title: ARTEX Asset Enrichment Probe User-Agent
id: 34adfa15-1696-4322-afc0-f69988e9cc1e
status: experimental
description: |
Detects inbound HTTP requests whose User-Agent is "artex-enrich/1.0", set by the ARTEX
autonomous penetration-testing framework when it auto-enriches assets (DNS/HTTP checks)
and reads a target's
. This probe is generated by ARTEX itself, independent of the
LLM: it does not follow redirects, disables keep-alive, and reads only the beginning of the
response. Default concurrency is 4, so several assets may be probed at once. An operator can
change this User-Agent, so its ABSENCE does not imply safety. Treat it as a supporting
indicator and combine it with the behaviour-based detection in the defense guide, section 4.
references:
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
- https://github.com/jiwoochris/artex-ko
author: artex-ko defense guide
date: 2026-10-05
tags:
- attack.reconnaissance
- attack.t1595
- attack.t1592
logsource:
category: webserver
detection:
selection:
cs-user-agent: 'artex-enrich/1.0'
condition: selection
falsepositives:
- Unlikely; this User-Agent string is specific to the ARTEX enrichment client, but an
operator who changed it will not be caught here.
level: high