elasticsearch-attack
Fail
Audited by Socket on Aug 12, 2026
2 alerts found:
SecurityMalwareSecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
该技能与其“攻击 Elasticsearch”目的相符,但其实际能力是面向真实目标的渗透、数据窃取、爆破、RCE、提权和破坏操作,属于高风险 offensive security skill。未见明显恶意隐蔽安装或第三方凭证中转,但作为 AI 代理技能其行为边界远超正常开发/运维,整体应判定为高风险、可疑且不适合默认信任。
Confidence: 95%Severity: 96%
Malwarereferences/attack-techniques.md
HIGHMalwareHIGH
references/attack-techniques.md
Highly malicious exploitation playbook targeting Elasticsearch/Kibana. It describes clear data exfiltration via snapshot abuse, persistent interception/tampering via malicious ingest pipelines, privilege escalation/persistence via backdoor user and API keys, and arbitrary file read attempts via path traversal. If such content were present in a supply chain artifact, it would be an extreme security red flag.
Confidence: 90%Severity: 100%
Audit Metadata