windows-lateral-movement

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent, but its stated purpose is to give an AI agent offensive lateral-movement capabilities, credential replay techniques, stealth tradecraft, and pivoting across Windows hosts. There is little sign of hidden exfiltration or deceptive install behavior, so this is not confirmed malware, but it is a high-risk offensive security skill inappropriate for general agent deployment.

Confidence: 95%Severity: 95%
MalwareHIGH
CREDENTIAL_DUMPING.md

This fragment is an explicit offensive credential-dumping and cracking playbook targeting Windows and Active Directory (LSASS/SAM/SECURITY/NTDS.dit/DPAPI), including multiple domain controller extraction methods and a direct hash-to-password cracking workflow. If included in a distributed package as content, it would represent a severe security risk consistent with facilitating unauthorized credential theft and subsequent compromise. No obfuscation is used, and the intent is direct and unambiguous.

Confidence: 90%Severity: 98%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fwindows-lateral-movement%2F@afac68a2bef19a26f4c47b11ab65bd6d5ed71811756a9f2ce54b070d7ab91d5c
Security Audit — socket — windows-lateral-movement