{"adoption": {"forks": 479, "observed_at": "2026-08-28T04:07:05.190184+00:00", "stars": 2623}, "canonical_url": "https://ross.abutalabs.com/products/defendercheck", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Identifies the bytes that Microsoft Defender flags on.", "domain": ["security", "penetration-testing", "developer-tools", "windows"], "enriched": true, "function": ["security", "penetration-testing", "cli"], "health_score": 56, "homepage": null, "language": "C#", "license": "BSD-3-Clause", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["matterpreter/DefenderCheck"], "name": "matterpreter/DefenderCheck", "platform": ["windows", "cli", "dotnet"], "pushed_at": "2025-12-31T23:04:51+00:00", "repo": "matterpreter/DefenderCheck", "stars": 2623, "tags": ["antivirus-evasion", "defender", "signature-scanning", "malware-research", "binary-analysis"], "topics": ["evasion", "research-tool", "csharp"], "urls": [], "use_cases": ["find which bytes in my binary Defender flags", "identify the bad code in my payload that triggers antivirus", "test if my tool gets detected by Microsoft Defender", "pinpoint signature detections in a compiled executable", "make evasion work easier by locating flagged bytes", "research antivirus signature detection on Windows"], "what_it_is": "A C# command-line tool that takes a binary as input and splits it iteratively to pinpoint the exact bytes that Microsoft Defender flags on. It prints the offending bytes to help identify bad code sections in tools or payloads during evasion research.", "when_to_avoid": ["you need multi-engine antivirus testing, not just Microsoft Defender", "you are on Linux or macOS with no access to Windows Defender", "you want a fully undetected tool out of the box - Defender itself now flags DefenderCheck"], "when_to_choose": ["you develop offensive security tools or payloads and need to know exactly which bytes trigger Defender", "you are doing antivirus evasion research on a Windows machine with Defender available", "you want a simple, focused CLI utility rather than a full AV testing framework"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/defendercheck", "repo": "matterpreter/DefenderCheck", "role": "main", "score": 59}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:05.190184+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:19:58.162418+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2a312a989c86ff43733beabb235b7853c8fb0ada703f6bded2d40dafb6f3ff9e", "fetched_at": "2026-08-28T04:07:05.190184+00:00", "kind": "readme", "missing": false, "url": "https://github.com/matterpreter/DefenderCheck"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 60, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2703, "days_push": 245, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 59, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}