hunting-for-persistence-mechanisms-in-windows

Warn

Audited by Snyk on Apr 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The playbook explicitly directs investigators to "remove malicious persistence" and to inspect and modify persistence mechanisms (registry keys, services, scheduled tasks, WMI), which entails changing system state and likely requires elevated privileges, so it encourages actions that can modify the host environment even though it does not instruct privilege escalation or account creation.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 7, 2026, 06:47 PM
Issues
1