offensive-anti-forensics
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides detailed instructions for executing potentially destructive commands intended for evidence removal, including clearing Windows Event Logs via
wevtutil, truncating Linux logs usingtruncate, and wiping files withshredorsdelete. - [PRIVILEGE_ESCALATION]: Describes advanced techniques that require administrative or system-level privileges, such as patching the ETW (Event Tracing for Windows) provider in memory and killing threads within the Event Log Service to blind telemetry.
- [EXTERNAL_DOWNLOADS]: References external tools and scripts for anti-forensics purposes, including the
Invoke-Phant0mrepository on GitHub and utilities from Microsoft Sysinternals. - [DYNAMIC_EXECUTION]: Includes source code snippets in C and C# for the operator to compile and execute, specifically for direct manipulation of binary login records (
utmp/wtmp) and runtime patching of system DLLs to disable logging.
Audit Metadata