Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
Инструменты/GitHubGitHub/adversarial-detection-engineering/adversarial-detection-engineering-framework
Defensive ToolsVulnerability AnalysisIDS/IPS EvasionPenetration TestingThreat IntelligenceLearning & EducationRed TeamingIncident ResponseCurated Resources
Log Analysis
GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

Adversarial-Detection-Engineering-Framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses.

Репозиторий
598202 дней назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

Adversarial Detection Engineering (ADE) Framework

Author GitHub Last Commit GitHub License

Get ahead of False Negatives by understanding how detection logic fails before threat actors abuse it.

Check out the website: https://adeframework.org/

What Is ADE?

Adversarial Detection Engineering (ADE) is the discipline of reasoning about False Negatives in detection rules. The ADE Framework provides a modern open-source formalization of Detection Logic Bugs - mismatches between what a detection rule intends to detect and what it actually detects.

The ADE Advantage

Instead of waiting for real-world False Negatives, detection engineers can proactively ask:

"What variations would cause this rule's detection logic to miss what it was intended to catch?"

This adversarial line of reasoning mirrors how threat actors can abuse weaknesses in detection logic.

Key Features

  • ✅ Identify reproducible detection logic bugs and map them to formal ADE categories
  • ✅ Embed an attacker's mental model into how detection logic is designed and reviewed
  • ✅ Expose structural weaknesses in rules used for hunts or production MDR tooling (SIEM, XDR, EDR)
  • ✅ Equip security teams with actionable detection logic bug intelligence
  • ✅ Get ahead of False Negatives before threat actors discover and exploit them

ADE Purpose

The purpose of ADE is not to force perfection in design, although that is an ideal goal - but to raise awareness and track limitations, even if intentional:

  • ADE is not about demanding perfect detection rules; it is about making the risk of false-negatives visible.
  • Many rules intentionally contain limitations due to scope, signal quality, or operational constraints, and these may still be mapped to ADE bug types without being “wrong.”
  • ADE provides a shared way to document, accept, mitigate, or compensate for those risks across a ruleset, rather than judging individual rules in isolation.

ADE link to Detection Logic Exposures (DLE)

  • ADE supplies a canonical taxonomy and bug classes for detection logic bugs.
  • DLE provides a recognized list of publically disclosed bypasses with ADE mappings.

Quick Start

New to ADE? Start here:

  1. Introduction - Understand what ADE is and why it matters
  2. Core Concepts - Learn the foundational terminology
  3. Quick Start Guide - Apply ADE to your first detection rule
  4. Bug Likelihood Test - Quick checklist to assess rules for bugs

Ready to dive deep?

  • Detection Logic Bug Theory - Formal foundations
  • Taxonomy Overview - All bug categories
  • Examples - Real-world examples

ADE Detection Logic Bug Taxonomy

The framework identifies 4 major categories and 16 subcategories of detection logic bugs:

🌳 ADE1 – Reformatting in Actions
    ├─ ADE1-01 Substring Manipulation
    └─ ADE1-02 Normalization Asymmetry

🌳 ADE2 – Omit Alternatives
    ├─ ADE2-01 Method/Binary
    ├─ ADE2-02 Versioning
    ├─ ADE2-03 Locations
    └─ ADE2-04 File Types

🌳 ADE3 – Context Development
    ├─ ADE3-01 Process Cloning
    ├─ ADE3-02 Aggregation Hijacking
    ├─ ADE3-03 Timing and Scheduling
    ├─ ADE3-04 Event Fragmentation
    ├─ ADE3-05 Lineage Spoofing
    └─ ADE3-06 Limit Saturation

🌳 ADE4 – Logic Manipulation
    ├─ ADE4-01 Gate Inversion
    ├─ ADE4-02 Conjunction Inversion
    ├─ ADE4-03 Incorrect Expression
    └─ ADE4-04 Field Mismapping & Semantics

→ Explore the Full Taxonomy

What the Framework Provides

1. Theory of Detection Logic Bugs

Formal definitions and theoretical foundation:

  • What constitutes a detection logic bug
  • How bugs create False Negatives
  • Relationship between scope and detection logic
  • Concept of Rule Bypasses

2. Formal Bug Taxonomy

Comprehensive classification with clear terminology:

  • 4 major categories
  • 16 detailed subcategories
  • Consistent labeling system (ADE1-01, ADE2-01, etc.)
  • Mapping to real-world detection rules

3. Real-World Examples

Concrete examples from production rulesets:

  • Sigma detection rules
  • Microsoft Sentinel analytics
  • Elastic Security SIEM & EDR rules

Example Categories:

  • ADE1 Examples - String manipulation bypasses
  • ADE2 Examples - Omitted alternatives
  • ADE3 Examples - Context development
  • ADE4 Examples - Logic manipulation

4. Practical Tools

  • Bug Likelihood Test - Quick pre-analysis checklist
  • Quick Start Guide - Step-by-step application process

How ADE Complements Existing Frameworks

ADE integrates with and enhances existing detection engineering practices:

Скачать инструмент