{ "name": "ARTEX detection coverage", "versions": { "attack": "16", "navigator": "5.1.0", "layer": "4.5" }, "domain": "enterprise-attack", "description": "MITRE ATT&CK (Enterprise) coverage of the ARTEX detection rules in this repository (detections/sigma, detections/suricata). Every technique below is drawn from the attack.* tags of a rule whose indicator is grounded in this repository's source; nothing is inferred. Score reflects detection strength: 100 = ARTEX-specific signature or behaviour, 50-65 = generic hunting lead that also catches legitimate administration. Maintained by hand from those tags and checked for rule<->layer consistency by detections/tests/attack/run.sh.", "filters": { "platforms": [ "PRE", "Windows", "Linux", "macOS", "Network", "Containers" ] }, "sorting": 0, "layout": { "layout": "side", "aggregateFunction": "average", "showID": true, "showName": true, "showAggregateScores": false, "countUnscored": false, "expandedSubtechniques": "annotated" }, "hideDisabled": false, "techniques": [ { "techniqueID": "T1595", "tactic": "reconnaissance", "score": 100, "comment": "ARTEX asset-enrichment probe (User-Agent artex-enrich/1.0). sigma/artex_enrich_user_agent.yml; behaviour via sigma/correlation/artex_enrich_scan_velocity.yml and artex_enrich_fanout.yml; network via suricata sid 1000001/1000002. Defense guide section 2 (target view), 4.1, 4.4.", "enabled": true, "showSubtechniques": false }, { "techniqueID": "T1592", "tactic": "reconnaissance", "score": 100, "comment": "ARTEX auto-enrichment gathers victim host info (DNS/HTTP, reads