THUGS(red) Security Check
A standardised benchmark for whether your EDR, AV and SOC actually react when something hostile happens.
Everybody owns endpoint security software. Far fewer have watched it be given something to detect. The Security Check client inventories the posture of a machine — EDR and AV present and their state, Defender and tamper protection, policy and join type, firewall, disk encryption, patch currency, secure boot and TPM, what is being logged and whether any of it leaves the host — and then behaves like an adversary in front of it: inert AV test signatures, obfuscated PowerShell, living-off-the-land binaries and injection, credential-store access, persistence, sandboxed ransomware-style file renaming, and egress to places a workstation has no business reaching, including DNS and HTTP exfiltration. Everything is mapped to MITRE ATT&CK and comes back as a report you can keep private or publish for comparison. Run it on a disposable machine — that instruction is not boilerplate.