enumexclusions.cna 672 B

1234567891011121314151617181920212223242526
  1. # author REDMED-X
  2. beacon_command_register(
  3. "enumexclusions", "Check the AV for excluded files, folders, extentions and processes.",
  4. "INFO:\nCheck the AV for excluded files, folders, extentions and processes. Currently only Windows Defender exclusions are supported.\n\n" .
  5. "USAGE:\nenumexclusions\n\n");
  6. alias enumexclusions {
  7. $bid = $1;
  8. # Read in the right BOF file
  9. $handle = openf(script_resource("enumexclusions.o"));
  10. $data = readb($handle, -1);
  11. closef($handle);
  12. # Pack our arguments
  13. $arg_data = bof_pack($bid);
  14. blog($bid, "Tasked to enumerate exclusions..");
  15. beacon_inline_execute($bid, $data, "go", $arg_data);
  16. }