winrm-pentesting
Fail
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides documentation for executing remote payloads on target systems, including techniques to download and run PowerShell scripts from attacker-controlled servers using the
Invoke-Expression(iex) command structure.\n- [REMOTE_CODE_EXECUTION]: Automated antivirus and reputation scanners identified malicious signatures inSKILL.mdandreferences/winrm-techniques.md. The detectionClip:Powershell-EL [Drp]highlights patterns associated with PowerShell-based droppers used to deliver and execute code.\n- [COMMAND_EXECUTION]: The skill facilitates the use of powerful administrative tools such asInvoke-Command,Enter-PSSession,wmic, andPsExecfor remote system management. It also includes instructions for usingntlmrelayx.pywith elevated privileges to perform NTLM relay attacks.
Recommendations
- CRITICAL: 2 infected file(s) detected - DO NOT USE
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
Audit Metadata