windows-av-evasion
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions and functional code stubs for downloading and executing remote payloads within the host environment.
- Evidence: Implementation details for downloading encrypted tools from external URLs and executing them via
Assembly.Loador shellcode injection. - [COMMAND_EXECUTION]: The skill contains functional C# and PowerShell code for advanced process injection and shellcode execution techniques.
- Evidence: Detailed code snippets for
CreateRemoteThread,Early Bird APC Injection, and shellcode execution via callback APIs likeEnumWindowsto avoid standard monitoring. - [DYNAMIC_EXECUTION]: The skill documents and provide code for runtime memory modification to disable core Windows security features.
- Evidence: Functional implementations for patching
AmsiScanBufferinamsi.dllandEtwEventWriteinntdll.dllto suppress security scanning and event telemetry. - [OBFUSCATION]: Explicitly provides methods for hiding malicious strings and payloads to evade static and behavioral analysis.
- Evidence: Code patterns for XOR encryption, Base64 string splitting, string reversal, and API hashing to hide sensitive function calls and strings from security scanners.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a high-risk capability tier that can be exploited if the agent processes untrusted inputs.
- Ingestion points: Designed to ingest and modify user-provided binaries or scripts (e.g., in SKILL.md and AMSI_BYPASS_TECHNIQUES.md).
- Boundary markers: None present to differentiate between safe and unsafe instructions.
- Capability inventory: Includes memory patching, process injection, network downloads, and direct shellcode execution.
- Sanitization: No input validation or sanitization routines are provided for the described attack techniques.
Recommendations
- AI detected serious security threats
Audit Metadata