windows-mitigations-bypass

Fail

Audited by Socket on Jul 2, 2026

6 alerts found:

Malwarex5Security
MalwareHIGH
SKILL.md

MALICIOUS. The skill’s stated purpose is offensive exploitation: bypassing Windows mitigations, blinding defenses, and enabling credential/process access such as LSASS dumping and BYOVD-assisted tampering. Even without suspicious installers or exfil endpoints in the text shown, the capability is fundamentally incompatible with a benign AI agent skill and should be treated as high risk offensive tooling.

Confidence: 95%Severity: 98%
MalwareHIGH
references/byovd-vbs-hvci.md

This fragment is an explicitly malicious, adversary-oriented BYOVD and Windows kernel tampering playbook. It describes how to recon security posture (Credential Guard/HVCI/VBS), load vulnerable signed kernel drivers, use IOCTLs for arbitrary kernel read/write, perform credential/process/kernel-structure tampering, optionally weaken VBS/HVCI, and minimize detectability via unload/cleanup. If present within a software supply-chain package (as code, docs, or embedded artifacts), it represents an extreme security risk and clear malicious intent. The content is not obfuscated and reads as direct attacker operational guidance rather than benign implementation.

Confidence: 83%Severity: 100%
MalwareHIGH
references/asr-amsi-etw-blinding.md

The provided content describes concrete, actionable methods to bypass core Windows/Defender protections and suppress telemetry: AMSI defeat (flag manipulation and AmsiScanBuffer short-circuit patching), ETW userland blinding (patching ntdll EtwEventWrite* to return early and/or disabling providers), and ASR bypass via execution from Defender-excluded/trusted contexts and trusted-image process hollowing. This is strongly indicative of malicious tradecraft enabling stealthy offensive execution and credential theft workflows, and would be unsafe to include in any supply-chain dependency.

Confidence: 85%Severity: 95%
MalwareHIGH
references/ppl-lsa-protection.md

This fragment constitutes highly malicious attacker playbook content: it instructs bypassing Windows PPL/LSA Protection to dump LSASS for credential theft, and it outlines kernel-level (BYOVD) techniques to strip/downgrade PPL and disable/impair EDR protections/telemetry. It also includes explicit off-host exfiltration guidance and defender-aware evasion/detection tuning. If this appears in a software package dependency, it should be treated as extreme supply-chain risk and not used in production environments.

Confidence: 90%Severity: 100%
MalwareHIGH
references/wdac-app-control-bypass.md

High-risk malicious/offensive material. The artifact provides actionable, step-by-step instructions to bypass WDAC/App Control for Business by leveraging allow-list weaknesses (trusted signed LOLBins), supply-chain integrity subversion of signed Electron apps (asar/main.js tampering), potential native escalation via signed Node/V8 concepts, and DLL sideloading into trusted/allowed images. It also includes network-based payload retrieval examples and OPSEC guidance, making misuse highly feasible. No obfuscation is evident; risk arises from explicit operational bypass content.

Confidence: 80%Severity: 100%
SecurityMEDIUM
references/acg-cig-dynamic-code.md
Audit Metadata
Analyzed At
Jul 2, 2026, 01:44 PM
Package URL
pkg:socket/skills-sh/hypnguyen1209%2Foffensive-claude%2Fwindows-mitigations-bypass%2F@382b577358df4cbc2f103501ed91da2426e59614b80b6df2fd277f3d4cab23f5
Security Audit — socket — windows-mitigations-bypass