log-evasion
Fail
Audited by Socket on Apr 22, 2026
2 alerts found:
SecurityMalwareSecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
该技能与其宣称目的高度一致,但其目的本身就是为AI代理提供反日志、反取证和检测规避能力,明显超出普通DFIR/防御参考的安全边界。无明显恶意投毒式供应链迹象,但属于高风险进攻性安全技能,应判定为SUSPICIOUS而非BENIGN。
Confidence: 94%Severity: 91%
Malwarereferences/linux-log-evasion.md
HIGHMalwareHIGH
references/linux-log-evasion.md
The provided fragment is strongly sabotage-oriented: it delivers concrete, actionable methods to disable kernel auditing, tamper with authentication and audit/session logs (including binary formats), disrupt centralized log forwarding, purge evidence via rotation, forge timestamps, and hide processes/entries using LD_PRELOAD hooking. This is highly inappropriate for a legitimate software dependency and should be treated as high-risk material for misuse.
Confidence: 84%Severity: 90%
Audit Metadata