detecting-ntlm-relay-with-event-correlation

Warn

Audited by Snyk on Apr 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill includes PowerShell and registry/GPO commands (Set-ItemProperty, domain-wide SMB/LDAP signing changes, revoking certs, blocking IPs, remote Invoke-Command/New-CimSession) that instruct changing system configuration and performing domain-wide actions requiring elevated privileges, so it encourages modifying the machine/state.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 05:19 PM
Issues
1