{"adoption": {"forks": 296, "observed_at": "2026-08-28T04:05:46.424775+00:00", "stars": 1868}, "canonical_url": "https://ross.abutalabs.com/products/cs-situational-awareness-bof", "card": {"archived": false, "artifact_type": "library", "description": "Situational Awareness commands implemented using Beacon Object Files", "domain": ["security", "penetration-testing", "developer-tools"], "enriched": true, "function": ["security", "cli", "developer-tools"], "health_score": 99, "homepage": null, "language": "C", "license": "GPL-2.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["trustedsec/CS-Situational-Awareness-BOF"], "name": "trustedsec/CS-Situational-Awareness-BOF", "platform": ["windows", "cli"], "pushed_at": "2026-08-17T18:13:05+00:00", "repo": "trustedsec/CS-Situational-Awareness-BOF", "stars": 1868, "tags": ["beacon-object-files", "cobalt-strike", "red-team", "offensive-security", "situational-awareness", "post-exploitation", "cna", "command-line"], "topics": ["bof", "cna", "c"], "urls": [], "use_cases": ["enumerate AD CS certificate authorities and templates from a beacon", "check for AV/EDR drivers by signing certificates on a host", "list ARP table, sessions, and environment variables during post-exploitation recon", "learn how to write and build Beacon Object Files for Cobalt Strike", "read files and enumerate directories with wildcards from a beacon", "check Active Directory Recycle Bin status and deleted objects"], "what_it_is": "A collection of situational awareness commands implemented as Cobalt Strike Beacon Object Files (BOFs) in C, letting operators run low-footprint host checks before more invasive actions. It also serves as a reference workflow and template for developing new BOFs.", "when_to_avoid": ["you use a C2 framework other than Cobalt Strike that lacks BOF support", "you need a standalone GUI or general-purpose pentesting toolkit rather than beacon-integrated commands", "you are looking for defensive/blue-team tooling"], "when_to_choose": ["you run Cobalt Strike and want low-overhead host enumeration without spawning processes", "you need a starting template and workflow for developing your own BOFs", "you want quick situational awareness checks like EDR detection or AD CS enumeration"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/cs-situational-awareness-bof", "repo": "trustedsec/CS-Situational-Awareness-BOF", "role": "main", "score": 97}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:46.424775+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:15:16.821878+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0602692be301db0376ed099368306d7a88e931e64dc052d5454f0d6a27e0aad1", "fetched_at": "2026-08-28T04:05:46.424775+00:00", "kind": "readme", "missing": false, "url": "https://github.com/trustedsec/CS-Situational-Awareness-BOF"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 98, "longevity": 100, "rhythm": 95}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2240, "days_push": 16, "days_rel": 37, "gap_med": 9, "n_releases_24m": 10}, "score": 97, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}