id,type,value,perspective,source,rule,description enrich-user-agent,http.user-agent,artex-enrich/1.0,target,enrich/enrich.go,detections/sigma/artex_enrich_user_agent.yml,"HTTP User-Agent of ARTEX asset-enrichment probes (short single GET, no redirects, reads only the title). Suricata also matches it by the prefix artex-enrich/. An operator can change it, so absence is not safety." selfupdate-user-agent,http.user-agent,artex-selfupdate,forensic,selfupdate/github.go;selfupdate/stage.go,detections/sigma/artex_selfupdate_egress.yml,"HTTP User-Agent of the self-update egress call to the release host; seen in outbound logs from a host running ARTEX." guard-audit-marker,string,【ARTEX 平台管控·非目标防御】,forensic,guard/guard.go,detections/sigma/artex_guard_audit_framing.yml,"Control-framing prefix written to the audit log on a blocked tool call; its presence in audit records supports an ARTEX-execution finding." server-listen-port,port,8787,forensic,cmd/artex/main.go,,"Default ARTEX server HTTP listen port (flag --addr). An internal host serving its admin UI here warrants triage; best checked on the host with ss or netstat, not as a network rule." recording-proxy-endpoint,ip-dst|port,127.0.0.1:8788,forensic,cmd/artex/main.go,,"Default loopback traffic-recording MITM proxy endpoint (flag --proxy). Check with ss or netstat on a suspected host." recording-proxy-ca,string,mitmproxy-ca-cert.pem,forensic,traffic/traffic.go,detections/sigma/artex_recording_proxy_ca.yml,"MITM CA certificate file the ARTEX recording proxy writes on first start (traffic/traffic.go, under