windows-lateral-movement
Fail
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains an extensive list of command-line instructions for performing offensive operations, including administrative tool usage and system manipulation.
- Evidence: Commands for
reg saveto extract registry hives,vssadminfor volume shadow copy manipulation, and execution of third-party tools likeMimikatz,Chisel, andLigolo-ng. - Evidence: Detailed WMI event subscription persistence patterns in PowerShell.
- [REMOTE_CODE_EXECUTION]: The skill documents numerous methods for executing code on remote targets using protocols such as SMB, WMI, WinRM, and DCOM.
- Evidence: Use of Impacket tools (
psexec.py,wmiexec.py,smbexec.py,atexec.py,dcomexec.py) and Windows-native methods (Invoke-Command,Invoke-WmiMethod, and DCOM object instantiation viaMMC20.ApplicationorShellWindows). - [DATA_EXFILTRATION]: The skill provides procedures for extracting highly sensitive security data and system credentials.
- Evidence: Instructions for dumping LSASS memory using
comsvcs.dll,ProcDump, andnanodump. - Evidence: Techniques for harvesting the
ntds.ditdatabase from Domain Controllers and extracting DPAPI master keys and browser credentials.
Recommendations
- AI detected serious security threats
Audit Metadata