hunt-deserialization
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads specialized security tools from third-party GitHub repositories, including ysoserial, phpggc, and JNDI-Exploit-Kit, to support vulnerability scanning and exploitation.\n- [COMMAND_EXECUTION]: Instructs the agent to utilize various system commands (curl, wget, git, xxd) and language runtimes (Java, Python, PHP) to perform network interactions and local tool execution.\n- [REMOTE_CODE_EXECUTION]: Provides specific methodologies and code templates for generating malicious serialized payloads intended to achieve arbitrary command execution on target systems.\n- [DATA_EXFILTRATION]: Recommends the use of out-of-band callback listeners (e.g., COLLAB_HOST) to verify exploitation results, which is a technique that involves sending data from the target system to a remote listener.
Audit Metadata