triaging-vulnerabilities-with-ssvc-framework
Audited by Socket on Jun 19, 2026
342 alerts found:
Securityx213Malwarex28Obfuscated Filex48Anomalyx53The browser-use skill is coherent and feature-rich for authenticated browser automation in both local and cloud environments. However, it introduces elevated data-flow and privacy risks through cookie/profile syncing and exports/imports to cloud contexts. Treat as high-risk with mitigations: enforce least-privilege cookie syncing (domain-scoped), restrict export/import to minimum necessary data, require explicit user consent for profile transfers, implement strong authentication for cloud endpoints, and segregate local vs cloud data paths. No explicit malware detected, but the data-exposure surface warrants careful governance.
This module is a dual-use OSINT reconnaissance script that facilitates domain and web-asset discovery and harvesting of potentially sensitive data (emails, subdomains, security headers, robots-disallowed paths). There is no evidence of embedded malware (no C2, no reverse shell, no obfuscation or dynamic code execution). However, the explicit offensive guidance in the generated report and the lack of safeguards (rate limiting, consent checks, secure storage) make it a high misuse-risk tool. Recommend restricting use to authorized engagements, adding consent/authorization checks, improving exception handling and logging, and removing or rephrasing offensive instructions in generated reports. Consider encrypting stored outputs and adding telemetry opt-in/out and rate limiting to reduce abuse potential.
Overall BENIGN with notable security risk. The skill’s capabilities match its stated SOC purpose and data mostly flows to expected security vendors/internal systems, but TLS verification is explicitly disabled and the skill enables autonomous firewall blocking, which raises operational and security risk.
SUSPICIOUS. The skill’s capabilities are mostly consistent with Google Workspace hardening, but its practical footprint depends on GAM, a third-party high-privilege admin CLI that Google does not support. That makes the skill higher risk than a pure Google Admin Console/API guide, especially because admin tokens and tenant-wide changes are routed through external code. No clear evidence of malware or overt exfiltration, but the trust model is weaker than the stated security-hardening purpose suggests.
SUSPICIOUS. The skill's capabilities are largely consistent with a Delinea Secret Server PAM deployment guide, and credentials flow to the expected Secret Server API rather than a third-party service. However, the installer reference to `thy.center` is inconsistent with Delinea's official documented download path (`support.delinea.com`) and introduces a notable install-trust risk. Aside from that provenance mismatch, the scope and data flows are proportionate to the PAM administration purpose.
SUSPICIOUS: the skill is internally coherent for API security testing, with proportionate tools and no obvious credential theft or covert exfiltration. However, it is an offensive security skill that enables an AI agent to probe live systems for vulnerabilities, so it carries elevated security risk despite appearing purpose-aligned.
SUSPICIOUS. The skill is internally coherent for threat-intelligence profiling and routes data to official APIs, so there is no strong evidence of credential theft or malware. However, it gives an AI agent offensive-adjacent cybersecurity reconnaissance capability and invokes external tooling, creating meaningful security risk despite generally legitimate install sources and proportional credentials.
This module is an authenticated credential validation/scan utility intended for assessing login validity and privilege level across SSH, WinRM, SMB and SNMPv3 services. The code contains no clear signs of obfuscated or intentionally malicious logic, no hard-coded credentials, and no exfiltration to external attacker infrastructure. The primary risk is its dual-use nature: it will transmit provided credentials to target hosts and execute commands to determine privileges, which makes it sensitive and potentially dangerous if used without proper authorization. Use only in authorized assessments; review credentials and target lists carefully and secure output artifacts (CSV, logs).
This is an offensive security/assessment script for Kerberoasting: it enumerates SPN-enabled accounts, helps request TGS tickets (or prints appropriate Impacket/Rubeus commands), analyzes kerberoast hashes, and writes a report. The code itself does not contain covert exfiltration, obfuscated payloads, or direct backdoor functionality. However, it handles and emits credentials in cleartext (building command strings containing the password) and performs sensitive network operations against a domain controller — behaviors that can be abused if run by an unauthorized user. Recommendation: treat as dual-use offensive tooling. Do not run with production credentials on hostile or untrusted machines; avoid printing credentials, and secure output and logs. Overall: not obfuscated, not covertly malicious, but capable of facilitating offensive attacks and therefore poses a moderate security risk if misused.
Mostly coherent and purpose-aligned threat-intelligence automation. The main security issue is the explicit disabling of TLS verification for MISP, which materially raises interception risk for credentials and shared IOC data; otherwise the install sources, scope, and data flows are proportionate.
The skill is purpose-aligned for Docker forensics and shows no clear malware or credential-harvesting behavior. Its main risks are high-impact security-investigation capabilities for an AI agent and unpinned download-and-execute steps for external analysis tools, so it is best classified as suspicious/high-risk-but-not-malicious.
SUSPICIOUS: The skill is largely coherent and defensive in purpose, with official-looking vendor/API data flows and no obvious exfiltration or malicious installer behavior. However, it meaningfully increases risk by teaching an agent to run security scanning workflows, disables TLS verification in authenticated examples, and forwards Qualys credentials to a third-party client library rather than using direct official API calls.
SUSPICIOUS: the skill’s purpose is coherent and most data flows are expected for MISP/SIEM integration, but trust and transport security are weakened by a non-current Docker image source, unpinned mutable tags, and disabled TLS verification. No clear credential harvesting or malicious exfiltration is present, but the examples create meaningful deployment and interception risk.
Purpose and capabilities are mostly aligned: this is a cloud CIS audit/remediation guide using standard tools and official APIs. It is not overtly malicious and shows no credential harvesting or third-party exfiltration, but it materially increases agent capability to perform cloud security scans and make impactful configuration changes across accounts, so it should be treated as a medium-risk security skill.
SUSPICIOUS. The skill is internally coherent for malware/rootkit forensics and shows no credential theft or exfiltration path, but it materially expands an AI agent’s offensive/advanced security-analysis capability and references powerful external tools without tightly scoped install guidance. Main risk is capability class, not hidden malicious behavior.
SUSPICIOUS but not malicious. The skill is coherent for Entra ID security auditing and primarily uses official Microsoft APIs, but it is a high-impact security assessment capability and it forwards Azure auth context to third-party ScoutSuite with unpinned install details. Risk is driven by offensive/security-tool nature and third-party credential-context handling, not by clear exfiltration or deceptive behavior.
This skill is purpose-aligned and not overtly malicious: it is an OT/ICS security assessment guide for SCADA/HMI systems, and its minimal dependency footprint is consistent with that purpose. However, it grants an AI agent offensive security testing guidance for critical infrastructure targets, so it should be treated as a high-sensitivity security skill with moderate overall risk despite low evidence of malware or exfiltration.
SUSPICIOUS: The skill is mostly aligned with its stated SOC ransomware-response purpose and uses official vendor APIs, but it enables high-impact security actions and sends sample data to a third-party identification service. Risk is driven more by powerful incident-response capabilities and external sample upload than by malware indicators; there is no clear credential harvesting, hidden execution, or deceptive install behavior.
