Files
artex/detections/attack
dela 0335d572de
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
First Commit
2026-10-09 08:38:16 +08:00
..
2026-10-09 08:38:16 +08:00
2026-10-09 08:38:16 +08:00
2026-10-09 08:38:16 +08:00

ARTEX ATT&CK coverage

English · 한국어

한국어: 이 디렉터리는 ../의 ARTEX 탐지 규칙(Sigma·Suricata)이 다루는 공격 기법을 MITRE ATT&CK 전술·기법으로 정리한 커버리지 레이어입니다. 각 기법은 저장소 소스에 근거가 있는 규칙의 attack.* 태그에서만 가져왔고, 추정으로 넣은 항목은 없습니다. ATT&CK Navigator에 그대로 올려 어떤 ARTEX 행위에 어떤 규칙이 걸리는지 한눈에 볼 수 있습니다. 이 레이어는 자신이 소유하거나 서면 허가를 받은 시스템을 지키는 방어·탐지 목적에만 쓰십시오. 한국어 전체 문서는 README.ko.md 를 보십시오.

A MITRE ATT&CK Navigator layer that maps the detection rules in this repository to the ATT&CK (Enterprise) techniques they tag. It is built by hand from the attack.* tags on the Sigma rules — every technique is grounded in a rule whose indicator is a string or behaviour verified in this repository's source, and the consistency test keeps the layer and the rules from drifting apart.

  • artex_navigator_layer.json — the layer, in ATT&CK Navigator v4.5 format.

What the score means

Coverage here means "this repository ships a detection that tags this technique", not "this technique is fully covered". The score is deliberately honest about detection strength:

  • 100 — ARTEX-specific signature or behaviour. A static indicator unique to ARTEX (the artex-enrich/1.0 / artex-selfupdate User-Agents, the guard audit marker) or a behaviour rule built on one (enrichment velocity / fan-out, guard-block burst).
  • 50–65 — generic hunting lead. Destructive-command hunting mirrored from the ARTEX guard deny list. The same commands are run by legitimate administrators, so these fire on benign activity too; treat a hit as a lead, not an attribution. 65 marks the case where a correlation rule raises specificity by pairing the command with the ARTEX guard marker.

Techniques covered

Eight techniques across six tactics. Each maps to the rule(s) that tag it:

How to use it

  1. Open the ATT&CK Navigator.
  2. Choose Open Existing Layer → Upload from local, and select artex_navigator_layer.json (or point it at the raw file URL from this repository).
  3. The scored techniques appear colour-graded by detection strength, each with a comment naming the rule file(s) and the defense-guide section behind it.

Scope and honesty

  • Coverage is not completeness. A technique scored here means a rule tags it, not that every variant of the technique is detected. Only two ARTEX-unique User-Agents are visible on the wire — the enrichment prober (artex-enrich/1.0) in the reconnaissance phase and the norma SDK WebFetch tool (norma/0.4) in the attack phase — while the rest of the attack traffic follows tool-default fingerprints; the durable detection is behavioural (see the defense guide, Korean · English, sections 1–2 and 4.1–4.2). The pure web multi-stage case still needs base rules specific to your environment.
  • Static indicators can be changed. An operator can set a different User-Agent, so the absence of a tagged indicator does not imply safety. This is the same caveat the rule files carry.

Validate and contribute

Run the consistency test — it needs only Docker and asserts that the layer's scored techniques and tactics are exactly the attack.* tags on the rules, with every technique grounded in a rule file that exists:

detections/tests/attack/run.sh

When you add or retag a rule, update this layer to match — the test fails if a rule technique is missing from the layer or a layer technique is absent from the rules. See ../README.md and ../../CONTRIBUTING.en.md.