Skip to content

Linux Post-Exploitation Discovery

Enumerating a compromised Linux host: who you are, what is running, and where to go next.

Why It Matters

The first minutes on a Linux foothold decide the engagement's direction. Knowing the current user's privileges, the host's network position, and what credentials or trust relationships are present is what turns a shell into a plan for escalation and movement.

Reference

What to Enumerate

Goal Why
Current user and privileges id, sudo -l: what you can already do
Network connections ss -tunap: established sessions point to lateral movement targets
Running processes and services ps aux: find services, agents, and running credentials
Scheduled tasks cron and systemd timers: common escalation and persistence points
Host role Is it domain-joined, a server, or a workstation; what applications it runs

Useful Commands

id; sudo -l                 # current privileges
ss -tunap                   # network connections
ps aux                      # processes
cat ~/.bash_history         # recent commands
cat ~/.ssh/config ~/.ssh/known_hosts   # where this host connects
find / -name "FILE" -type f 2>/dev/null   # locate files of interest

SSH keys, config, and known_hosts often reveal other hosts and users to pivot to.

Automated Enumeration

Tool Use
LinPEAS Thorough local enumeration and privilege-escalation checks
LinEnum Classic enumeration script
linux-smart-enumeration Leveled enumeration with context

How I Use It

I run the manual checks above first to understand where I am, then an automated script like LinPEAS for breadth. SSH keys and history frequently hand over the next host. Findings feed Linux Privilege Escalation and Movement.

Resources