asm-offensive-patterns
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONPRIVILEGE_ESCALATIONTIME_DELAYED_CONDITIONALDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides functional assembly stubs and detailed instructions for sophisticated process injection techniques, including Fiber-based execution, Threadless callback injection, Module Stomping, and Phantom DLL Hollowing using NTFS transactions (TxF) as described in
references/injection-techniques.mdandreferences/advanced-evasion.md. - [COMMAND_EXECUTION]: The skill includes raw assembly code for executing shell commands, specifically providing
/bin/shshellcode patterns for Linux x86-64 and ARM64 macOS/Linux inreferences/linux-macos-patterns.md. - [OBFUSCATION]: It implements and describes multiple advanced metamorphic and polymorphic encoding techniques designed to evade signature-based detection. This includes Additive Feedback Loops (ADFL), Rolling-XOR, Mixed Boolean Arithmetic (MBA-XOR), and the Morph RX-compatible rewriter found in
assets/decoder-stubs.asmandreferences/encoders.md. - [PRIVILEGE_ESCALATION]: The skill provides explicit methods for disabling critical security telemetry and interface scanning, such as patching NtTraceEvent to bypass ETW and flipping conditionals in AmsiScanBuffer to disable AMSI scanning, as detailed in
SKILL.mdSection 7. - [DYNAMIC_EXECUTION]: It contains implementations for resolving system APIs without using the Import Address Table (IAT) by walking the Process Environment Block (PEB) and export tables using custom hashes. It also details the construction of ROP, JOP, and COP chains to bypass Data Execution Prevention (DEP) and Control-flow Enforcement Technology (CET) in
assets/peb-walk-x64.asmandreferences/advanced-evasion.md. - [TIME_DELAYED_CONDITIONAL]: The skill incorporates numerous anti-analysis and anti-debugging techniques, such as RDTSC timing checks to detect single-stepping, hypervisor bit validation for VM detection, and the use of TLS callbacks to execute checks before the main entry point in
references/advanced-evasion.md.
Recommendations
- AI detected serious security threats
Audit Metadata