First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s

This commit is contained in:
dela
2026-10-09 08:38:16 +08:00
commit 0335d572de
756 changed files with 201663 additions and 0 deletions
@@ -0,0 +1,37 @@
title: ARTEX Recording-Proxy MITM CA Certificate Artifact
id: 3bac40a5-a780-4d1f-a7e8-5d0daa29ef47
status: experimental
description: |
Detects creation of the man-in-the-middle certificate-authority file the ARTEX recording proxy writes
when it starts. ARTEX embeds a go-mitmproxy traffic recorder that decrypts and logs every HTTP(S)
exchange its worker tools make; on first start the recorder generates a CA under its data directory
(traffic/traffic.go writes "<dir>/_ca/mitmproxy-ca-cert.pem") and injects it into spawned tools through
SSL_CERT_FILE / CURL_CA_BUNDLE / REQUESTS_CA_BUNDLE / NODE_EXTRA_CA_CERTS together with an
HTTP(S)_PROXY pointing at the loopback recorder (agent/worker.go). The file appearing on a host is a
forensic artifact of that recording proxy having run: an adversary-in-the-middle traffic recorder
(ATT&CK T1557) whose trust anchor is an installed root certificate. The "_ca/mitmproxy-ca-cert.pem"
layout narrows it to ARTEX's data directory; a bare mitmproxy-ca-cert.pem is shared with standalone
go-mitmproxy / mitmproxy, so treat a hit as a host-triage lead to correlate with the loopback proxy
endpoint and server port (see the indicators list), not a standalone alert.
references:
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
- https://github.com/jiwoochris/artex-ko
author: artex-ko defense guide
date: 2026-10-07
tags:
- attack.credential-access
- attack.collection
- attack.t1557
logsource:
category: file_event
detection:
selection:
TargetFilename|contains|all:
- '_ca'
- 'mitmproxy-ca-cert.pem'
condition: selection
falsepositives:
- Standalone go-mitmproxy or mitmproxy deployments that write the same CA filename.
- Developers intentionally running a recording or debugging proxy on the host.
level: medium