The skill is purpose-aligned for detection engineering, but it materially increases risk by instructing an AI agent to install a remote PowerShell framework and execute Atomic Red Team attack simulations. The install path appears official and not credential-harvesting, so this is not confirmed malware; however, the combination of remote-script execution and offensive security capability makes the skill suspicious/high-risk for agent use.
SUSPICIOUS: mostly coherent GCP assessment guidance using official Google tools, but it mixes in a third-party auditor and can hand a raw service-account key to that tool. No clear malicious exfiltration path is shown, yet the third-party credential forwarding and unpinned install make the skill higher-risk than a pure Google-native assessment guide.
SUSPICIOUS overall due to dual-use cloud security auditing capability, required AWS credentials, and third-party tool reliance. The core purpose and AWS data flows are coherent and mostly proportionate, but the unpinned Prowler install, unspecified S3audit provenance, and inclusion of live remediation commands create meaningful security risk without clear signs of outright malicious intent.
MALICIOUS. The skill’s purpose is offensive exploitation: it instructs an AI agent to probe targets, enumerate internal networks, access cloud metadata, steal credentials, and exfiltrate evidence through known interception services. This footprint is incompatible with safe general-purpose agent use and creates high real-world abuse risk.
SUSPICIOUS rather than malicious. The skill is internally coherent for DFIR live-response collection and keeps data local, but it grants an AI agent broad access to highly sensitive host state and references external forensic tools whose provenance is only partly established in the skill. High operational sensitivity, moderate supply-chain risk, no clear credential harvesting or exfiltration behavior.
The code provides a static analysis workflow for APKs, including hash computation, permission extraction via aapt, dex pattern scanning, and optional VirusTotal checks. There is no active malware payload; instead, the tool aggregates risk indicators to assess potential risk. Notable security considerations include dependency on external tooling (aapt), optional network calls to VirusTotal, and heuristic risk scoring that could yield false positives. To improve reliability and privacy, consider sandboxed execution, explicit opt-in/deny controls for VT, and stronger input validation. Overall, the tool is suitable for defensive analysis but should be used with trusted environments and versioned dependencies.
This module is a legitimate memory forensics helper that invokes Volatility 3 command-line plugins to extract process/network/credential data from a memory dump. No signs of hidden backdoor, obfuscated payloads, or network exfiltration are present in the code itself. However, the code dangerously concatenates untrusted inputs into shell commands (subprocess.run with shell=True) creating a clear command-injection vector. It also calls credential-dumping plugins and prints their raw output — valid forensic capability but high-sensitivity functionality that could be abused. Treat this code as non-malicious but high-risk: only run with trusted inputs and harden to avoid shell=True and to validate/sanitize inputs.
This document is an explicit offensive red team engagement playbook providing actionable TTPs (phishing, credential theft, privilege escalation, persistence, exfiltration) and tooling recommendations commonly used in real-world intrusions. It is not obfuscated code but contains high-risk, adversarial guidance that could be misused. If found in a public package or dependency, it represents a significant security and abuse risk and should be treated with caution: ensure presence is intended (e.g., part of a sanctioned training repo) and restrict distribution. For supply-chain concerns, inclusion of this content increases likelihood of misuse even though it is not executable malware by itself.
BENIGN for its stated purpose, but operationally high impact. The skill is internally consistent with incident-response triage, uses proportionate credentials, and routes data mainly to official/internal systems. Main risk comes from giving an AI agent live security-operations and paging capabilities, so human approval and scoped tokens are important.
This appears to be a legitimate administrative auditing tool for Google Workspace. I found no indicators of malicious intent or covert exfiltration — network interactions are limited to Google APIs, and there is no obfuscated or dynamic execution. The primary security concerns are operational: handling and protection of the service account JSON key and delegated admin identity, broad OAuth scopes granting powerful access, potential local exposure of sensitive PII via stdout or output files, and incomplete pagination/error handling which could cause missed events or unhandled exceptions. Recommendations: protect the key (use IAM restrictions, short-lived credentials or workload identity where possible), apply least-privilege scopes, sanitize/redact sensitive output or restrict file permissions when writing reports, add consistent pagination and error handling for API calls, and avoid delegating a super-admin unless required.
This module is a legitimate AWS penetration-testing helper that performs sensitive enumeration (IAM, policies, Secrets Manager/SSM) and delegates powerful actions to external Pacu modules. The file itself does not contain obfuscated or overtly malicious code or hardcoded secrets. However, because it uses environment-sourced AWS credentials and executes third-party Pacu modules without sandboxing or integrity checks, running it with real or high-privilege credentials in an untrusted environment poses a meaningful risk of data exposure, privilege escalation, or resource modification. Treat this script as dangerous in production; only run in authorized, controlled test environments with least-privilege credentials and audited execution.
The script itself is not malicious: it is a straightforward automation wrapper that calls the external sqlmap CLI. The primary security risks are (1) misuse for unauthorized scanning and data exfiltration because it gives direct control over sqlmap; and (2) supply-chain risk where a compromised or trojan sqlmap binary on PATH would be executed by this wrapper. There are also operational concerns about predictable /tmp output and storage of potentially sensitive results. Mitigations include verifying the sqlmap binary, restricting execution context, using a non-shared output directory, and ensuring authorized use.
This content is an explicit operational playbook and IaC for deploying and operating Havoc command-and-control infrastructure and associated malicious payloads. It contains strong, explicit indicators of malicious intent (C2 setup, payload generation, evasion and OPSEC techniques). The Terraform automates provisioning and execution (user_data) that will install and run offensive tooling. Treat this as malicious and high risk; do not deploy or include in trusted supply chains.
BENIGN for purpose alignment and data flow: this is a legitimate AFL++ CI/CD guide using official tooling and expected commands. Security risk is still moderate because it grants an AI agent offensive security testing capability and CI execution power, plus minor supply-chain hygiene issues from mutable action/package versions.
The artifact is a non‑executable, highly actionable offensive playbook for enumerating and exploiting Active Directory using BloodHound/SharpHound techniques. It contains no hardcoded secrets, obfuscated code, or embedded network callbacks within the fragment, so it is not malware by itself. However, because it codifies discovery-to-exploitation chains (Kerberoast, ACL abuse, delegation, GPO abuse, LSASS dumping), it poses a significant operational misuse risk: possession of this document materially aids attackers and lowers their execution effort. From a supply‑chain security perspective treat the file as sensitive operational guidance; monitor distribution and restrict access to authorized red team/defensive personnel. Further inspection of related binaries/scripts in the repository would be required to fully assess malware or supply‑chain compromise risks.
This file is a Covenant C2 client/CLI that implements powerful offensive capabilities (listener and launcher creation, implant/task orchestration) and persists operation details locally. It lacks TLS verification, does not securely handle or redact sensitive data (credentials/token/operation details), and will forward arbitrary task/launcher parameters to the server. The code is dual-use: acceptable in authorized red-team contexts but high-risk if included as a dependency or run in untrusted environments. Review and restrict use, enable TLS verification, avoid storing plaintext sensitive data, and add stronger safeguards (authorization checks, input validation, sanitized logging) before deploying.
