conducting-pass-the-ticket-attack

Fail

Audited by Socket on Apr 7, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are internally consistent with red-team post-exploitation, but that purpose itself gives an AI agent credential-theft and lateral-movement instructions with real attack impact. Not confirmed malware, but clearly unsafe and inappropriate for general agent use.

Confidence: 95%Severity: 96%
MalwareHIGH
references/workflows.md

This file is an explicit, operational playbook for Pass-the-Ticket attacks using known offensive tools (Mimikatz, Rubeus, Impacket). It instructs how to extract, convert, inject, and forge Kerberos tickets to impersonate privileged accounts and perform lateral movement and persistence. The content should be treated as malicious: presence of these commands, scripts, or associated binaries in an environment is a high-severity indicator requiring immediate investigation and containment. Monitor for the listed detection indicators and assume compromise if these actions are observed.

Confidence: 75%Severity: 95%
Audit Metadata
Analyzed At
Apr 7, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fconducting-pass-the-ticket-attack%2F@e83b82ecc125502208904d458f4941b008fed3ec