First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s

This commit is contained in:
dela
2026-10-09 08:38:16 +08:00
commit 0335d572de
756 changed files with 201663 additions and 0 deletions
@@ -0,0 +1,31 @@
title: ARTEX Asset Enrichment Probe User-Agent
id: 34adfa15-1696-4322-afc0-f69988e9cc1e
status: experimental
description: |
Detects inbound HTTP requests whose User-Agent is "artex-enrich/1.0", set by the ARTEX
autonomous penetration-testing framework when it auto-enriches assets (DNS/HTTP checks)
and reads a target's <title>. This probe is generated by ARTEX itself, independent of the
LLM: it does not follow redirects, disables keep-alive, and reads only the beginning of the
response. Default concurrency is 4, so several assets may be probed at once. An operator can
change this User-Agent, so its ABSENCE does not imply safety. Treat it as a supporting
indicator and combine it with the behaviour-based detection in the defense guide, section 4.
references:
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
- https://github.com/jiwoochris/artex-ko
author: artex-ko defense guide
date: 2026-10-05
tags:
- attack.reconnaissance
- attack.t1595
- attack.t1592
logsource:
category: webserver
detection:
selection:
cs-user-agent: 'artex-enrich/1.0'
condition: selection
falsepositives:
- Unlikely; this User-Agent string is specific to the ARTEX enrichment client, but an
operator who changed it will not be caught here.
level: high