mimikatz
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2High-risk offensive security skill. Its capabilities are coherent with its stated Mimikatz purpose, but that purpose is credential extraction, persistence, and attack tradecraft; if exposed to an AI agent with shell access, it materially enables real-world compromise. Not confirmed malware by itself, but clearly a dangerous exploit/abuse skill.
The fragment is not ordinary dependency functionality. It is a highly actionable guide to Windows credential theft, LSASS dumping, domain credential replication, PPL bypass, ticket forgery, and EDR evasion. It does not by itself constitute executable malware or demonstrate direct data exfiltration, but executing the listed commands could compromise hosts and entire domains. Treat the containing file as high-risk offensive-security content and review the unseen portions before inclusion in a software package.