|
||||
|
||||
The same indicators ship as a ready-to-import [MISP](https://www.misp-project.org/) event,
|
||||
[`artex_indicators.misp.json`](artex_indicators.misp.json), so a defender running a MISP instance (or a
|
||||
threat-intelligence platform that ingests the MISP format) can import the fingerprints directly instead of
|
||||
mapping the CSV columns by hand. STIX 2.1 is then one export away using MISP's own converter, so the
|
||||
repository does not hand-roll a second, lossy format.
|
||||
|
||||
- **Type mapping.** Each CSV `type` becomes the equivalent MISP attribute type: `http.user-agent` →
|
||||
`user-agent`, the guard marker `string` → `pattern-in-file` (category *Artifacts dropped*), `port` →
|
||||
`port`, `ip-dst|port` → `ip-dst|port` (the composite value uses MISP's `ip|port` form, so
|
||||
`127.0.0.1:8788` is stored as `127.0.0.1|8788`), and the exploration-graph schema fingerprint `other` →
|
||||
`other` (category *Other*).
|
||||
- **`to_ids` follows the `rule` column, honestly.** A row that a detection rule is built on is an actionable
|
||||
indicator and is flagged `to_ids: true`. A host-forensic row with no rule — the default listen port, the
|
||||
loopback proxy endpoint, and the exploration-graph schema fingerprint — is a triage hint, not a blocking
|
||||
IoC, so it is `to_ids: false` with `disable_correlation: true` (a common port, `127.0.0.1`, or a generic
|
||||
table name should not pollute MISP correlations). This is the same distinction the CSV `rule` column and
|
||||
the caveats below already carry.
|
||||
- **Import.** `MISPEvent().load_file("artex_indicators.misp.json")` with
|
||||
[pymisp](https://github.com/MISP/PyMISP), the *Add event → Populate from … → MISP format* UI, or the REST
|
||||
API. The event is unpublished and tagged `tlp:clear`; set the distribution and publish state your instance
|
||||
needs on import.
|
||||
|
||||
## How to read this honestly
|
||||
|
||||
- **These are changeable fingerprints, not proof of safety.** An operator can set a different User-Agent
|
||||
or change a default port, so the *absence* of any value here does **not** mean ARTEX is absent. The
|
||||
durable signal is behaviour — see the correlation rules and sections 1, 2, and 4.1–4.2 of the defense
|
||||
guide.
|
||||
- **Generic hunting leads are deliberately excluded.** Destructive shell/DB commands (`rm -rf`, `DROP
|
||||
DATABASE`, …) are *not* ARTEX fingerprints — legitimate administrators run them too. They are a hunting
|
||||
lead, not an import-ready indicator, so they live in
|
||||
[`destructive_command_hunting.yml`](../sigma/destructive_command_hunting.yml) and the defense guide, not
|
||||
in this list. Importing them as blocking indicators would cause false positives.
|
||||
- **The norma WebFetch User-Agent is a wire signature, not an atomic indicator.** The worker's page-fetch
|
||||
tool sends `norma/0.4` during the attack phase, and Suricata sid 1000003 fires on the `norma/` prefix, but
|
||||
that string is the norma SDK's own hardcoded User-Agent (`github.com/Autumn-27/norma/tool/webfetch.go`), shared by every tool built on
|
||||
norma rather than an ARTEX-unique fingerprint. Importing it here as a blocking indicator would alert on all
|
||||
norma-SDK traffic — the same false-positive trap the destructive commands sit in — so it is deliberately
|
||||
kept out of this list and shipped only as the network rule
|
||||
([`../suricata/README.md`](../suricata/README.md), sid 1000003). It is also grounded in a pinned dependency
|
||||
(`github.com/Autumn-27/norma`), not this repository's own source, so the source-of-truth test below cannot
|
||||
re-read it the way it re-reads ARTEX's own emitters.
|
||||
- **Host-forensic ports are for triage, not blocking.** `:8787` and `127.0.0.1:8788` describe a host that
|
||||
may be running ARTEX; check them with `ss`/`netstat`, do not firewall them blindly.
|
||||
- **The exploration-graph schema fingerprint is for DB inspection, not a network/file IoC.** The
|
||||
`exploration_nodes` table is the core of the exploration graph ARTEX keeps in PostgreSQL. Do not conclude
|
||||
from a single hit; confirm that the sibling tables (`exploration_edges`, `exploration_anchors`, `assets`,
|
||||
`companies`, `activity`) and the `agent_prompts` seed sit in the same database. An operator can rename or
|
||||
drop tables, so absence does not mean safety.
