asm-offensive-patterns

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONPRIVILEGE_ESCALATIONTIME_DELAYED_CONDITIONALDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides functional assembly stubs and detailed instructions for sophisticated process injection techniques, including Fiber-based execution, Threadless callback injection, Module Stomping, and Phantom DLL Hollowing using NTFS transactions (TxF) as described in references/injection-techniques.md and references/advanced-evasion.md.
  • [COMMAND_EXECUTION]: The skill includes raw assembly code for executing shell commands, specifically providing /bin/sh shellcode patterns for Linux x86-64 and ARM64 macOS/Linux in references/linux-macos-patterns.md.
  • [OBFUSCATION]: It implements and describes multiple advanced metamorphic and polymorphic encoding techniques designed to evade signature-based detection. This includes Additive Feedback Loops (ADFL), Rolling-XOR, Mixed Boolean Arithmetic (MBA-XOR), and the Morph RX-compatible rewriter found in assets/decoder-stubs.asm and references/encoders.md.
  • [PRIVILEGE_ESCALATION]: The skill provides explicit methods for disabling critical security telemetry and interface scanning, such as patching NtTraceEvent to bypass ETW and flipping conditionals in AmsiScanBuffer to disable AMSI scanning, as detailed in SKILL.md Section 7.
  • [DYNAMIC_EXECUTION]: It contains implementations for resolving system APIs without using the Import Address Table (IAT) by walking the Process Environment Block (PEB) and export tables using custom hashes. It also details the construction of ROP, JOP, and COP chains to bypass Data Execution Prevention (DEP) and Control-flow Enforcement Technology (CET) in assets/peb-walk-x64.asm and references/advanced-evasion.md.
  • [TIME_DELAYED_CONDITIONAL]: The skill incorporates numerous anti-analysis and anti-debugging techniques, such as RDTSC timing checks to detect single-stepping, hypervisor bit validation for VM detection, and the use of TLS callbacks to execute checks before the main entry point in references/advanced-evasion.md.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — asm-offensive-patterns