/ASRenum-BOF

Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations

Primary LanguageC++

ASRenum

Identify ASR rules, actions, and exclusion locations

Thanks to EspressoCake

ASRenum-BOF.cpp/.cna

$ make all
  • load cna

Screenshot from 2022-12-28 14-05-34

ASRenum.cpp

  • initial script

ASRenum.cs

beacon> inlineExecuteAssembly --dotnetassembly C:\Tools\ASRenum.exe
beacon> bofnet_executeassembly ASRenum