Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Adversarial-Detection-Engineering-Framework — A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses. | Kitploit
工具/GitHubGitHub/adversarial-detection-engineering/adversarial-detection-engineering-framework
Defensive ToolsVulnerability AnalysisIDS/IPS EvasionPenetration TestingThreat IntelligenceLearning & EducationRed TeamingIncident ResponseCurated Resources

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
Log Analysis
GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

Adversarial-Detection-Engineering-Framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples and real-world bypasses.

查看仓库
598202天前Kitploit 审核通过
内容在请求的语言中不可用。显示英文版本。

Adversarial Detection Engineering (ADE) Framework

Author GitHub Last Commit GitHub License

Get ahead of False Negatives by understanding how detection logic fails before threat actors abuse it.

Check out the website: https://adeframework.org/

What Is ADE?

Adversarial Detection Engineering (ADE) is the discipline of reasoning about False Negatives in detection rules. The ADE Framework provides a modern open-source formalization of Detection Logic Bugs - mismatches between what a detection rule intends to detect and what it actually detects.

The ADE Advantage

Instead of waiting for real-world False Negatives, detection engineers can proactively ask:

"What variations would cause this rule's detection logic to miss what it was intended to catch?"

This adversarial line of reasoning mirrors how threat actors can abuse weaknesses in detection logic.

Key Features

  • ✅ Identify reproducible detection logic bugs and map them to formal ADE categories
  • ✅ Embed an attacker's mental model into how detection logic is designed and reviewed
  • ✅ Expose structural weaknesses in rules used for hunts or production MDR tooling (SIEM, XDR, EDR)
  • ✅ Equip security teams with actionable detection logic bug intelligence
  • ✅ Get ahead of False Negatives before threat actors discover and exploit them

ADE Purpose

The purpose of ADE is not to force perfection in design, although that is an ideal goal - but to raise awareness and track limitations, even if intentional:

  • ADE is not about demanding perfect detection rules; it is about making the risk of false-negatives visible.
  • Many rules intentionally contain limitations due to scope, signal quality, or operational constraints, and these may still be mapped to ADE bug types without being “wrong.”
  • ADE provides a shared way to document, accept, mitigate, or compensate for those risks across a ruleset, rather than judging individual rules in isolation.

ADE link to Detection Logic Exposures (DLE)

  • ADE supplies a canonical taxonomy and bug classes for detection logic bugs.
  • DLE provides a recognized list of publically disclosed bypasses with ADE mappings.

Quick Start

New to ADE? Start here:

  1. Introduction - Understand what ADE is and why it matters
  2. Core Concepts - Learn the foundational terminology
  3. Quick Start Guide - Apply ADE to your first detection rule
  4. Bug Likelihood Test - Quick checklist to assess rules for bugs

Ready to dive deep?

  • Detection Logic Bug Theory - Formal foundations
  • Taxonomy Overview - All bug categories
  • Examples - Real-world examples

ADE Detection Logic Bug Taxonomy

The framework identifies 4 major categories and 16 subcategories of detection logic bugs:

🌳 ADE1 – Reformatting in Actions
    ├─ ADE1-01 Substring Manipulation
    └─ ADE1-02 Normalization Asymmetry

🌳 ADE2 – Omit Alternatives
    ├─ ADE2-01 Method/Binary
    ├─ ADE2-02 Versioning
    ├─ ADE2-03 Locations
    └─ ADE2-04 File Types

🌳 ADE3 – Context Development
    ├─ ADE3-01 Process Cloning
    ├─ ADE3-02 Aggregation Hijacking
    ├─ ADE3-03 Timing and Scheduling
    ├─ ADE3-04 Event Fragmentation
    ├─ ADE3-05 Lineage Spoofing
    └─ ADE3-06 Limit Saturation

🌳 ADE4 – Logic Manipulation
    ├─ ADE4-01 Gate Inversion
    ├─ ADE4-02 Conjunction Inversion
    ├─ ADE4-03 Incorrect Expression
    └─ ADE4-04 Field Mismapping & Semantics

→ Explore the Full Taxonomy

What the Framework Provides

1. Theory of Detection Logic Bugs

Formal definitions and theoretical foundation:

  • What constitutes a detection logic bug
  • How bugs create False Negatives
  • Relationship between scope and detection logic
  • Concept of Rule Bypasses

2. Formal Bug Taxonomy

Comprehensive classification with clear terminology:

  • 4 major categories
  • 16 detailed subcategories
  • Consistent labeling system (ADE1-01, ADE2-01, etc.)
  • Mapping to real-world detection rules

3. Real-World Examples

Concrete examples from production rulesets:

  • Sigma detection rules
  • Microsoft Sentinel analytics
  • Elastic Security SIEM & EDR rules

Example Categories:

  • ADE1 Examples - String manipulation bypasses
  • ADE2 Examples - Omitted alternatives
  • ADE3 Examples - Context development
  • ADE4 Examples - Logic manipulation

4. Practical Tools

  • Bug Likelihood Test - Quick pre-analysis checklist
  • Quick Start Guide - Step-by-step application process

How ADE Complements Existing Frameworks

ADE integrates with and enhances existing detection engineering practices:

下载工具