This module is an explicit offensive NoSQL injection testing and exploitation tool. It deliberately constructs operator and $where payloads to bypass authentication and to perform blind exfiltration of fields. There is no sign of covert supply-chain malware (no external C2 domains, no obfuscation for stealth, no system compromise routines), but the tool is high-risk to targets if used without authorization. Fixes recommended: correct _escape_regex to properly escape brackets, fix Markdown table formatting, add clear authorization checks/warnings, add rate-limiting/backoff, and avoid storing sensitive extracted data unless encrypted or explicitly approved. Use only in authorized security testing contexts.
This module is a reconnaissance and privilege-assertion utility that aggregates kubectl outputs to report cluster inventory, RBAC capability, exposed UI services, and pod escape indicators. It does not contain direct network exfiltration, obfuscated payloads, or embedded credentials, but it will surface sensitive cluster information when run with credentials that permit it. The script is dual-use: useful for authorized testing and auditing, but dangerous in untrusted hands or CI systems that capture output. Review and restrict execution to authorized operators and ensure output is handled securely.
The fragment implements a multi-technique SQL injection assessment tool. It is not inherently malicious, but its capabilities enable active probing of external systems. Unauthorized use could be harmful or illegal; the insecure SSL handling (verify=False) and lack of consent checks are notable safety concerns. No obvious backdoors or data exfiltration beyond the test payloads are present.
This module is a straightforward GoPhish API client and CLI for managing phishing simulations. The code itself shows no obfuscated or hidden malicious payloads, no hard-coded exfiltration targets, and no dynamic code execution — so it is not malware in the conventional sense. However, it is inherently dual-use: when run with valid credentials against a GoPhish server it can create and manage phishing campaigns, which can be abused. Primary security concerns in this file are disabled TLS verification (verify=False and suppressed warnings), exposure of API keys via CLI arguments, lack of input validation, and absence of confirmation/auditing around campaign creation. Recommend enabling TLS verification, avoid passing API keys on command lines (use env vars or secured prompting), validate inputs (URLs and ids), and add confirmation/logging for destructive operations.
This script is an automation wrapper for LiME and Volatility 3 and contains expected high-risk operations for memory forensics (kernel module insertion and execution of external tooling). The code itself does not show explicit malicious intent or obfuscation, but it performs dangerous actions if untrusted artifacts are provided or if executed with excessive privileges. Recommendations: only run with verified/signed LiME kernel modules and Volatility binaries from trusted sources; avoid executing insmod on production systems — use isolated analysis hosts; validate and protect the generated report (sensitive data); consider adding integrity checks (hash/signature) for external binaries and modules and add clearer privilege/use warnings and safer path handling.
This skill is a high-risk offensive red-team capability that centers on credential dumping, Kerberos ticket forgery, and persistence in Active Directory. Its actual footprint is fully aligned with unauthorized domain compromise, making it inappropriate for general AI agent use and dangerous even without hidden behavior.
This module is an automation agent for the GoPhish phishing platform. It purposely creates phishing artifacts (email templates, credential-capturing landing pages), uploads target lists, and can launch campaigns that harvest credentials. The code is not obfuscated and contains no covert exfiltration mechanisms, but it enables high-impact malicious activity (credential theft, mass phishing). Operational security issues include disabled TLS verification, lack of input validation, plain handling of secrets, and logging that can leak sensitive identifiers. Use only in authorized, consented red-team or training contexts; otherwise treat as dangerous and avoid execution.
This skill appears purpose-aligned as a parallel orchestration tool, not overt malware. The main risks are autonomous high-impact actions (mass parallel edits, tests, and commits), prompt-injection exposure from plan/repo content, and moderate trust concerns around external npx-based installation flows referenced outside the skill body. Overall classification: SUSPICIOUS due to disproportionate automation and weak safety constraints, but not confirmed malicious.
This skill is a high-risk offensive security playbook that equips an AI agent to exploit an AD privilege-escalation chain, impersonate administrators, dump domain credentials, and obtain DC-level access. Its capabilities are coherent with its stated red-team purpose, but that purpose itself is dangerous and unsuitable for general agent deployment.
This script is an offensive AD pentest automation tool that shells out to known offensive utilities (impacket, bloodhound-python, certipy, netexec). The code itself does not implement hidden backdoors or network exfiltration, but it handles credentials insecurely (passing them on command line) and will perform sensitive and potentially destructive AD enumeration and hash collection when run with valid credentials. It is dual-use: legitimate for authorized security testing, but dangerous if used by unauthorized actors. Recommend auditing usage, avoiding passing plaintext credentials on command-line (use more secure methods supported by tools), and restrict execution to authorized personnel and environments.
This module is an active packet injection and network reconnaissance tool that implements multiple offensive techniques (port scans, malformed packets, IP spoofing, LAND attack, fragmentation overlap, TTL evasion). It is dual-use: it can be used for legitimate security testing but also for unauthorized scanning and attacks. There is no obfuscation or hidden backdoor, but the capability to send spoofed and malformed packets makes it high risk if run against third-party systems without permission. Use only in authorized testing environments and with appropriate safeguards and permissions.
This script is a dual-use forced-browsing and sensitive-file discovery utility: it is not obfuscated and contains no explicit backdoor, remote C2, or obvious malware behaviors. It intentionally probes for exposed configuration files and admin paths and can aid attackers or defenders depending on usage. Primary security issues: disabled SSL verification, no rate limiting, crude auth-bypass heuristic, and potential accidental disclosure of a session cookie or discovered sensitive contents via the generated report. Recommend adding HTTPS verification by default, optional rate-limiting/delays, better auth-bypass heuristics (content hashing, fingerprints), output sanitization for secrets, and explicit user warnings about legal/authorized testing.
SUSPICIOUS: the skill is an offensive exploitation runbook that enables unauthenticated domain controller compromise, credential dumping, and remote admin access. Its capabilities are internally consistent with its stated red-team purpose, but giving an AI agent exploit and credential-theft instructions makes it high risk and unsuitable for general deployment.
This module is a GraphQL testing/probing utility with explicit offensive framing. It is dual-use: suitable for authorized security testing but also readily usable to perform resource-exhaustion or denial-of-service style probes against GraphQL servers. No signs of traditional malware (backdoor, credential theft, obfuscated payloads, or hard-coded exfiltration domains) are present in the file. Primary risks are operational/abuse-related (unthrottled heavy queries) and accidental credential forwarding when Authorization headers are supplied. Use only against systems you are authorized to test and avoid supplying production credentials.
This document is a high-confidence malicious spearphishing playbook. It contains step-by-step instructions to create phishing infrastructure, craft convincing emails and landing pages to harvest credentials, deliver and execute malware payloads (HTML smuggling, macros, ISO/LNK chains), and evade defenses (SPF/DKIM/DMARC, SSL, typosquatting, obfuscation). It explicitly instructs capturing passwords and setting up C2/callbacks. This content should be treated as malicious operational guidance and not used in production; hosting or executing any of these steps would facilitate targeted compromise. Recommend immediate removal/blocking, reporting to relevant abuse channels, and further investigation of any artifacts or domains used.
