establishing-persistence

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALPERSISTENCEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONOBFUSCATION
Full Analysis
  • [PERSISTENCE]: The skill documents numerous methods to maintain persistent access across system restarts and user sessions. Evidence includes configuration snippets for Linux cron jobs, systemd service creation, init.d script manipulation, SSH authorized_keys injection, shell profile modifications (.bashrc/.bash_profile), LD_PRELOAD environment hijacking, and package manager hooks. On Windows, it covers Registry Run keys, scheduled tasks, WMI event subscriptions, and startup folder replication.
  • [PRIVILEGE_ESCALATION]: Detailed guidance is provided for creating root-equivalent accounts on Linux via useradd options (-u 0 -o) and local Administrator accounts on Windows. It also documents registry modifications to hide backdoor accounts from the Windows logon UI.
  • [COMMAND_EXECUTION]: The resource includes an exhaustive catalog of system commands that manipulate critical operating system mechanisms, service control managers, and registry structures to install unauthorized software.
  • [OBFUSCATION]: The instruction set outlines specific evasion techniques designed to bypass antivirus detection, demonstrating how to use bracketed string fragmentation (e.g., 'syst[e]m', 'ev[a]l', '$_G[E]T') to mask known webshell signatures.
Recommendations
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 03:30 AM
Security Audit — agent-trust-hub — establishing-persistence