Files
artex/detections/sigma/artex_selfupdate_egress.yml
T
dela 0335d572de
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
First Commit
2026-10-09 08:38:16 +08:00

28 lines
1.1 KiB
YAML

title: ARTEX Self-Update Egress User-Agent
id: e96380a3-2a34-4237-be2b-088ad9cc947d
status: experimental
description: |
Detects outbound (egress) HTTP requests whose User-Agent is "artex-selfupdate", used by the
ARTEX self-update routine when it queries code-repository hosts (for example GitHub releases)
for a newer binary. Seeing this User-Agent leave an internal host toward a code-hosting
service suggests an ARTEX binary is installed on that host. This is primarily an operator and
forensic indicator on a (possibly compromised relay) host, not a target-side signal.
references:
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
- https://github.com/jiwoochris/artex-ko
author: artex-ko defense guide
date: 2026-10-05
tags:
- attack.command-and-control
- attack.t1105
logsource:
category: proxy
detection:
selection:
c-useragent: 'artex-selfupdate'
condition: selection
falsepositives:
- Unlikely; this User-Agent string is specific to the ARTEX self-update client.
level: medium