This module implements active MITM behavior (ARP poisoning) and passive network sniffing with report generation. The code is not obfuscated and contains no obvious hidden exfiltration, but it includes dangerous functionality that can perform unauthorized interception and alteration of LAN traffic if executed with sufficient privileges. Use only in authorized testing environments. Safeguards (consent checks, privilege checks, explicit warnings) are missing and TLS verification is disabled in one check. The code is dual-use: potentially legitimate for security testing but high risk if misused or included inadvertently.
The skill is purpose-aligned for defensive malware analysis and does not itself exfiltrate data or install payloads, so it is not malicious. Its main risk comes from giving an AI agent reverse-engineering capability against RAT samples and from referencing some archived analysis tools; overall this is a high-risk security skill but not a credential-harvesting or covert-exfiltration skill.
This module is a security testing tool that both detects serialized blobs and contains active exploit probes intended to confirm insecure deserialization (including a Python pickle that triggers os.system('nslookup ...') on the remote if unpickled). It is dual-use: useful for defenders and auditors, but potentially dangerous if run against systems without authorization. Key risks: active remote code execution payloads, disabled TLS verification, and lack of safeguards. No evidence of self-contained malware or obfuscated backdoors, but the active probe functions are explicit attack vectors and should only be used with permission.
High-risk offensive skill. Its purpose and capabilities align, but that purpose is to conduct AiTM phishing, steal credentials/session cookies, bypass MFA, and hijack accounts. The install source is only mildly risky; the dominant issue is explicit attack enablement and theft of authentication material.
SUSPICIOUS: The skill is internally aligned with malware-analysis use, and the sample client mainly talks to an expected CAPE API. However, it grants an AI agent high-risk offensive-security-adjacent capability, can upload samples to arbitrary CAPE endpoints, and references mutable same-org installer scripts without strong release verification. Not confirmed malware, but risky and should be tightly scoped to controlled local environments.
BENIGN but high-risk in operation: the skill is internally consistent and uses official Aqua Security sources, with no clear credential harvesting or covert exfiltration. Main concerns are that it grants an AI agent Kubernetes security-audit capability, needs broad cluster privileges, and uses unpinned raw manifests plus a download/install path without checksum verification.
SUSPICIOUS. The skill’s purpose, GitHub-focused capabilities, and official data destinations are broadly coherent and there is no clear exfiltration or third-party interception in the provided text. However, it uses a repo-scoped PAT and executes unsupplied local bash scripts that register secrets and perform assignment, so trust depends on unseen credential-handling code; that uncertainty and autonomous repo-changing behavior make it medium risk rather than benign.
This script is a utility for extracting credentials and cookies from EvilGinx3 session capture files and exporting them in browser-compatible formats. It does not itself perform network exfiltration or run obfuscated/malicious system commands, but it explicitly processes and persists highly sensitive data (usernames, passwords, session cookies) which can be used to hijack accounts. Use of this code in a project or as a dependency carries significant risk because it facilitates credential theft and reuse; treat it as a high-risk utility and review intent and provenance before including or running it.
This script is a straightforward parser and reporter for NTDS/secretsdump outputs that extracts NTLM hashes and cleartext credentials, detects password reuse, and produces a human-readable DCSync analysis report. There is no built-in network exfiltration or overtly malicious code, but the tool explicitly surfaces high-value artifacts (KRBTGT and Administrator NT hashes) and includes attacker-focused persistence guidance. The primary risk is operational/abuse risk (dual-use): it facilitates post-compromise activity if provided with stolen dumps. Treat the code as sensitive tooling: acceptable for controlled defensive incident-response use but high-risk if distributed without controls or used by malicious actors. Recommend restricting access to input files, encrypting/storing reports securely, and removing or rephrasing offensive guidance strings in defensive distributions.
This module is an offensive, dual-use pentest helper: it performs active port probes, calls nmap, and can enumerate AD using credentials supplied by the operator. I found no indicators of covert malware (no C2, no obfuscated payloads, no reverse shell logic). The main security risks are misuse and sensitive-data leakage: the script accepts plaintext AD credentials and may persist enumeration results to disk or stdout without redaction, and it explicitly recommends using Responder (an active credential-capture tool). Treat as a tool for authorized testing only; do not run in production or with real credentials unless permitted. Add safeguards: confirmatory prompts before high-risk actions, avoid writing credentials to disk, sanitize reports, and document intended usage and authorization requirements.
This module is a dual-use AD assessment orchestration script. The code itself does not contain hidden backdoors or dynamic obfuscation, but it intentionally invokes offensive collectors and sends user-supplied Cypher to Neo4j. Key risks: credentials passed on the command line (exposure via ps), insecure default Neo4j credentials, potential reading/writing of arbitrary JSON files if analyze_dir/output are attacker-controlled, and inclusion of potentially sensitive collector output in saved/printed reports. Use only in authorized test environments; remove or override insecure defaults and avoid passing secrets on CLI in production.
The module is a legitimate Active Directory auditing/detection utility with no clear malicious code patterns. Primary risks are operational: plaintext credential handling on the command line, potential lack of TLS for LDAP transport, and reliance on a coarse heuristic (adminCount=1) that can produce false positives. It is dual-use — useful for defenders but could assist an attacker who already possesses valid credentials. No evidence of covert exfiltration, obfuscation, or backdoor behavior in the inspected file.
SUSPICIOUS: the skill’s image-generation purpose is plausible, but it relies on a proprietary intermediary CLI, routes data through inference.sh instead of Alibaba directly, and instructs transitive skill installation. This is not confirmed malware, but the install path and credential/data forwarding make the trust model materially riskier than a direct API skill.
The Python fragment is a utility to prepare and optionally execute Frida-based SSL pinning bypasses. The code facilitates injection of JS into mobile apps, which is a powerful capability: it can be used legitimately for testing but is easily abused for interception or secret extraction. The provided fragment lacks the actual Frida payloads (placeholders are empty) so it is not runnable as-is; however, the true security impact depends entirely on the contents of ANDROID_BYPASS_SCRIPT and IOS_BYPASS_SCRIPT. Immediate issues: predictable temp file usage, lack of input validation, and a brittle command construction/execution pattern. No explicit data-exfiltration or network communication is present in the Python file itself, but the tool is high-risk in its intended function and must be treated as potentially dangerous depending on payloads and operator intent.
This module is intentionally malicious: it is a social-engineering pretext call planner whose templates explicitly instruct soliciting passwords, MFA codes, admin credentials, and coercing financial transfers. While it contains no obfuscated code, network connections, or technical exploits, its functionality directly facilitates fraud and credential theft and thus constitutes a high-risk malicious artifact. Do not include this code in libraries or share it in software supply chains; remove and treat as malicious tooling.
