All cheatsheets
Cheatsheet · intermediate
Linux privesc quick
Post-foothold checklist: identity, sudo, SUID, timers, creds, kernel hints.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
privesc
linux
Who am I?
Command
id; whoami; hostname; cat /etc/os-release
Command
env; echo $PATH; ls -la
Command
sudo -l 2>/dev/null
Interesting files & perms
Command
find / -perm -4000 -type f 2>/dev/null
Command
getcap -r / 2>/dev/null
Command
ls -la /etc/cron*; ls -la /etc/systemd/system
Command
find /home /opt /var/www -name '*.conf' 2>/dev/null | head
creds & auto enum
Command
grep -RniE 'pass|secret|key' /var/www 2>/dev/null | head
Command
./linpeas.sh | tee linpeas.out
Command
pspy64 # watch cron/timer processes
Checklist
- sudo -l reviewed against GTFOBins
- Writable service scripts / cron checked
- No destructive tests on production without RoE
- Path to root written before running exploit