metasploit
Audited by Socket on Sep 5, 2026
3 alerts found:
Malwarex2SecurityThis fragment is a highly malicious, offensive post-exploitation runbook for Metasploit. It explicitly instructs credential dumping/secret extraction (Windows SAM/LSA/NTDS and Linux /etc/shadow), privilege escalation, persistence (scheduled task/registry/cron), internal pivoting and scanning (route/autoroute, SOCKS), surveillance (keylogging and screenshot/screen streaming), and data theft via file search/download/upload. There are strong malicious intent indicators and no obfuscation.
This artifact is not a benign software module; it is highly actionable offensive documentation for generating reverse-shell/meterpreter payloads (including cross-platform and web-style formats) and starting a handler to receive connections. While it contains no intrinsic runtime behavior, its inclusion in a software package would represent a serious supply-chain risk due to direct weaponization guidance and enablement of malware-like operations.
SUSPICIOUS: internally consistent as a Metasploit reference, but it is an offensive security skill that enables exploitation, session control, credential dumping, and remote host manipulation. Install trust is mostly official/low concern; the primary risk is the AI agent being given high-impact exploit and post-exploitation capability.