|
||||
- **The host/DB rows with no `rule` have a runner.** The three indicators triaged directly rather than
|
||||
shipped as a Sigma rule — the listen ports, the recording-proxy endpoint, and this schema fingerprint —
|
||||
are all checked by the [host-triage script](../triage/) on a suspected host, so a responder with
|
||||
shell access but no SIEM does not have to run `ss`/`netstat`/`psql` by hand.
|
||||
|
||||
## Verification
|
||||
|
||||
The list is covered by the [indicator source-of-truth test](../tests/indicators/run.sh): it re-reads this
|
||||
CSV and asserts, for every row, that the value is still present in the cited source file(s) and pinned in
|
||||
the cited rule(s), and that every indicator the test grounds appears in the list. A row that drifts from
|
||||
the source, or a known fingerprint dropped from the list, fails the test. Run it with:
|
||||
|
||||
```sh
|
||||
detections/tests/indicators/run.sh
|
||||
```
|
||||
|
||||
The MISP event is covered by its own [MISP export consistency test](../tests/misp/run.sh): it loads the
|
||||
event under pymisp (so every attribute type is a real MISP type a server accepts) and asserts it stays
|
||||
row-for-row in sync with this CSV — same values, the intended type/category, and the `to_ids` flag matching
|
||||
the `rule` column. The event is maintained by hand alongside the CSV — it also carries curated per-attribute
|
||||
comments, stable UUIDs, and event-level tags that the CSV does not hold, so there is no generator that would
|
||||
overwrite them with lossy defaults. When you add, remove, or retype a CSV row, edit
|
||||
[`artex_indicators.misp.json`](artex_indicators.misp.json) to match in the same commit (give a new attribute a
|
||||
fresh `uuid` and a grounding `comment`); this test fails until the two agree, so the update cannot be silently
|
||||
forgotten. Run it with:
|
||||
|
||||
```sh
|
||||
detections/tests/misp/run.sh
|
||||
```
|
||||
@@ -0,0 +1,8 @@
|
||||
id,type,value,perspective,source,rule,description
|
||||
enrich-user-agent,http.user-agent,artex-enrich/1.0,target,enrich/enrich.go,detections/sigma/artex_enrich_user_agent.yml,"HTTP User-Agent of ARTEX asset-enrichment probes (short single GET, no redirects, reads only the title). Suricata also matches it by the prefix artex-enrich/. An operator can change it, so absence is not safety."
|
||||
selfupdate-user-agent,http.user-agent,artex-selfupdate,forensic,selfupdate/github.go;selfupdate/stage.go,detections/sigma/artex_selfupdate_egress.yml,"HTTP User-Agent of the self-update egress call to the release host; seen in outbound logs from a host running ARTEX."
|
||||
guard-audit-marker,string,【ARTEX 平台管控·非目标防御】,forensic,guard/guard.go,detections/sigma/artex_guard_audit_framing.yml,"Control-framing prefix written to the audit log on a blocked tool call; its presence in audit records supports an ARTEX-execution finding."
|
||||
server-listen-port,port,8787,forensic,cmd/artex/main.go,,"Default ARTEX server HTTP listen port (flag --addr). An internal host serving its admin UI here warrants triage; best checked on the host with ss or netstat, not as a network rule."
|
||||
recording-proxy-endpoint,ip-dst|port,127.0.0.1:8788,forensic,cmd/artex/main.go,,"Default loopback traffic-recording MITM proxy endpoint (flag --proxy). Check with ss or netstat on a suspected host."
|
||||
recording-proxy-ca,string,mitmproxy-ca-cert.pem,forensic,traffic/traffic.go,detections/sigma/artex_recording_proxy_ca.yml,"MITM CA certificate file the ARTEX recording proxy writes on first start (traffic/traffic.go, under <dir>/_ca/); injected into spawned worker tools via SSL_CERT_FILE/CURL_CA_BUNDLE/REQUESTS_CA_BUNDLE/NODE_EXTRA_CA_CERTS with a loopback HTTP_PROXY. Its presence on a host evidences the recorder having run. The bare filename is shared with standalone go-mitmproxy/mitmproxy, so treat it as a host-triage lead, not a unique fingerprint."
|
||||
postgres-exploration-schema,other,exploration_nodes,forensic,db/schema.sql,,"ARTEX exploration-graph table in its PostgreSQL store (db/schema.sql). With exploration_edges/exploration_anchors/assets/companies/activity and an agent_prompts seed it forms the ARTEX dual-graph schema; their presence together is a strong host-forensic tell. A triage lead checked by inspecting the database, not a network or file IoC, so to_ids is off."
