ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
2.3 KiB
2.3 KiB
| 1 | id | type | value | perspective | source | rule | description |
|---|---|---|---|---|---|---|---|
| 2 | enrich-user-agent | http.user-agent | artex-enrich/1.0 | target | enrich/enrich.go | detections/sigma/artex_enrich_user_agent.yml | HTTP User-Agent of ARTEX asset-enrichment probes (short single GET, no redirects, reads only the title). Suricata also matches it by the prefix artex-enrich/. An operator can change it, so absence is not safety. |
| 3 | selfupdate-user-agent | http.user-agent | artex-selfupdate | forensic | selfupdate/github.go;selfupdate/stage.go | detections/sigma/artex_selfupdate_egress.yml | HTTP User-Agent of the self-update egress call to the release host; seen in outbound logs from a host running ARTEX. |
| 4 | guard-audit-marker | string | 【ARTEX 平台管控·非目标防御】 | forensic | guard/guard.go | detections/sigma/artex_guard_audit_framing.yml | Control-framing prefix written to the audit log on a blocked tool call; its presence in audit records supports an ARTEX-execution finding. |
| 5 | server-listen-port | port | 8787 | forensic | cmd/artex/main.go | Default ARTEX server HTTP listen port (flag --addr). An internal host serving its admin UI here warrants triage; best checked on the host with ss or netstat, not as a network rule. | |
| 6 | recording-proxy-endpoint | ip-dst|port | 127.0.0.1:8788 | forensic | cmd/artex/main.go | Default loopback traffic-recording MITM proxy endpoint (flag --proxy). Check with ss or netstat on a suspected host. | |
| 7 | recording-proxy-ca | string | mitmproxy-ca-cert.pem | forensic | traffic/traffic.go | detections/sigma/artex_recording_proxy_ca.yml | MITM CA certificate file the ARTEX recording proxy writes on first start (traffic/traffic.go, under <dir>/_ca/); injected into spawned worker tools via SSL_CERT_FILE/CURL_CA_BUNDLE/REQUESTS_CA_BUNDLE/NODE_EXTRA_CA_CERTS with a loopback HTTP_PROXY. Its presence on a host evidences the recorder having run. The bare filename is shared with standalone go-mitmproxy/mitmproxy, so treat it as a host-triage lead, not a unique fingerprint. |
| 8 | postgres-exploration-schema | other | exploration_nodes | forensic | db/schema.sql | ARTEX exploration-graph table in its PostgreSQL store (db/schema.sql). With exploration_edges/exploration_anchors/assets/companies/activity and an agent_prompts seed it forms the ARTEX dual-graph schema; their presence together is a strong host-forensic tell. A triage lead checked by inspecting the database, not a network or file IoC, so to_ids is off. |