relaying-ntlm-for-adcs-esc8

Fail

Audited by Socket on Aug 11, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a red-team guide, but its actual purpose is to enable an AI agent to perform an active NTLM relay/AD CS privilege-escalation attack and DCSync. Install sources are mostly legitimate, yet the offensive scope, credential handling, and real-world attack capability make it high risk even without clear third-party exfiltration or confirmed malware.

Confidence: 94%Severity: 88%
MalwareHIGH
scripts/agent.py

This module is best characterized as offensive orchestration code for AD CS ESC8-style exploitation: it runs coercion techniques against a target DC, starts an NTLM relay listener with ADCS relaying enabled, parses relay output to extract a base64-encoded relayed certificate, decodes it, and writes the resulting PFX to disk. It also accepts plaintext credentials on the command line and relies on PATH-based tool discovery, increasing the impact of any environment tampering. No obfuscation is present; the primary risk comes from the explicit exploit/certificate-theft workflow and sensitive material persistence.

Confidence: 90%Severity: 95%
SecurityMEDIUM
references/api-reference.md

The fragment is a weaponized command reference for AD CS exploitation (ESC8 NTLM relay), including coercion and post-exploitation credential/ticket extraction steps using widely used offensive tools. It contains no obfuscated logic or embedded payloads, but it meaningfully enables credential theft and domain compromise when executed. Treat any package that ships this content as high risk from a malicious/enablement perspective, especially if delivered to environments where users did not explicitly request offensive tooling or defensive training context.

Confidence: 82%Severity: 93%
Audit Metadata
Analyzed At
Aug 11, 2026, 04:06 AM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Frelaying-ntlm-for-adcs-esc8%2F@a96ebf50180f75ef0dfa4e4c5a54fcc2c7c884a668faab44db0caae03fa11c79
Security Audit — socket — relaying-ntlm-for-adcs-esc8