T08 · Insecure Dependencies
- Location
SKILL.md:87- Finding
Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a memory-forensics reference skill whose sensitive commands are aligned with that purpose, though users should handle credential recovery and elevated acquisition steps carefully.
Install only if you need memory-forensics guidance. Run the acquisition and credential-recovery commands only on systems and memory images you are authorized to examine, avoid installing tools as root, prefer a pinned isolated environment, and protect or redact any recovered secrets in reports and notes.
SKILL.md:87Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
functions vol -f memory.raw windows.ssdt # System Service Descriptor Table
vol -f memory.raw windows.driverscan vol -f memory.raw windows.driverirp
### Credential Extraction
```bash
# Dump hashes (requires hivelist first)
vol -f memory.raw windows.hashdump
# LSA secrets
vol -f memory.raw windows.lsadump
# Cached domain credentials
vol -f memory.raw windows.cachedump
# Mimikatz-style extraction
# Requires specific plugins/tools
rule Suspicious_Injection
{
meta:
description = "Detects common injection shellcode"
strings:
// Common shellcode patterns
$mz = { 4D 5A }
$shellcode1 = { 55 8B EC 83 EC } // Function prologue
$api_hash = { 68 ?? ?? ?? ?? 68 ?? ?? ?? ?? E8 } // Push hash, call
condition:
$mz at 0 or any of ($shellcode*)
}
rule Cobalt_Strike_Beacon
{
meta:
description = "Detects Cobalt Strike beacon in memory"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# LiME (Linux Memory Extractor)
sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)
sudo dd if=/dev/mem of=memory.raw bs=1M
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# LiME (Linux Memory Extractor)
sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)
sudo dd if=/dev/mem of=memory.raw bs=1M
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# LiME (Linux Memory Extractor)
sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)
sudo dd if=/dev/mem of=memory.raw bs=1M
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo insmod lime.ko "path=/tmp/memory.lime format=lime"
# /dev/mem (limited, requires permissions)
sudo dd if=/dev/mem of=memory.raw bs=1M
# /proc/kcore (ELF format)
sudo cp /proc/kcore memory.elf
The skill includes credential extraction techniques such as hash dumping, LSA secret extraction, cached credential recovery, and references to Mimikatz-style extraction without an explicit warning that these operations expose highly sensitive secrets and must only be used with authorization. In a security/forensics context this can be legitimate, but the lack of guardrails increases the risk of misuse and accidental disclosure of credentials.
No suspicious patterns detected.