windows-privilege-escalation
Audited by Socket on Jul 21, 2026
3 alerts found:
SecurityMalwarex2High-risk offensive security skill. Its capabilities align with its stated purpose, but that purpose is to help an AI agent perform Windows privilege escalation, credential access, and post-exploitation while also chaining into other attack skills. No clear hidden exfiltration or obfuscation is present, so this is not confirmed malware, but it is dangerous and inappropriate for general agent deployment.
This module is highly indicative of malicious exploitation/privilege-escalation tooling. It provides actionable UAC bypass and auto-elevation abuse instructions using trusted Windows binaries, manipulates HKCU registry keys to redirect elevated execution, performs DLL hijacking-style file placement, triggers elevated scheduled tasks (DiskCleanup/SilentCleanup), and includes an INF example referencing a remote attacker-controlled HTTP payload. In a supply-chain context, it should be treated as dangerous and not as legitimate dependency code.
This fragment is high-risk and strongly malicious instructional content. It provides an actionable Windows privilege-escalation and credential-theft playbook: obtain SYSTEM-level execution via token impersonation (“Potato” family and related coercion paths), then extract SAM/SYSTEM/SECURITY hives and NTDS.dit using backup semantics for offline credential dumping. It further includes guidance for driver-loading/kernel exploitation steps. No defensive or benign software functionality is present in this module.