First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
# references base rule: ../artex_enrich_user_agent.yml (ARTEX Asset Enrichment Probe User-Agent)
|
||||
title: ARTEX Enrichment Fan-Out (One Source, Many Distinct Hosts)
|
||||
id: 6fba3b7c-1dd9-4e18-bf55-d93fc1d2e2e0
|
||||
status: experimental
|
||||
description: |
|
||||
Correlates a single client carrying the ARTEX enrichment User-Agent to many DISTINCT
|
||||
destination hosts within a short window (distinct count of cs-host). Autonomous enrichment
|
||||
fans out across an asset list at machine speed, so breadth — the number of different hosts
|
||||
touched, not just request volume — is what separates it from a person browsing a few pages.
|
||||
Evaluate this where your telemetry spans multiple hosts (CDN, WAF, reverse proxy, or shared
|
||||
hosting) or at an egress point that sees outbound enrichment. As with the base rule, the
|
||||
User-Agent can be changed; the durable signal is the fan-out behaviour, so pair this with the
|
||||
defense guide section 4 and tune the distinct-host threshold and window to your environment.
|
||||
references:
|
||||
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
|
||||
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
|
||||
- https://github.com/jiwoochris/artex-ko
|
||||
author: artex-ko defense guide
|
||||
date: 2026-10-05
|
||||
tags:
|
||||
- attack.reconnaissance
|
||||
- attack.t1595
|
||||
- attack.t1592
|
||||
correlation:
|
||||
type: value_count
|
||||
rules:
|
||||
- 34adfa15-1696-4322-afc0-f69988e9cc1e
|
||||
group-by:
|
||||
- c-ip
|
||||
timespan: 10m
|
||||
condition:
|
||||
gte: 20
|
||||
field: cs-host
|
||||
falsepositives:
|
||||
- Shared egress (NAT/proxy) where many users appear as one source; a legitimate scanner or
|
||||
uptime monitor that fronts many hosts. Allow-list known sources and raise the threshold.
|
||||
level: high
|
||||
Reference in New Issue
Block a user