ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
32 lines
1.4 KiB
YAML
32 lines
1.4 KiB
YAML
title: ARTEX Asset Enrichment Probe User-Agent
|
|
id: 34adfa15-1696-4322-afc0-f69988e9cc1e
|
|
status: experimental
|
|
description: |
|
|
Detects inbound HTTP requests whose User-Agent is "artex-enrich/1.0", set by the ARTEX
|
|
autonomous penetration-testing framework when it auto-enriches assets (DNS/HTTP checks)
|
|
and reads a target's <title>. This probe is generated by ARTEX itself, independent of the
|
|
LLM: it does not follow redirects, disables keep-alive, and reads only the beginning of the
|
|
response. Default concurrency is 4, so several assets may be probed at once. An operator can
|
|
change this User-Agent, so its ABSENCE does not imply safety. Treat it as a supporting
|
|
indicator and combine it with the behaviour-based detection in the defense guide, section 4.
|
|
references:
|
|
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
|
|
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
|
|
- https://github.com/jiwoochris/artex-ko
|
|
author: artex-ko defense guide
|
|
date: 2026-10-05
|
|
tags:
|
|
- attack.reconnaissance
|
|
- attack.t1595
|
|
- attack.t1592
|
|
logsource:
|
|
category: webserver
|
|
detection:
|
|
selection:
|
|
cs-user-agent: 'artex-enrich/1.0'
|
|
condition: selection
|
|
falsepositives:
|
|
- Unlikely; this User-Agent string is specific to the ARTEX enrichment client, but an
|
|
operator who changed it will not be caught here.
|
|
level: high
|