ntlm-relay-attack

Fail

Audited by Socket on Apr 22, 2026

3 alerts found:

Securityx2Malware
SecurityMEDIUM
SKILL.md

该技能并非伪装成无害工具;它公开且系统性地赋予AI代理执行NTLM中继、强制认证、证书滥用和远程命令执行的攻击能力。目的与能力一致,但该目的本身属于高风险 offensive security/横向移动,用于真实环境时可直接导致未授权访问、域提权和恶意投递,因此应归类为高风险、可疑的攻击型技能而非普通开发者技能。

Confidence: 94%Severity: 97%
SecurityMEDIUM
evals/evals.json

No operational malware or data-flow execution exists in this snippet because it is purely static, but it contains highly actionable offensive guidance for NTLM relay and ADCS-based domain compromise. If packaged/distributed as part of software artifacts, this materially increases misuse risk and should be treated as high security concern for a supply-chain context.

Confidence: 90%Severity: 86%
MalwareHIGH
references/relay-techniques.md

本材料不是正常依赖的代码逻辑,而是针对 Active Directory 的高可实施入侵链条:通过 forced authentication 与(NTLM/Kerberos)中继捕获并滥用身份认证,利用 ADCS 证书链获取票据/密钥,继而完成凭证/哈希/票据窃取与远端命令执行,并可结合 IPv6/DNS 劫持提高成功率。若该内容出现在任何供应链产物中,属于极高风险,建议立即隔离、溯源发布链路并进行恶意内容处置。

Confidence: 78%Severity: 98%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:11 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fntlm-relay-attack%2F@cbb0d82b9b0dc2e6677e9d72f1c5f3ade40430b8
Security Audit — socket — ntlm-relay-attack