Rmagent Redteam

Purple-team DRILL for the rmagent-windows skill. Stages 8 reversible living-off-the-land (LOTL) artifacts on WS1/WS2 — failed Administrator logons, a new local admin, a SYSTEM scheduled task, a new LocalSystem service, PowerShell spawns, a SYSTEM outbound connection, a registry Run key (T1547.001), and an IFEO debugger hijack (T1546.010) — then runs rmagent census+hunt to score what it detects, and sends a Telegram alert with the detection report. Use to TEST rmagent effectiveness. This is a benign drill, not a real attack: every artifact is prefixed RMAgentDrill_ and is reversible with clean. Requires --confirm. Do NOT use against boxes you do not administer.

DrOlu fcc0304 8 files · 45.9 KB Updated

File contents

DrOlu/agent-skills/tree/main/skills/rmagent-redteam commit fcc030453f

Frequently asked questions

npx skillmds@latest add drolu/rmagent-redteam