moving-laterally-with-netexec
Audited by Socket on Aug 7, 2026
2 alerts found:
Securityx2The skill is internally consistent with its stated penetration-testing purpose, and the install source appears to be the official NetExec project. However, the purpose itself is a high-risk offensive capability set for an AI agent: large-scale authentication, password spraying, remote execution, and credential dumping. This is not confirmed malware, but it is a high-risk security skill.
This file is a high-risk dual-use orchestration wrapper around NetExec. It does not itself implement exploitation, persistence, or obfuscated malware, but it can automate authenticated access testing and, when configured, remote command execution on hosts flagged as “Pwn3d!”—functionality commonly associated with malicious lateral movement. Primary risks are misuse (credential/target-driven remote execution) and sensitive data leakage via logging and optional JSON output. Treat as unsafe in untrusted environments unless tightly controlled and ensure the nxc binary provenance is verified.