title: ARTEX Asset Enrichment Probe User-Agent id: 34adfa15-1696-4322-afc0-f69988e9cc1e status: experimental description: | Detects inbound HTTP requests whose User-Agent is "artex-enrich/1.0", set by the ARTEX autonomous penetration-testing framework when it auto-enriches assets (DNS/HTTP checks) and reads a target's . This probe is generated by ARTEX itself, independent of the LLM: it does not follow redirects, disables keep-alive, and reads only the beginning of the response. Default concurrency is 4, so several assets may be probed at once. An operator can change this User-Agent, so its ABSENCE does not imply safety. Treat it as a supporting indicator and combine it with the behaviour-based detection in the defense guide, section 4. references: - https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md - https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md - https://github.com/jiwoochris/artex-ko author: artex-ko defense guide date: 2026-10-05 tags: - attack.reconnaissance - attack.t1595 - attack.t1592 logsource: category: webserver detection: selection: cs-user-agent: 'artex-enrich/1.0' condition: selection falsepositives: - Unlikely; this User-Agent string is specific to the ARTEX enrichment client, but an operator who changed it will not be caught here. level: high