Files
artex/detections/sigma/artex_guard_audit_framing.yml
T
dela 0335d572de
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
First Commit
2026-10-09 08:38:16 +08:00

28 lines
1.1 KiB
YAML

title: ARTEX Platform Guard Audit-Log Framing
id: 3add497e-36cb-47c4-8993-df8f98585ef7
status: experimental
description: |
Detects the control-framing string the ARTEX platform guard writes to its audit log when it
blocks a tool call. Blocked calls are recorded with a message beginning with the literal
marker shown below (ARTEX platform control, non-target defence). Finding this marker in a
host's application or audit logs strongly supports that ARTEX ran on that host. This is a
host and forensic indicator, not a target-side signal.
references:
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
- https://github.com/jiwoochris/artex-ko
author: artex-ko defense guide
date: 2026-10-05
tags:
- attack.execution
- attack.t1059
logsource:
category: application
detection:
keywords:
- '【ARTEX 平台管控·非目标防御】'
condition: keywords
falsepositives:
- Logs that quote this defense guide or the ARTEX source code for documentation purposes.
level: high