This module is an offensive-security wrapper that automates Kerberoasting tasks by invoking external tools (Impacket GetUserSPNs.py, PowerShell, and hashcat). The code is not obfuscated and contains no clear hidden backdoor, but it has insecure practices (passing credentials on the command line) and will perform potentially harmful actions against Active Directory if used with real credentials. Use of this code presents a moderate security risk: it is dangerous in adversarial hands or if executed inappropriately, and it depends on external binaries which pose supply-chain risk. The code itself appears not to be malware but is a facilitator for offensive operations.
SUSPICIOUS. The core purpose is coherent for a multi-LLM planning orchestrator, and the documented vendor CLIs appear to come from official same-org sources. However, the skill has elevated risk because it explores the local codebase, forwards content to multiple external LLM CLIs, supports arbitrary custom command execution, references an unseen setup.sh, and instructs the agent to remain active for long periods without yielding. This looks more like a high-risk orchestration skill than malware, but its scope and execution model exceed what many users would expect from a planning helper.
This skill is not a benign red-team guide for constrained review; it explicitly enables AI-driven spearphishing, credential theft, MFA bypass, malicious payload delivery, and C2-enabled compromise. Its capabilities are fundamentally offensive and disproportionate to safe agent use, making it high risk and effectively malicious in purpose.
This artifact is a high-risk operational playbook for conducting vishing-based social engineering campaigns. It contains actionable, role-tailored pretexts (including CEO/wire-transfer fraud), normalization of caller ID spoofing, and measurement-driven optimization of deception. The document enables financial fraud, unauthorized access, and privacy violations. If found in code or project repositories, treat as malicious or highly suspicious content: remove, audit repository history, identify authors, and verify legitimate authorized testing scope before any use.
This document is a clear, actionable offensive playbook for Kerberoasting and post-exploitation against Active Directory. It enumerates data sources, shows how to obtain and persist TGS hashes, provides detailed cracking configurations, and demonstrates credential reuse for lateral movement and DCSync. It also contains OPSEC tips to evade detection. Treat distribution or execution of these instructions as high risk: they facilitate credential theft, privilege escalation, and domain compromise. Defensive teams should monitor for the enumerated behaviors and commands and treat artifacts matching these patterns as potential compromise indicators.
SUSPICIOUS. The skill’s capabilities match its stated purpose, and the `infsh` dependency appears to be an official same-org tool with some release verification evidence, so this is not strongly indicative of malware. However, it enables autonomous social-media actions, routes access through a third-party CLI/service rather than direct official X API usage, and includes transitive skill installation, making the overall risk medium.
The artifact is a clear operational playbook for offensive C2 operations. While it can be legitimate for authorized red-team engagements, the document contains explicit guidance for payload delivery, lateral movement, evasion, and cleanup that make it high-risk if discovered in a software dependency or public repository. The file should be treated as sensitive: remove from public packages/repos, audit related artifacts (payloads, keys), and verify authorization before use. Mitigations include removing plaintext credentials, restricting repository access, and ensuring such templates are tracked only in controlled, legal engagements.
This document is a high-risk exploitation playbook for CVE-2020-1472 (Zerologon) that provides actionable steps to reset a DC machine account password to empty, perform DCSync to extract all domain credential hashes (including krbtgt), and obtain full domain compromise via Pass-the-Hash and Golden Ticket techniques. It should be treated as offensive material: if present where not explicitly authorized, consider it a security incident, remove sensitive content, and investigate authorship and intent. If used for authorized testing, enforce strict approvals, monitoring, and immediate restoration procedures.
SUSPICIOUS: the skill’s purpose is coherent as a readability helper, but its core behavior routes arbitrary website access through an unrelated third-party proxy. That intermediary data flow is the main risk; there is no evidence of malware or remote code execution, but privacy and prompt-injection exposure are materially elevated.
This file is a clear privilege-escalation playbook containing actionable steps to enumerate and escalate privileges on Linux systems, including remote downloads and execution of tools, SUID/sudo abuse, kernel exploit usage, creation of SUID binaries, LD_PRELOAD abuse, cron PATH hijacking, Docker/NFS escapes. It is dual-use but poses a high security risk if used maliciously. Treat as dangerous guidance and do not execute these instructions on systems without explicit authorization.
SUSPICIOUS: The skill’s capabilities largely match its stated purpose, but it relies on installing and trusting a third-party personal-publisher CLI that can access sensitive email contents. Scope is mostly proportionate for disposable inbox automation, yet the external CLI provenance and opaque handling of mailbox credentials/content raise medium supply-chain and privacy risk.
This file is an explicit, operational playbook for Pass-the-Ticket attacks using known offensive tools (Mimikatz, Rubeus, Impacket). It instructs how to extract, convert, inject, and forge Kerberos tickets to impersonate privileged accounts and perform lateral movement and persistence. The content should be treated as malicious: presence of these commands, scripts, or associated binaries in an environment is a high-severity indicator requiring immediate investigation and containment. Monitor for the listed detection indicators and assume compromise if these actions are observed.
SUSPICIOUS: the skill’s purpose and capabilities mostly align, but its core function depends on a third-party proxy service (gitmcp.io) instead of direct GitHub access, and it can fetch arbitrary external URLs from repo docs. No credential theft or overtly malicious behavior is shown, so this is better classified as medium security risk than malware.
This is an explicit Kubernetes penetration-testing playbook describing reconnaissance, exploitation, privilege escalation, lateral movement, and cleanup. It contains actionable offensive steps (token theft, privileged pod deployment, querying cloud metadata) that are operationally dangerous if used without authorization. The content is not executable malware, nor obfuscated, but it presents a moderate-to-high security risk if published or used improperly because it enables attackers to find and exploit misconfigurations. Use only in authorized testing contexts and ensure proper safeguards and auditability when applying these actions.
This code is a dual-use AD auditing/offensive tool that enumerates forest trusts and resolves cross-forest SIDs via LDAP and LSAT MSRPC calls. It does not present obvious signs of hidden backdoors or obfuscation in the provided fragment, but it performs powerful, sensitive operations that can be abused to facilitate lateral movement and privilege escalation. Treat as high-risk for inclusion in general-purpose dependencies: restrict usage to controlled environments, avoid passing plaintext credentials via CLI, and ensure output reports are stored/transmitted securely. Consider additional safeguards (credential prompting, ephemeral credentials, strict logging controls, and code review) before deployment.
SUSPICIOUS but not malicious. The skill is internally coherent and uses mostly legitimate install paths, but it enables an AI agent to run specialized security-analysis tooling, which raises inherent risk despite the absence of credential theft, covert behavior, or suspicious data routing.
This is a high-value offensive/defensive reference describing precise IAM/STS API calls and tools that enable privilege escalation and persistence in AWS accounts. While not malicious code by itself, it is highly actionable: with valid credentials it provides a clear roadmap for compromising AWS privileges. Use only in authorized testing with proper approvals and monitoring; defenders should use the document to hunt for the listed misuse patterns and harden IAM policies, enable logging/alerts, and enforce least privilege.
BENIGN for stated purpose but high-impact. The skill is internally consistent: official python-gvm install path, official Greenbone data flows, and proportionate credentials. Main risk is not hidden malware behavior but granting an AI agent live vulnerability-scanning capability against real hosts.
