Book a 30-minute demo →
Skill scan report

ntlm-relay-coercion

View on GitHub
24 Low Automated analysis flagged 2 potential risk patterns.

What this skill does

This skill is a real attack playbook for NTLM relay and authentication coercion techniques, including methods like PetitPotam, PrinterBug, and others. It provides detailed instructions on how to perfo

github/yaklang - Malicious Code - 1.6k stars

ThreatsMalicious Code

Threat analysis

Malicious Code2 findings

Skill info

Nameyaklang/ntlm-relay-coercion
Registrygithub
Versionc9a4b9e
PURLpkg:github/yaklang/hack-skills@c9a4b9e?skill=ntlm-relay-coercion
Stars1.6k

Assessments (2)

Malicious Code2 findings HIGH
HIGH

Malicious Code via local-llm-review

SKILL.md

The skill contains code examples for NTLM relay attacks, such as 'PetitPotam.py LISTENER_IP TARGET_IP', which are genuine attack instructions.
HIGH

Malicious Code via local-llm-review

COERCION_METHODS.md

The skill provides detailed instructions on various coercion methods, including PrinterBug, DFSCoerce, ShadowCoerce, MSEven, and CheeseOunce, which are all known attack techniques.

Badge

Add the Anomity scan badge for ntlm-relay-coercion to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/yaklang/ntlm-relay-coercion/)
HTML
<a href="https://anomity.ai/skills/github/yaklang/ntlm-relay-coercion/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of ntlm-relay-coercion? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok