windows-lateral-movement
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill is internally consistent, but its stated purpose is to give an AI agent offensive lateral-movement capabilities, credential replay techniques, stealth tradecraft, and pivoting across Windows hosts. There is little sign of hidden exfiltration or deceptive install behavior, so this is not confirmed malware, but it is a high-risk offensive security skill inappropriate for general agent deployment.
This fragment is an explicit offensive credential-dumping and cracking playbook targeting Windows and Active Directory (LSASS/SAM/SECURITY/NTDS.dit/DPAPI), including multiple domain controller extraction methods and a direct hash-to-password cracking workflow. If included in a distributed package as content, it would represent a severe security risk consistent with facilitating unauthorized credential theft and subsequent compromise. No obfuscation is used, and the intent is direct and unambiguous.