BENIGN but high-risk dual-use. The skill’s file access and privileges are proportionate to Linux persistence analysis, and its data flow stays local with no suspicious installer or credential routing. The main concern is that it grants an AI agent privileged threat-hunting capability over sensitive system areas, which raises security risk but is consistent with the stated purpose.
This document is a high-confidence operational playbook for deploying and operating a C2 infrastructure (Sliver) and managing implants for post-exploitation. It provides explicit, actionable guidance to generate and deploy implants, evade detection, and maintain resilient covert channels for remote control and data exfiltration. The artifact itself is not executable code but materially enables severe malicious activity if used against unauthorized targets. Treat any associated code, operator config files, or generated implants as high-risk; protect or remove such artifacts from trusted supply chains and perform in-depth review of any binaries or scripts produced following these instructions.
SUSPICIOUS: The overall purpose is legitimate and network flow targets the official Context7 service, but the skill is not fully coherent with a low-risk docs helper because it instructs secret-file discovery from hidden .env files and uses an undocumented local Python wrapper whose provenance is unclear. Main risk is credential handling and local wrapper trust, not confirmed malware.
This is an informed analyst playbook for extracting Agent Tesla configuration and indicators. It contains actionable, dual-use detection and extraction patterns (regexes, YARA rule, decompiler tips) that are valuable for defenders but could be misused by adversaries. The document itself is non-executable and does not contain hardcoded secrets or obfuscated payloads, but it advises workflows (uploads to VirusTotal/sandboxes) that can leak sample metadata or recovered credentials if performed without proper isolation. Treat as sensitive threat intelligence, restrict distribution, and perform any analysis in isolated environments; avoid uploading sensitive artifacts to public services without authorization.
This document is an instructional guide describing Kerberoasting techniques and commands for extracting Kerberos TGS hashes and cracking them offline. It contains dual-use offensive guidance: not malicious code itself, but it facilitates credential theft and unauthorized access when executed by an attacker. Use of the described commands and passing credentials on the command line pose operational security risks. Defenders should monitor EventID 4769 and apply recommended mitigations (gMSA, strong passwords, disable RC4) to reduce risk.
The described agent is a legitimate ransomware incident-response automation tool that provides high-value defender functionality (identification, enrichment, containment, and search). There is no clear evidence of intentionally malicious code in the provided description. However, the capability to upload samples to public repositories and to execute CrowdStrike 'contain' actions without described safeguards creates moderate-to-high operational and privacy risks if misused or executed with exposed credentials. Treat the tool as powerful but sensitive: enforce secure handling of secrets, explicit opt-ins for sample uploads, confirmation for destructive actions, and auditing before deployment in production.
This document is a practical, actionable guide that enumerates multiple, well-known techniques to bypass API rate limits and identifies header and URL manipulation vectors. It does not contain executable malware or obfuscated code, but it clearly enables abusive behavior (resource exhaustion, large-scale scraping, evasion of throttling) when used against third-party APIs. Treat as high-risk guidance: restrict distribution, apply access controls, and audit any code that automates these techniques. Recommended mitigations: enforce auth-based rate limits, canonicalize inputs (paths, query params, encoding), ignore or sanitize untrusted client IP headers, apply consistent enforcement across methods/versions, and log/alert on anomalous header rotations or encoding patterns.
This document is an actionable offensive playbook for enumerating and abusing Kerberos delegation (S4U and RBCD). While it contains defender-oriented detection pointers, the inclusion of exact commands to acquire or forge Kerberos tickets and to write RBCD attributes enables high-impact attacks (privilege escalation, lateral movement, persistent impersonation) if executed in an Active Directory environment. The text itself is not executable malware, but it materially facilitates severe compromise and should be treated as high-risk instructional material; distribution or execution in production environments without explicit, authorized testing controls is dangerous.
This artifact is an exploitation guide for the ESC1 AD CS misconfiguration (enrollee-supplies-subject/SAN combined with Client Authentication EKU and permissive enrollment). It contains actionable commands to discover vulnerable templates and request certificates that impersonate privileged accounts. The content should be treated as high-sensitivity operational guidance: defenders should audit templates, remove enrollee-supplies flags, enforce manager approval and restrictive enrollment ACLs, and enable CA auditing. The file itself is not malware, but it documents a realistic and high-impact attack path if environment is misconfigured.
The snippet is a dual-use security guide: it correctly recommends defusedxml to mitigate XXE risks but also provides explicit offensive XXE payloads and testing instructions that are actionable. The content itself is not malware, but it enables potential exploitation if used against vulnerable or unauthorized targets. Use the offensive examples only in authorized test environments and apply recommended mitigations in production (disable DTD/external entities, restrict outbound network access).
This document is an explicit, high-risk malicious playbook for AiTM phishing and session hijacking using EvilGinx3 and cookie import tools. It provides actionable steps to bypass MFA, import stolen session cookies, and establish persistence inside tenant accounts. Treat as malicious content: remove, investigate, and remediate any deployments or artifacts that implement these instructions.
This file is an offensive-focused injection testing playbook: it enumerates SQL/NoSQL/command payloads, shows how to deliver them (Python requests, Burp API), and how to interpret responses. The fragment is dual-use—acceptable for authorized security testing—but contains insecure practices (TLS disabled) and provides actionable exploit strings that facilitate abuse if used without consent. The text itself is not active malware, but its inclusion in a package that automates execution without safeguards would constitute a significant supply-chain risk. Recommend: treat as high-abuse documentation; ensure any accompanying tooling requires explicit authorization, logging, rate-limiting, and secure defaults (enable TLS validation), and include defensive examples and legal/ethical usage warnings.
This file is a clear, actionable exploitation playbook for MS17-010 (EternalBlue) that provides stepwise instructions for discovery, exploitation, credential theft, persistence, and lateral movement. The content directly facilitates high-impact compromise and data exfiltration. It should not be included in production dependencies or distributed without strict access controls and explicit, authorized use-case context (e.g., controlled red-team or lab training with documented permission). If discovered in a project without benign intent documentation, treat it as a serious security risk and remove or quarantine.
This document is a non-executable configuration/template designed to plan and record deployment of Sliver C2 infrastructure. The file itself is not malware, contains no obfuscation or hard-coded secrets, but it explicitly facilitates deployment of offensive remote-access infrastructure. It is high-risk if used by unauthorized actors. Treat occurrences as sensitive: validate authorization, and if filled-in deployments exist, perform a security audit of the configured endpoints, certificate/key handling, and operator access mechanisms.
This specification documents an offensive Active Directory assessment agent that, if implemented, would perform sensitive reconnaissance and credential-theft enabling actions (Kerberoast, AS-REP roast, SMB signing checks, possible DCSync). The artifact is dual-use: acceptable for authorized red-team/defensive assessments, but dangerous if used without authorization or with production/high-privilege credentials. The provided text itself contains no obfuscated or hidden malicious code, but it prescribes high-risk operations and lacks documented safety controls — handle strictly in authorized, isolated environments and avoid passing plaintext credentials on CLI.
