hunting-for-persistence-mechanisms-in-windows
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). The playbook explicitly directs investigators to "remove malicious persistence" and to inspect and modify persistence mechanisms (registry keys, services, scheduled tasks, WMI), which entails changing system state and likely requires elevated privileges, so it encourages actions that can modify the host environment even though it does not instruct privilege escalation or account creation.
Issues (1)
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata