attack-chain
Audited by Socket on Sep 4, 2026
4 alerts found:
SecurityMalwarex3SUSPICIOUS. The skill’s capabilities are internally consistent with its stated purpose, but that purpose is to equip an AI agent for end-to-end offensive operations, including credential theft, persistence, stealth, and evidence removal. There is no confirmed malware payload or hidden exfiltration endpoint in the text, but the real-world abuse potential and transitive trust footprint make this a high-risk offensive security skill.
This fragment is not analyzable as a software dependency/module; it is an offensive intrusion/cheat-sheet that provides actionable reconnaissance, exploitation, credential-seeking, persistence, evasion, and anti-forensics instructions. If such content exists in a repository or is packaged/distributed, it materially increases misuse risk and should be treated as malicious operational guidance rather than legitimate code.
This artifact is an adversarial malware/stealth tradecraft guide. It provides actionable instructions to bypass EDR/AV and AMSI, evade ETW/telemetry, conceal payloads in memory (injection/module stomping/memory encryption), and execute/download attacker payloads via LOLBins, followed by covert C2 transport techniques. It should be treated as high-risk malicious operational content and not as a legitimate dependency or reference material for production systems.
The provided artifact is not a software dependency implementation; it is an explicitly adversary-oriented intrusion playbook covering end-to-end exploitation, credential theft, lateral movement, AD/AD CS abuse, phishing, and cloud metadata/token exploitation. No executable code is present in the snippet, but its content is directly reusable for wrongdoing and represents an extreme security risk if included in or distributed with a software package.