This agent is a dual-use insecure deserialization detection tool that combines safe passive detection with high-impact active tests that create attacker-observable OOB callbacks. The code fragment description does not show hidden obfuscation or local credential theft, but includes intentionally malicious payload generation for detection which can be abused. Use only with explicit permission, restrict callback hosts and target scope, and add operational controls (authorization checks, logging, rate limits, passive-only mode) to reduce misuse risk.
This is an explicit exploitation playbook describing how to abuse AD CS (ESC1) misconfigurations to obtain privileged domain credentials and perform DCSync/credential dumping. It is actionable and high-risk if used against production environments. Use of these steps constitutes offensive activity unless performed under authorized testing. Recommend treating packages or automation implementing these steps as malicious or high-risk in untrusted contexts and only use in authorized labs with consent.
This document describes a dual-use SQL injection assessment agent (offensive security tool). The specification itself contains no explicit indicators of malware — no obfuscated code, hardcoded credentials, or external C2 endpoints are present. However, the described behavior is actively intrusive (injection payloads, sleep-based probes, UNION-based data extraction) and can cause service impact or data disclosure if used without explicit authorization. Before deployment, review the implementation for safe defaults (rate-limiting, consent checks, secure output handling), validate logs and file writes for sensitive data leakage, and ensure usage is authorized. Treat as a high operational risk tool rather than intrinsic malware.
This is a non-executable reference document describing privilege-escalation enumeration commands, MITRE techniques, and helpful libraries/resources. It is not itself malicious code and contains no programmatic sources or sinks. However, the content is actionable and dual-use: it could be used for legitimate security assessments or abused by attackers. Treat it as a guidance artifact rather than executable code; if incorporated into a runtime dependency that executes commands, that runtime code should be audited carefully.
This tool is a dual-use SSRF assessment agent that explicitly contains high-risk test capabilities (cloud metadata probing, internal port scanning, alternate protocol testing). The provided fragment shows no signs of obfuscation or deliberate malicious backdoors in itself, but its features can be weaponized if misused. Use strictly in authorized contexts and review the full implementation for safeguards (consent, rate limiting, careful defaults, no exfiltration helpers) before deployment.
The described agent is not intrinsically exfiltrative or covert, but it performs high-impact privileged operations (creating policies and attaching permission boundaries) and documents a DenyBoundaryChanges control that could cause administrative lockout if misconfigured or maliciously modified. Treat the package as operationally dangerous: require strict code review, execution controls, dry-run and approval workflows, narrow scoping of generated policies, and sandbox testing before any production use. The risk arises from misuse or supply-chain tampering rather than signs of built-in malware.
This code appears to be a dual-use local privilege-escalation enumeration tool: not intrinsically malicious (no clear network exfiltration or obfuscation described) but intentionally prescriptive about exploitable vectors (GTFOBins, dangerous sudo patterns, writable cron scripts). It poses a meaningful security risk if executed by untrusted users or included as a dependency in contexts with elevated privileges because it packages actionable escalation knowledge. Recommended actions: restrict execution to trusted auditors, review full implementation for any automated exploitation or network features, and avoid bundling into production components accessible to untrusted parties.
SUSPICIOUS: The skill is internally aligned with Linux memory forensics and does not show overt credential exfiltration or third-party routing, but it grants an AI agent powerful security/IR capabilities on compromised systems and relies on a less-verifiable LiME acquisition path. Volatility 3 provenance looks normal; overall risk is driven by offensive-adjacent security tooling and sensitive memory access rather than clear malware behavior.
The described agent is a legitimate IPv6 assessment utility that actively probes and passively sniffs the local network and reads ip6tables output. The fragment contains no explicit malicious code or obfuscation. However, because it requires elevated privileges and gathers sensitive local network topology and router information, it poses a moderate security risk if sourced from an untrusted or tampered package. Verify provenance, audit the implementation, and run in an isolated environment before using with sudo.
This package is a dual-use red-team planning utility that downloads MITRE ATT&CK STIX data, maps techniques for an emulated actor, and generates operation plans. The code as described does not itself perform exploitation or exfiltration, nor does it exhibit obfuscation. Primary concerns are: (1) supply-chain risk from downloading live JSON without integrity checks, and (2) the potential for misuse because it produces detailed operational plans. Apply integrity verification, add usage controls/auditing, and treat generated outputs as sensitive.
The fragment documents an active SSTI detection/exploitation agent that intentionally sends engine-specific template payloads and includes explicit RCE and secret-exfiltration payloads. This is dual-use tooling: appropriate for authorized security assessments but dangerous if used without permission. No obfuscation or embedded C2 infrastructure is present in the specification, but the absence of operational safeguards (consent checks, safe-mode) increases the risk of misuse. Treat this package as high-impact offensive tooling; require explicit authorization and auditing before use.
The described module is an explicit offensive/tooling utility to craft and test forged JWTs exploiting 'alg=none' acceptance and RS256->HS256 algorithm confusion. It enables automated probing of endpoints with forged tokens, which can facilitate authentication bypass and privilege escalation on vulnerable services. There are no hidden obfuscation or data-exfiltration behaviors evident in the fragment; however, its presence in a dependency or CI environment represents a meaningful security risk because it provides ready-made exploitation capabilities. Use should be restricted to authorized security testing contexts and isolated environments; inclusion in general-purpose dependencies or production CI workflows is ill-advised.
The code demonstrates threat-emulation tooling that can perform remote code execution and access credential-related utilities. While intended for controlled testing, these capabilities introduce significant risk if misused or exposed publicly. Strict controls, environment isolation, input whitelisting, signed atomics, and explicit user consent are essential to mitigate potential abuse and supply-chain risks.
The fragment describes a comprehensive credential harvesting and post-compromise workflow with clear pathways for privilege escalation, extraction, validation, and lateral movement. While it may reflect red-team testing, its presence in a library or package that could be publicly distributed constitutes high-risk content requiring removal or strict sanitization, access controls, and governance before inclusion in any open-source or supply-chain context.
The reviewed code is a focused GraphQL probing and stress-testing utility that constructs deep, wide, circular, and batched queries to detect missing depth limits and to find amplification vectors. It does not show signs of traditional malware (no persistence, no exfiltration, no C2), but it is a high-risk dual-use tool that can be abused to perform denial-of-service attacks or to enumerate weaknesses when used without authorization or safeguards. Treat as potentially dangerous for use against third-party or production endpoints and enforce strict operational controls when used for legitimate security testing.
This code is a clear, readable demonstration of Scapy packet crafting and sending. It is not itself obfuscated, nor does it contain typical malware behaviors (no C2, no local data exfiltration, no credential harvesting). However, it shows powerful, dual-use network capabilities (SYN sending, fire-and-forget sends, and sending many large fragments) that can be misused for unauthorized scanning, evasion, or DoS. Treat the examples as dangerous to run against systems you do not own or have permission to test; use only in controlled/test environments and include rate limiting and authorization checks in real tooling.
