asm-offensive-patterns
Audited by Socket on Sep 15, 2026
8 alerts found:
Securityx5Anomalyx3SUSPICIOUS. The skill is internally coherent as an offensive-security reference, but its actual function is to equip an AI agent with exploit-adjacent evasion, injection, and anti-detection techniques. There is no installer, credential theft, or hidden exfiltration path, so this is not confirmed malware; however, it is a high-risk offensive capability skill.
The fragment is documentation, not a self-contained malicious payload. It contains no direct data theft or destructive operations, but it provides detailed, operational guidance for syscall obfuscation, forged call stacks, return-address manipulation, VEH/debug-register abuse, and EDR signature evasion. If incorporated into a package or tooling, these capabilities could support malware or unauthorized stealth activity and warrant security review and strong usage controls.
This fragment is not itself evidence of data theft or system damage, but it documents and illustrates advanced syscall-hook and endpoint-detection evasion mechanisms. The clean ntdll mapping, indirect/recycled syscall gadgets, VEH/HWBP manipulation, and call-stack concealment are high-risk capabilities commonly used by malware and offensive tooling. Treat associated implementation as security-sensitive and require review of call sites and actual syscall targets before use.
This is dual-use low-level Windows assembly documentation, but it explicitly facilitates EDR/AV hook bypass, native syscall access, shellcode execution, and signature evasion. The fragment does not itself demonstrate data theft or destructive malware, yet its operational guidance is strongly associated with offensive tooling and stealth payloads. It should be treated as high-risk code-generation or research material when included in a software package, especially if accompanied by executable assembly or payloads.
The fragment is documentation for a polymorphic/metamorphic shellcode and decoder-morphing system. It contains no direct evidence of network exfiltration, persistence, credential theft, or system damage, but its explicit focus on shellcode encoding, decoder randomization, dead-code insertion, opaque predicates, and static-analysis evasion presents substantial dual-use and malware-enabling risk. The fragment alone is insufficient to establish active malware behavior.
The code is a shellcode/PIC technique reference with several capabilities commonly used in offensive tooling, particularly staged payload discovery and API-resolution concealment. It contains no demonstrated malicious payload or unauthorized system action, so malware intent is not established. Its presence in an otherwise unrelated package would warrant strong provenance and context review because the techniques can support stealthy code injection.
The supplied content is offensive-security educational material containing working-style direct syscall and shellcode examples that can spawn /bin/sh. It contains no demonstrated package malware, data theft, persistence, or network exfiltration, but execution of the examples would have significant local impact and the vDSO/evasion discussion is security-sensitive. Risk derives from the documented capability rather than hidden malicious behavior.
The fragment is documentation for advanced process-injection and shellcode-execution techniques with clear offensive and evasion use. It is not itself executable malware and contains no demonstrated data theft or system compromise, but the techniques described can enable stealthy unauthorized code execution and warrant restricted handling.