discovered 03 Aug 2026
CS-EDR-Enumeration
→ View on GitHubCS-EDR-Enumeration is a Cobalt Strike Aggressor Script designed to enumerate antivirus (AV), endpoint protection platform (EPP), endpoint detection and response (EDR), and telemetry/SIEM products on Windows hosts post-compromise. It features six commands with varying noise levels to suit different operational risk tolerances, and includes a comprehensive signature database for major security vendors, enabling silent enumeration techniques that minimize detection. Notable capabilities include kernel driver enumeration, automatic threat level assessment, and color-coded output for quick identification of security products.