The fragment serves as a legitimate tooling reference for conducting phishing simulations via the GoPhish API. It does not itself execute malicious code but introduces capabilities that could be misused for credential harvesting if deployed without proper controls. Security posture should emphasize authorization, consent, access controls, logging, and secure handling of credentials and collected data during campaigns.
This fragment is an API/CLI reference for the Sliver C2 framework describing how to generate implants, configure listeners, and perform post-exploitation actions. The text itself is non-executable documentation but documents clear offensive capabilities (remote code execution, DLL sideloading, shell access, file transfer, proxying) that, if implemented, present significant security risks. Treat any corresponding implementation, binaries, or packages as high-risk: they should only be used in authorized red-team or controlled lab environments, and code/artifacts should be audited before inclusion in a supply chain or production environment.
The code/document fragment is defense-oriented, compiling patterns and references for detecting Mimikatz-related activity. It does not contain executable payload, backdoors, or data exfiltration logic. Its supply-chain risk is low, primarily related to potential accidental exposure of sensitive detection details in dashboards, but it remains a valuable reference for defenders when included in a secure repository.
This code snippet is not itself malware, but it demonstrates insecure practices that create a meaningful security risk: hardcoded administrative credentials and disabled TLS certificate verification. In a supply-chain context these issues can lead to credential leakage and unauthorized access to the Cisco ISE appliance. Recommended remediation: remove hardcoded secrets (use environment variables, secret managers, or OS key stores), enable TLS verification (or implement certificate pinning), avoid committing secrets to VCS, and add error handling and secure logging. Treat any real credentials found here as compromised and rotate them.
This is a non-executable design document describing an OT-aware scanning agent. The concept demonstrates safe-minded controls (passive discovery, rate limits, skip high-risk protocols, conservative nmap timing), but critical security-relevant implementation details are missing. Primary risks are unsafe subprocess invocation (command injection), lack of enforced scoping/allowlists (unauthorized scanning), insecure handling/storage of captured data, and insufficient runtime enforcement of forbidden ports/timing. I find no explicit malicious indicators in the spec itself, but the agent would be dual-use and requires a careful implementation review. Treat as moderate security risk until the concrete code follows safe subprocess usage, input validation, strict enforcement of forbidden scans, and secure handling of outputs.
The document is a clear, practical guide to bypassing mobile certificate pinning using widely available tooling (Objection, Frida) and binary/manifest modification. The content is dual-use: it supports authorized security testing but directly enables man-in-the-middle interception of TLS traffic and exfiltration of sensitive data if misused. There are no direct malware indicators in the text, but the operational techniques described pose significant security risk and should be restricted to authorized, legal testing environments with safeguards and auditing.
This package is a dual-use certificate-pinning detection and bypass toolkit. It intentionally disables critical TLS verification routines at runtime (via Frida/Objection) and executes system tooling via subprocess. While not containing direct exfiltration or backdoor code in the provided fragment, it materially weakens app security and therefore poses a significant operational risk if misused or run with untrusted inputs. Recommended controls: restrict execution to authorized testers, validate/sanitize all CLI inputs before passing to subprocess, avoid installing in CI/build hosts or restrict access, and log/monitor usage.
The content presents a high-risk, attacker-oriented blueprint for DCSync and Golden Ticket techniques. It is valuable for defensive threat modeling but inappropriate for public distribution in its current form. Recommend removing or redacting actionable details from public-facing materials, while preserving high-level awareness, and pairing with concrete defenses (monitoring, least privilege, privileged access management, and robust ticket lifecycle controls).
This Markdown template is an operational playbook for running phishing campaigns with EvilGinx3. It explicitly guides attackers to collect credentials and session cookies, bypass MFA, export artifacts, and document post-authentication access. Although non-executable, it materially facilitates malicious activity and should be treated as high risk. If found in a repository or on a host, escalate to incident response, remove the document from public access, and audit related artifacts and infrastructure for compromise. If the file is claimed to be part of an authorized engagement, require written authorization and scope documentation before retention or use.
This file is a concise Active Directory offensive testing playbook outlining reconnaissance (enumeration), Kerberos and ADCS attacks, credential harvesting, domain escalation, and impact demonstration. The fragment is non-executable documentation and contains no hardcoded credentials or obfuscated code, but it provides explicit, actionable guidance for compromising AD environments. As a high-sensitivity dual-use document, it should be handled with caution: benign in an authorized pentest context, dangerous if used by unauthorized actors. Further investigation of associated tooling or repository context is recommended.
This playbook is a detailed, actionable social-engineering/phishing campaign workflow that maps data sources to collection sinks and outlines attacker infrastructure and tactics. It is dual-use: appropriate under tightly scoped, authorized penetration tests with documented legal and data handling safeguards; dangerous if used without authorization. Key deficiencies are the lack of explicit, enforceable safeguards (consent, minimization, retention, destruction, and legal boundaries). No code-level obfuscation or embedded secrets detected in the document itself, but the guidance materially enables credential/session theft and privacy violations. Recommend restricting distribution, adding mandatory legal/consent procedures, and including safe-handling and minimization controls if retained for legitimate use.
The document is a clear offensive NoSQL injection playbook that provides practical, stepwise methods to discover, confirm, and extract data from vulnerable NoSQL-backed applications and to attempt remote code execution where server-side JS is enabled. It poses a high security risk if distributed within a codebase or package; it should be treated as malicious/inappropriate content for benign libraries and handled by security teams accordingly.
The described tool is a dual-use security-testing utility that enumerates GraphQL schemas and probes for missing depth limits. The provided fragment contains no explicit signs of obfuscation, hardcoded credentials, or exfiltration, but its functionality is explicitly offensive-capable and can be misused to discover sensitive fields or to conduct resource-exhaustion attacks. Before use or inclusion in a supply chain, review the actual implementation for logging/exfiltration, credential handling, built-in safeguards (consent, rate limits, redaction), and ensure usage is limited to authorized testing contexts.
This fragment is a high-risk, actionable description of Kerberos constrained delegation abuse and an SPN-modification technique to achieve domain escalation (DCSync). It is not executable code, so there are no immediate code-level indicators (secrets, network calls, obfuscation), but the operational guidance can enable full domain compromise by a malicious actor with sufficient access. Treat presence of such instructions as sensitive: restrict access, add clear research/lab labeling and mitigations, or remove if not appropriate for the repository's audience.
This artifact is an explicit malicious lateral-movement playbook detailing credential theft (Mimikatz/LaZagne/SAM dumps), account enumeration, and iterative pivoting using WMIExec with operational fallbacks. It describes high-risk post-exploitation techniques intended to achieve remote code execution and domain compromise. Without clear authorized red-team context and controls, treat as malicious guidance and investigate any implementation or distribution.
This fragment is a high-risk offensive playbook describing concrete steps to impersonate domain controllers, harvest AD credentials (including KRBTGT), and achieve persistent Golden Ticket access. The document should be treated as potentially malicious or dual-use: do not include in public/production dependencies, restrict distribution to authorized red-team/defensive contexts with legal authorization, and flag repositories containing this text for security review and access controls.