sharphound
Warn
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading executable files from remote, potentially untrusted servers using system utilities such as
certutilandInvoke-WebRequest(iwr). - [COMMAND_EXECUTION]: Numerous commands are provided for executing the SharpHound binary with various collection flags to map and analyze Active Directory environments.
- [DATA_EXFILTRATION]: The skill describes methods for gathering and packaging sensitive domain architecture data—including user lists, group memberships, and access control lists—for exfiltration and external visualization.
Audit Metadata