relaying-ntlm-for-adcs-esc8

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The orchestration script scripts/agent.py executes several local command-line tools to perform the attack. It uses the subprocess module to call certipy, ntlmrelayx, and coercion tools like PetitPotam.py and coercer. These commands are constructed using lists from user-provided arguments, which is a standard practice for CLI wrappers.
  • [EXTERNAL_DOWNLOADS]: The SKILL.md and references/api-reference.md files provide instructions for installing necessary security tools from well-known public repositories on GitHub (e.g., Impacket, Certipy, PetitPotam) and via official package managers like pipx. These are standard procedures for establishing the required environment for the documented security exercises.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 04:04 AM
Security Audit — agent-trust-hub — relaying-ntlm-for-adcs-esc8