attack-chain
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides an extensive index of CLI tools and shell commands for every phase of a cyber attack, including reconnaissance, vulnerability exploitation, and lateral movement across several files (SKILL.md, references/phases.md).\n- [REMOTE_CODE_EXECUTION]: The evasion-cheatsheet.md and phases.md files provide specific command patterns for downloading and executing remote payloads using system binaries (LOLBins) like certutil, mshta, regsvr32, and msiexec.\n- [PRIVILEGE_ESCALATION]: Includes detailed instructions for exploiting SUID binaries, abusing sudo permissions, and using specialized escalation tools like GodPotato and winPEAS to gain administrator or root access on multiple operating systems.\n- [PERSISTENCE]: The skill instructs the agent on how to maintain long-term access to a target system using techniques such as cron jobs, SSH key injection, WMI event subscriptions, and LD_PRELOAD hijacking as documented in phases.md.\n- [DATA_EXFILTRATION]: Provides methods for harvesting sensitive credentials from memory (e.g., mimikatz), extracting domain hashes (DCSync), and identifying sensitive data in configuration files or cloud metadata services.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process large amounts of untrusted data from target systems (recon results, tech stacks, web responses) and has the capability to execute shell commands and write files based on that data (e.g., processing tech.json or all_subs.txt).\n- [DYNAMIC_EXECUTION]: The evasion reference details techniques for runtime code manipulation, including direct system calls, API unhooking, and memory-only execution (Module Stomping, Sleep Encryption) to bypass security software.\n- [PERSISTENCE]: The phases.md reference includes explicit commands for anti-forensic activities such as clearing Windows Security, System, and Application event logs using wevtutil and purging Linux logs.
Audit Metadata