VirtualAlllocEx / CS-EDR-Enumeration
PublicCobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.
Cobalt Strike Aggressor script and companion tool for detecting antivirus, endpoint protection, EDR, and monitoring products on Windows hosts via methods ranked by detection risk.
How It Works
You find a handy GitHub project that quietly spots security software like antivirus and monitoring tools on test computers.
You copy the main script into your security testing program, unlocking simple commands to check for protections.
You follow easy steps to create a super-silent scanner that checks inside without starting new programs.
On the test computer you've reached, you run the quietest scans to peek at running processes, services, and hidden drivers.
A colorful list appears showing detected security products, grouped by type with threat levels marked.
You're now fully aware of all protections on the machine and can continue your test smartly and safely.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.