windows-internals-dev
Audited by Socket on Sep 5, 2026
6 alerts found:
Malwarex3Securityx2AnomalyAs provided, this fragment is not legitimate dependency/application logic; it is attacker-focused guidance for bypassing EDR/AMSI/telemetry and adapting credential-access tactics under Windows mitigations. While the excerpt lacks concrete runnable implementation (so execution is unconfirmed), the presence of detailed, actionable evasion/credential tradecraft makes it a high supply-chain security concern and merits immediate review/removal/quarantine if found in a distributed package.
This fragment is highly consistent with offensive Windows stealth/evasion tooling. It describes hash-based dynamic module/API selection and explicit remote PEB/ProcessParameters UNICODE_STRING overwrites to spoof the process command line (optionally coupled with ImagePathName consistency). These are direct indicators of process deception and EDR/forensics evasion. Because the provided content appears to be excerpted instructional code rather than complete deployable package logic, exact confirmation of execution behavior beyond these described primitives is limited; nevertheless, the security risk is high and the artifact should be treated as suspicious for malware/loader use.
High supply-chain security risk. While the provided fragment is descriptive rather than directly executable, it serves as an operationally detailed offensive reference for Windows x64 call-stack spoofing and EDR/ETW stack-walk evasion using exception/unwind mechanics, including context manipulation and dynamic function-table registration guidance. This materially increases the likelihood the containing package could enable stealthy malicious tooling, even though active malware behavior cannot be confirmed from this excerpt alone.
No executable code is provided, so direct proof of malware execution or specific source-to-sink behavior cannot be established from this fragment alone. However, the text is highly actionable and explicitly oriented toward bypassing Windows ETW-TI and evading detection, including credential-dumping-adjacent references and kernel-level tampering concepts. If this material is embedded within an otherwise distributable dependency, it should be treated as a major supply-chain concern pending review of the surrounding package for actual implementation.
SUSPICIOUS. The skill is internally consistent and not a supply-chain lure, but its stated purpose is to help an AI agent perform advanced offensive Windows tradecraft, including evasion and tampering with security telemetry. That makes it a high-risk exploit/security tool skill even without direct malware payloads, installers, or credential collection.
This fragment provides detailed, security-relevant guidance and one concrete primitive for manual PE mapping via relocation patching, plus descriptions of TLS callback execution, unwind metadata usage, and COFF/BOF loading workflows. While no direct malicious actions (exfiltration, credential theft, command execution, or networking) are shown in the provided text, the strong offensive/anti-analysis framing and inclusion of loader-evasion-relevant mechanics make the broader codebase worth high scrutiny. Treat any package containing this material as potentially dangerous until verified that it is only for benign tooling and that it does not perform runtime in-memory execution, import patching, or anti-analysis behavior beyond legitimate debugging/research use.