{"repo":"FourCoreLabs/EDRHunt","free":true,"listed":false,"github":"https://github.com/FourCoreLabs/EDRHunt","clone":"git clone https://github.com/FourCoreLabs/EDRHunt.git","description":"Scan installed EDRs and AVs on Windows","language":"Go","stars":610,"topics":["security","security-tools","infosec"],"license":"MIT","category":"security-tools","readme_excerpt":"EDRHunt EDRHunt scans Windows services, drivers, processes, registry, wmi for installed EDRs (Endpoint Detection And Response). Read more about EDRHunt here. Install - Binary - Download the latest release from the release section. Releases are built for windows/amd64. - Go - Requires Go to be installed on system. Tested on Go1.17+. - go install github.com/fourcorelabs/edrhunt/cmd/EDRHunt@master Usage - Find installed EDRs - Scan Everything - Find drivers matching EDR keywords - Find services matching EDR keywords - Find drivers matching EDR keywords - Find registry keys matching EDR keywords - Find WMI Repository keys matching EDR keywords Detections EDR Detections Currently Available - Windows Defender - Kaspersky Security - Symantec Security - Crowdstrike Security - Mcafee Security - Cylance Security - Carbon Black - SentinelOne - FireEye - Elastic EDR - Qualys EDR - Trend Micro EDR - ESET EDR - Cybereason EDR - BitDefender EDR - Checkpoint EDR - Cynet EDR - DeepInstinct EDR - Sophos EDR - Fortinet EDR - MalwareBytes EDR - LimaCharlie Agent More to be added soon. Community Would appreciate if you ran EDRHunt on your own deployments and test the detections! Thanks.","default_branch":null,"files":null,"tree":[],"storefront":"/r/FourCoreLabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/FourCoreLabs/EDRHunt/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}