|
||||
|
@@ -0,0 +1,84 @@
|
||||
{
|
||||
"Event": {
|
||||
"uuid": "1a5aa723-0e87-4cbe-97f4-c84f93e4efeb",
|
||||
"info": "ARTEX (autonomous AI pentest framework) — defensive host/network fingerprints",
|
||||
"date": "2026-10-07",
|
||||
"threat_level_id": "4",
|
||||
"analysis": "2",
|
||||
"distribution": "3",
|
||||
"published": false,
|
||||
"Orgc": {
|
||||
"name": "artex-ko",
|
||||
"uuid": "fff4e6e6-a076-433d-9a12-873ff60de4e6"
|
||||
},
|
||||
"Tag": [
|
||||
{ "name": "tlp:clear" },
|
||||
{ "name": "type:OSINT" }
|
||||
],
|
||||
"Attribute": [
|
||||
{
|
||||
"uuid": "cb9d8f4e-cef3-44a4-8499-457620861b74",
|
||||
"type": "user-agent",
|
||||
"category": "Network activity",
|
||||
"to_ids": true,
|
||||
"disable_correlation": false,
|
||||
"value": "artex-enrich/1.0",
|
||||
"comment": "ARTEX asset-enrichment prober User-Agent (enrich/enrich.go). Target-side. An operator can change it, so absence is not safety. Sigma: artex_enrich_user_agent.yml."
|
||||
},
|
||||
{
|
||||
"uuid": "dbe975a6-0a12-43a7-a8e8-4bd0ba65daea",
|
||||
"type": "user-agent",
|
||||
"category": "Network activity",
|
||||
"to_ids": true,
|
||||
"disable_correlation": false,
|
||||
"value": "artex-selfupdate",
|
||||
"comment": "ARTEX self-update egress User-Agent to the release host (selfupdate/github.go, selfupdate/stage.go). Seen in outbound logs from an ARTEX host. Sigma: artex_selfupdate_egress.yml."
|
||||
},
|
||||
{
|
||||
"uuid": "053cbbbd-c345-49f0-b6e3-1b6f6075a218",
|
||||
"type": "pattern-in-file",
|
||||
"category": "Artifacts dropped",
|
||||
"to_ids": true,
|
||||
"disable_correlation": false,
|
||||
"value": "【ARTEX 平台管控·非目标防御】",
|
||||
"comment": "Control-framing prefix ARTEX writes to its audit log on a blocked tool call (guard/guard.go). Its presence in audit records supports an ARTEX-execution finding. Sigma: artex_guard_audit_framing.yml."
|
||||
},
|
||||
{
|
||||
"uuid": "d5fe7761-c297-4e35-acfe-a3a4a5f01f7b",
|
||||
"type": "port",
|
||||
"category": "Network activity",
|
||||
"to_ids": false,
|
||||
"disable_correlation": true,
|
||||
"value": "8787",
|
||||
"comment": "Default ARTEX server HTTP listen port (cmd/artex/main.go --addr). Host-triage hint, not a blocking indicator; check with ss/netstat on a suspected host."
|
||||
},
|
||||
{
|
||||
"uuid": "b575c98a-629d-42d4-bac0-3280f6c6c6b8",
|
||||
"type": "ip-dst|port",
|
||||
"category": "Network activity",
|
||||
"to_ids": false,
|
||||
"disable_correlation": true,
|
||||
"value": "127.0.0.1|8788",
|
||||
"comment": "Default loopback traffic-recording MITM proxy endpoint (cmd/artex/main.go --proxy). Loopback — a host-triage hint, not a network block; check with ss/netstat."
|
||||
},
|
||||
{
|
||||
"uuid": "7628f0dc-d5f8-45ea-8aec-64843667658e",
|
||||
"type": "pattern-in-file",
|
||||
"category": "Artifacts dropped",
|
||||
"to_ids": true,
|
||||
"disable_correlation": false,
|
||||
"value": "mitmproxy-ca-cert.pem",
|
||||
"comment": "MITM CA certificate file the ARTEX recording proxy writes on first start (traffic/traffic.go, under <dir>/_ca/); injected into spawned tools via SSL_CERT_FILE/CURL_CA_BUNDLE/REQUESTS_CA_BUNDLE/NODE_EXTRA_CA_CERTS with a loopback HTTP_PROXY. Evidences the recorder having run; the bare filename is shared with standalone mitmproxy, so it is a host-triage lead. Sigma: artex_recording_proxy_ca.yml."
|
||||
},
|
||||
{
|
||||
"uuid": "134f14d2-0af0-4a4b-89bb-805ab5f2b1a7",
|
||||
"type": "other",
|
||||
"category": "Other",
|
||||
"to_ids": false,
|
||||
"disable_correlation": true,
|
||||
"value": "exploration_nodes",
|
||||
"comment": "ARTEX exploration-graph table in its PostgreSQL store (db/schema.sql); with exploration_edges/exploration_anchors/assets/companies/activity and an agent_prompts seed it forms the ARTEX dual-graph schema. Host-triage lead checked by inspecting the database, not a blocking IoC."
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user