ics-ctf
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes command-line examples for common security and industrial tools such as
tshark,nmap,can-utils, andmosquitto_sub. These are provided for protocol analysis and auditing purposes within an authorized CTF or lab context. - [PRIVILEGE_ESCALATION]: Reference files provide instructions for using
sudoto set up virtual CAN interfaces (vcan) andiptablesrules for traffic redirection. These are standard administrative actions for network simulation and security research in controlled environments. - [REMOTE_CODE_EXECUTION]: The skill references various remote code execution (RCE) techniques and malware variants (e.g., Industroyer, Stuxnet, DynoWiper) within the
references/incidents.mdfile. These mentions are strictly educational, serving as historical context and behavioral fingerprints for threat actor recognition, rather than functional triggers. - [DATA_EXFILTRATION]: Documentation describes various data exfiltration tactics used by adversaries (e.g.,
certutil -encode, Slack webhooks, and Dropbox staging) to help users identify indicators of compromise (IOCs). The skill does not implement any exfiltration logic of its own.
Audit Metadata