Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Adversarial-Detection-Engineering-Framework — A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses. | Kitploit
Outils/GitHubGitHub/adversarial-detection-engineering/adversarial-detection-engineering-framework
Defensive ToolsVulnerability AnalysisIDS/IPS EvasionPenetration TestingThreat IntelligenceLearning & EducationRed TeamingIncident ResponseCurated Resources
Log Analysis
GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

Adversarial-Detection-Engineering-Framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses.

Voir le dépôt
59820il y a 1 jourVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Adversarial Detection Engineering (ADE) Framework

Author GitHub Last Commit GitHub License

Get ahead of False Negatives by understanding how detection logic fails before threat actors abuse it.

Check out the website: https://adeframework.org/

What Is ADE?

Adversarial Detection Engineering (ADE) is the discipline of reasoning about False Negatives in detection rules. The ADE Framework provides a modern open-source formalization of Detection Logic Bugs - mismatches between what a detection rule intends to detect and what it actually detects.

The ADE Advantage

Instead of waiting for real-world False Negatives, detection engineers can proactively ask:

"What variations would cause this rule's detection logic to miss what it was intended to catch?"

This adversarial line of reasoning mirrors how threat actors can abuse weaknesses in detection logic.

Key Features

  • ✅ Identify reproducible detection logic bugs and map them to formal ADE categories
  • ✅ Embed an attacker's mental model into how detection logic is designed and reviewed
  • ✅ Expose structural weaknesses in rules used for hunts or production MDR tooling (SIEM, XDR, EDR)
  • ✅ Equip security teams with actionable detection logic bug intelligence
  • ✅ Get ahead of False Negatives before threat actors discover and exploit them

ADE Purpose

The purpose of ADE is not to force perfection in design, although that is an ideal goal - but to raise awareness and track limitations, even if intentional:

  • ADE is not about demanding perfect detection rules; it is about making the risk of false-negatives visible.
  • Many rules intentionally contain limitations due to scope, signal quality, or operational constraints, and these may still be mapped to ADE bug types without being “wrong.”
  • ADE provides a shared way to document, accept, mitigate, or compensate for those risks across a ruleset, rather than judging individual rules in isolation.

ADE link to Detection Logic Exposures (DLE)

  • ADE supplies a canonical taxonomy and bug classes for detection logic bugs.
  • DLE provides a recognized list of publically disclosed bypasses with ADE mappings.

Quick Start

New to ADE? Start here:

  1. Introduction - Understand what ADE is and why it matters
  2. Core Concepts - Learn the foundational terminology
  3. Quick Start Guide - Apply ADE to your first detection rule
  4. Bug Likelihood Test - Quick checklist to assess rules for bugs

Ready to dive deep?

  • Detection Logic Bug Theory - Formal foundations
  • Taxonomy Overview - All bug categories
  • Examples - Real-world examples

ADE Detection Logic Bug Taxonomy

The framework identifies 4 major categories and 16 subcategories of detection logic bugs:

🌳 ADE1 – Reformatting in Actions
    ├─ ADE1-01 Substring Manipulation
    └─ ADE1-02 Normalization Asymmetry

🌳 ADE2 – Omit Alternatives
    ├─ ADE2-01 Method/Binary
    ├─ ADE2-02 Versioning
    ├─ ADE2-03 Locations
    └─ ADE2-04 File Types

🌳 ADE3 – Context Development
    ├─ ADE3-01 Process Cloning
    ├─ ADE3-02 Aggregation Hijacking
    ├─ ADE3-03 Timing and Scheduling
    ├─ ADE3-04 Event Fragmentation
    ├─ ADE3-05 Lineage Spoofing
    └─ ADE3-06 Limit Saturation

🌳 ADE4 – Logic Manipulation
    ├─ ADE4-01 Gate Inversion
    ├─ ADE4-02 Conjunction Inversion
    ├─ ADE4-03 Incorrect Expression
    └─ ADE4-04 Field Mismapping & Semantics

→ Explore the Full Taxonomy

What the Framework Provides

1. Theory of Detection Logic Bugs

Formal definitions and theoretical foundation:

  • What constitutes a detection logic bug
  • How bugs create False Negatives
  • Relationship between scope and detection logic
  • Concept of Rule Bypasses

2. Formal Bug Taxonomy

Comprehensive classification with clear terminology:

  • 4 major categories
  • 16 detailed subcategories
  • Consistent labeling system (ADE1-01, ADE2-01, etc.)
  • Mapping to real-world detection rules

3. Real-World Examples

Concrete examples from production rulesets:

  • Sigma detection rules
  • Microsoft Sentinel analytics
  • Elastic Security SIEM & EDR rules

Example Categories:

  • ADE1 Examples - String manipulation bypasses
  • ADE2 Examples - Omitted alternatives
  • ADE3 Examples - Context development
  • ADE4 Examples - Logic manipulation

4. Practical Tools

  • Bug Likelihood Test - Quick pre-analysis checklist
  • Quick Start Guide - Step-by-step application process

How ADE Complements Existing Frameworks

ADE integrates with and enhances existing detection engineering practices:

Télécharger l’outil