Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Adversarial-Detection-Engineering-Framework — A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses. | Kitploit
도구/GitHubGitHub/adversarial-detection-engineering/adversarial-detection-engineering-framework
Defensive ToolsVulnerability AnalysisIDS/IPS EvasionPenetration TestingThreat IntelligenceLearning & EducationRed TeamingIncident ResponseCurated Resources

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Log Analysis
GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

Adversarial-Detection-Engineering-Framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses.

저장소 보기
598202일 전Kitploit 검토 완료
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Adversarial Detection Engineering (ADE) Framework

Author GitHub Last Commit GitHub License

Get ahead of False Negatives by understanding how detection logic fails before threat actors abuse it.

Check out the website: https://adeframework.org/

What Is ADE?

Adversarial Detection Engineering (ADE) is the discipline of reasoning about False Negatives in detection rules. The ADE Framework provides a modern open-source formalization of Detection Logic Bugs - mismatches between what a detection rule intends to detect and what it actually detects.

The ADE Advantage

Instead of waiting for real-world False Negatives, detection engineers can proactively ask:

"What variations would cause this rule's detection logic to miss what it was intended to catch?"

This adversarial line of reasoning mirrors how threat actors can abuse weaknesses in detection logic.

Key Features

  • ✅ Identify reproducible detection logic bugs and map them to formal ADE categories
  • ✅ Embed an attacker's mental model into how detection logic is designed and reviewed
  • ✅ Expose structural weaknesses in rules used for hunts or production MDR tooling (SIEM, XDR, EDR)
  • ✅ Equip security teams with actionable detection logic bug intelligence
  • ✅ Get ahead of False Negatives before threat actors discover and exploit them

ADE Purpose

The purpose of ADE is not to force perfection in design, although that is an ideal goal - but to raise awareness and track limitations, even if intentional:

  • ADE is not about demanding perfect detection rules; it is about making the risk of false-negatives visible.
  • Many rules intentionally contain limitations due to scope, signal quality, or operational constraints, and these may still be mapped to ADE bug types without being “wrong.”
  • ADE provides a shared way to document, accept, mitigate, or compensate for those risks across a ruleset, rather than judging individual rules in isolation.

ADE link to Detection Logic Exposures (DLE)

  • ADE supplies a canonical taxonomy and bug classes for detection logic bugs.
  • DLE provides a recognized list of publically disclosed bypasses with ADE mappings.

Quick Start

New to ADE? Start here:

  1. Introduction - Understand what ADE is and why it matters
  2. Core Concepts - Learn the foundational terminology
  3. Quick Start Guide - Apply ADE to your first detection rule
  4. Bug Likelihood Test - Quick checklist to assess rules for bugs

Ready to dive deep?

  • Detection Logic Bug Theory - Formal foundations
  • Taxonomy Overview - All bug categories
  • Examples - Real-world examples

ADE Detection Logic Bug Taxonomy

The framework identifies 4 major categories and 16 subcategories of detection logic bugs:

🌳 ADE1 – Reformatting in Actions
    ├─ ADE1-01 Substring Manipulation
    └─ ADE1-02 Normalization Asymmetry

🌳 ADE2 – Omit Alternatives
    ├─ ADE2-01 Method/Binary
    ├─ ADE2-02 Versioning
    ├─ ADE2-03 Locations
    └─ ADE2-04 File Types

🌳 ADE3 – Context Development
    ├─ ADE3-01 Process Cloning
    ├─ ADE3-02 Aggregation Hijacking
    ├─ ADE3-03 Timing and Scheduling
    ├─ ADE3-04 Event Fragmentation
    ├─ ADE3-05 Lineage Spoofing
    └─ ADE3-06 Limit Saturation

🌳 ADE4 – Logic Manipulation
    ├─ ADE4-01 Gate Inversion
    ├─ ADE4-02 Conjunction Inversion
    ├─ ADE4-03 Incorrect Expression
    └─ ADE4-04 Field Mismapping & Semantics

→ Explore the Full Taxonomy

What the Framework Provides

1. Theory of Detection Logic Bugs

Formal definitions and theoretical foundation:

  • What constitutes a detection logic bug
  • How bugs create False Negatives
  • Relationship between scope and detection logic
  • Concept of Rule Bypasses

2. Formal Bug Taxonomy

Comprehensive classification with clear terminology:

  • 4 major categories
  • 16 detailed subcategories
  • Consistent labeling system (ADE1-01, ADE2-01, etc.)
  • Mapping to real-world detection rules

3. Real-World Examples

Concrete examples from production rulesets:

  • Sigma detection rules
  • Microsoft Sentinel analytics
  • Elastic Security SIEM & EDR rules

Example Categories:

  • ADE1 Examples - String manipulation bypasses
  • ADE2 Examples - Omitted alternatives
  • ADE3 Examples - Context development
  • ADE4 Examples - Logic manipulation

4. Practical Tools

  • Bug Likelihood Test - Quick pre-analysis checklist
  • Quick Start Guide - Step-by-step application process

How ADE Complements Existing Frameworks

ADE integrates with and enhances existing detection engineering practices:

도구 다운로드