attack-chain
Audited by Socket on Aug 19, 2026
3 alerts found:
Malwarex3High-risk offensive agent skill. Its stated purpose matches its capabilities, but those capabilities are inherently dangerous for an AI agent: multi-stage attack orchestration, credential theft, persistence, evasion, anti-forensics, and delegation to more tooling/skills. Not enough evidence for confirmed malware, but it is a severe security risk and should be treated as a dangerous exploit/orchestration skill.
This artifact is an adversarial malware/stealth tradecraft guide. It provides actionable instructions to bypass EDR/AV and AMSI, evade ETW/telemetry, conceal payloads in memory (injection/module stomping/memory encryption), and execute/download attacker payloads via LOLBins, followed by covert C2 transport techniques. It should be treated as high-risk malicious operational content and not as a legitimate dependency or reference material for production systems.
The provided artifact is not a software dependency implementation; it is an explicitly adversary-oriented intrusion playbook covering end-to-end exploitation, credential theft, lateral movement, AD/AD CS abuse, phishing, and cloud metadata/token exploitation. No executable code is present in the snippet, but its content is directly reusable for wrongdoing and represents an extreme security risk if included in or distributed with a software package.