smb-pentesting
Audited by Socket on Aug 12, 2026
2 alerts found:
SecurityMalware该技能与其声明目的基本一致,但其目的本身就是为 AI Agent 提供完整的 SMB 攻击与后渗透作战手册。未见明显伪装、偷传到陌生中转站或恶意安装器,因此不像“伪装型恶意技能”;但它赋予 Agent 高危进攻能力、凭据获取与远程执行路径,应归类为高风险而非良性。
This artifact is best characterized as an attacker-oriented SMB exploitation and credential theft/relay playbook packaged as documentation. It provides explicit, actionable steps and command examples for scanning and exploiting SMB vulnerabilities, coercing victim authentication (SMB Trap), capturing NetNTLMv2 credentials (Responder), relaying them (ntlmrelayx), cracking hashes, and using them for further remote execution. No obfuscation is present; the maliciousness signal is the operational offensive content itself. If included in a software dependency, it should be treated as a serious supply-chain compromise/misuse risk and investigated/removed.