skills/aeondave/malskill/nanodump/Gen Agent Trust Hub

nanodump

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill facilitates the acquisition of LSASS process memory, which is a primary source of Windows credentials, including NTLM hashes and cleartext passwords.
  • Evidence includes instructions for parsing dumps with Mimikatz and pypykatz to extract sensitive authentication data.
  • [DATA_EXFILTRATION]: The skill documents specific methods for moving harvested credential dumps to external systems.
  • Evidence includes commands for transferring files via SMB shares (copy lsass.dmp \\attacker\share\) and downloading files through Command & Control (C2) frameworks like Cobalt Strike.
  • [PRIVILEGE_ESCALATION]: The instructions describe methods for manipulating system handles and accessing the LSASS process, which requires high-level administrative or SYSTEM privileges.
  • Evidence includes the use of flags like --elevate-handle, --dup, and --sec-logon to abuse existing handles or secondary logon services.
  • [COMMAND_EXECUTION]: The skill provides precise command-line arguments for executing binaries designed to evade Endpoint Detection and Response (EDR) solutions.
  • Evidence includes the implementation of direct syscalls, forking techniques, and silent process exit mechanisms to bypass monitoring and security hooks.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — nanodump