post-exploit-technique

Fail

Audited by Socket on Sep 5, 2026

10 alerts found:

Malwarex8SecurityAnomaly
MalwareHIGH
SKILL.md

MALICIOUS. This skill’s stated purpose is post-exploitation: privilege escalation, credential theft, persistence, and lateral movement. The capabilities, data flows, and system modifications are internally consistent with that offensive purpose, but that purpose itself gives an AI agent explicit attack capabilities with real-world impact. Install provenance is mixed but not the main issue; the dominant risk is deliberate offensive host compromise workflow.

Confidence: 99%Severity: 99%
MalwareHIGH
references/linux-privesc.md

The provided fragment is highly indicative of malicious/supply-chain-harmful content: it gives explicit instructions for privilege escalation, persistence (SUID and root target writes), credential harvesting, and multiple code-execution pathways (including parser/RCE-style workflows, localhost admin/service abuse, and SCM_RIGHTS secret access). There is no legitimate purpose consistent with benign dependency behavior.

Confidence: 85%Severity: 98%
MalwareHIGH
references/persistence.md

This fragment is unequivocally malicious. It provides concrete, multi-platform backdoor persistence methods (Linux and Windows) plus remote command execution webshells and explicit detection-evasion/anti-forensics steps. If included anywhere in a package/dependency, it should be treated as a high-confidence malicious payload/tooling indicator and handled as a serious supply-chain security incident.

Confidence: 96%Severity: 100%
MalwareHIGH
references/credential-harvest.md

This fragment is an explicit offensive credential-harvesting and credential-handoff playbook covering Linux credential stores, Windows LSASS/SAM/NTDS extraction, browser credential theft, and extraction of device/app secrets from management platforms and secret stores, followed by cracking and direct reuse via pass-the-hash/pass-the-ticket. There is no indication of benign functionality. If included in a distributed package/artifact, it would be an extremely high supply-chain security risk. Malware intent is highly probable, but confidence is limited by lack of actual executable/package code and execution context.

Confidence: 78%Severity: 100%
MalwareHIGH
references/windows-privesc.md

This fragment is an offensive, directly actionable Windows privilege-escalation and post-exploitation guide that includes SYSTEM/admin execution paths, persistence/backdoor creation, reverse-shell payload delivery, and credential harvesting (including SAM/SYSTEM/SECURITY hive dumping and stored-secret extraction). It contains no defensive or legitimate software functionality. If included in any dependency, it should be treated as high-risk malicious/weaponized content requiring removal and incident-style review.

Confidence: 90%Severity: 100%
MalwareHIGH
references/pivoting.md

This fragment is an offensive, attacker-oriented pivoting/lateral-movement instruction guide. It provides concrete, actionable commands to establish tunnels/relays (SOCKS/SSH forwarding/socat/netsh/DNS/ICMP) and route internal scanning/exploitation through an intermediate host. It also includes explicit guidance to retrieve cloud/Kubernetes identity and credentials from sensitive metadata endpoints (e.g., IMDS), which materially increases misuse potential. There is no evidence of obfuscation, and there is no dependency/code execution to assess; the primary risk is direct attack enablement if published as part of or distributed with software artifacts.

Confidence: 82%Severity: 95%
SecurityMEDIUM
references/backup-restore-pipelines.md

The provided fragment is not a benign library implementation; it is operational guidance that includes explicit, step-by-step exploitation methodology for a post-validation pathname substitution/integrity-check bypass targeting privileged backup/restore workflows. The only concrete executable actions shown are local process monitoring and log filtering, but the surrounding instructions materially enable a high-impact attack scenario (TOCTOU/race-based replacement of a validated archive). Treat the content as high security risk if present in a supply-chain package, as it can be repurposed to compromise privileged jobs even without embedded payload code.

Confidence: 70%Severity: 85%
MalwareHIGH
references/lateral-movement.md

This fragment is a high-risk offensive lateral movement and post-compromise operational guide. It provides actionable logic and concrete commands for authenticating to remote systems, executing commands via multiple remote administration channels, dumping credentials, enabling additional remote access paths (e.g., RDP), and pivoting through internal segments using tunnels/proxying. If included in any distributed software or repository, it would materially increase attacker capability and should be treated as malicious or dangerously enabling content rather than legitimate software behavior.

Confidence: 82%Severity: 98%
MalwareHIGH
references/windows-admin-center.md

The provided artifact is not library/runtime code; it is attacker-style post-exploitation guidance targeting Windows Admin Center/local management gateways. It instructs identity probing, canary file operations, and detailed evidence collection to map trust boundaries and identify privilege-impact paths. While it does not demonstrate embedded malware logic, the instructional content is highly actionable for intrusion and therefore represents a high security risk in a supply-chain context. Additional context (how/where it is packaged and executed, if at all) is needed to fully assess impact, but based on the fragment alone it is suspicious and potentially enabling.

Confidence: 78%Severity: 87%
AnomalyLOW
references/cloud-and-cicd-post-exploit.md

No executable code is present in the provided fragment; it is an attack-oriented guidance document describing how to capture cloud/CI tokens/credentials, enumerate effective permissions, access secret stores, and implement persistence across IAM/Kubernetes/serverless/CI/CD. If this content appears within a dependency (tooling/library) alongside actual automation, it would be strongly suspicious and should be reviewed for credential-handling, network/API activity, and CI/workflow manipulation logic. As provided, concrete malware behavior cannot be confirmed, but the operational intent and target selection are highly concerning.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:48 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fpost-exploit-technique%2F@3811ad5fcdf17930ac9b817eadc747fc73ab3fa43d9150112fee8764190f60c0
Security Audit — socket — post-exploit-technique