Files
dela 0335d572de
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
First Commit
2026-10-09 08:38:16 +08:00

2.3 KiB

1idtypevalueperspectivesourceruledescription
2enrich-user-agenthttp.user-agentartex-enrich/1.0targetenrich/enrich.godetections/sigma/artex_enrich_user_agent.ymlHTTP User-Agent of ARTEX asset-enrichment probes (short single GET, no redirects, reads only the title). Suricata also matches it by the prefix artex-enrich/. An operator can change it, so absence is not safety.
3selfupdate-user-agenthttp.user-agentartex-selfupdateforensicselfupdate/github.go;selfupdate/stage.godetections/sigma/artex_selfupdate_egress.ymlHTTP User-Agent of the self-update egress call to the release host; seen in outbound logs from a host running ARTEX.
4guard-audit-markerstring【ARTEX 平台管控·非目标防御】forensicguard/guard.godetections/sigma/artex_guard_audit_framing.ymlControl-framing prefix written to the audit log on a blocked tool call; its presence in audit records supports an ARTEX-execution finding.
5server-listen-portport8787forensiccmd/artex/main.goDefault ARTEX server HTTP listen port (flag --addr). An internal host serving its admin UI here warrants triage; best checked on the host with ss or netstat, not as a network rule.
6recording-proxy-endpointip-dst|port127.0.0.1:8788forensiccmd/artex/main.goDefault loopback traffic-recording MITM proxy endpoint (flag --proxy). Check with ss or netstat on a suspected host.
7recording-proxy-castringmitmproxy-ca-cert.pemforensictraffic/traffic.godetections/sigma/artex_recording_proxy_ca.ymlMITM CA certificate file the ARTEX recording proxy writes on first start (traffic/traffic.go, under <dir>/_ca/); injected into spawned worker tools via SSL_CERT_FILE/CURL_CA_BUNDLE/REQUESTS_CA_BUNDLE/NODE_EXTRA_CA_CERTS with a loopback HTTP_PROXY. Its presence on a host evidences the recorder having run. The bare filename is shared with standalone go-mitmproxy/mitmproxy, so treat it as a host-triage lead, not a unique fingerprint.
8postgres-exploration-schemaotherexploration_nodesforensicdb/schema.sqlARTEX exploration-graph table in its PostgreSQL store (db/schema.sql). With exploration_edges/exploration_anchors/assets/companies/activity and an agent_prompts seed it forms the ARTEX dual-graph schema; their presence together is a strong host-forensic tell. A triage lead checked by inspecting the database, not a network or file IoC, so to_ids is off.