offensive-anti-forensics

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions for executing potentially destructive commands intended for evidence removal, including clearing Windows Event Logs via wevtutil, truncating Linux logs using truncate, and wiping files with shred or sdelete.
  • [PRIVILEGE_ESCALATION]: Describes advanced techniques that require administrative or system-level privileges, such as patching the ETW (Event Tracing for Windows) provider in memory and killing threads within the Event Log Service to blind telemetry.
  • [EXTERNAL_DOWNLOADS]: References external tools and scripts for anti-forensics purposes, including the Invoke-Phant0m repository on GitHub and utilities from Microsoft Sysinternals.
  • [DYNAMIC_EXECUTION]: Includes source code snippets in C and C# for the operator to compile and execute, specifically for direct manipulation of binary login records (utmp/wtmp) and runtime patching of system DLLs to disable logging.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 02:26 PM
Security Audit — agent-trust-hub — offensive-anti-forensics