windows-lateral-movement

Fail

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains an extensive list of command-line instructions for performing offensive operations, including administrative tool usage and system manipulation.
  • Evidence: Commands for reg save to extract registry hives, vssadmin for volume shadow copy manipulation, and execution of third-party tools like Mimikatz, Chisel, and Ligolo-ng.
  • Evidence: Detailed WMI event subscription persistence patterns in PowerShell.
  • [REMOTE_CODE_EXECUTION]: The skill documents numerous methods for executing code on remote targets using protocols such as SMB, WMI, WinRM, and DCOM.
  • Evidence: Use of Impacket tools (psexec.py, wmiexec.py, smbexec.py, atexec.py, dcomexec.py) and Windows-native methods (Invoke-Command, Invoke-WmiMethod, and DCOM object instantiation via MMC20.Application or ShellWindows).
  • [DATA_EXFILTRATION]: The skill provides procedures for extracting highly sensitive security data and system credentials.
  • Evidence: Instructions for dumping LSASS memory using comsvcs.dll, ProcDump, and nanodump.
  • Evidence: Techniques for harvesting the ntds.dit database from Domain Controllers and extracting DPAPI master keys and browser credentials.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — windows-lateral-movement