chisel
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMPERSISTENCEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONOBFUSCATION
Full Analysis
- [PERSISTENCE]: The skill provides instructions for establishing persistence on a Linux host by launching the Chisel client as a transient systemd unit using
systemd-run --unit=pivot-chisel. This method ensures the tunnel remains active across shell deaths and cgroup terminations. - [PRIVILEGE_ESCALATION]: The persistence mechanism explicitly instructs the use of
sudo systemd-run, requiring the agent or user to elevate privileges to root to maintain a persistent connection. - [COMMAND_EXECUTION]: The documentation focuses on executing commands on a "compromised host" to connect back to an "attacker" machine. These commands establish reverse SOCKS5 proxies and multiple port relays, facilitating remote control and internal network access.
- [OBFUSCATION]: The skill details methods for evading detection, such as native TLS masking to bypass Deep Packet Inspection (DPI) and binary manipulation techniques like stripping symbols (
-ldflags="-s -w") and UPX packing to evade Endpoint Detection and Response (EDR) systems.
Audit Metadata