Linux Post-Exploitation Discovery¶
Enumerating a compromised Linux host: who you are, what is running, and where to go next.
Why It Matters¶
The first minutes on a Linux foothold decide the engagement's direction. Knowing the current user's privileges, the host's network position, and what credentials or trust relationships are present is what turns a shell into a plan for escalation and movement.
Reference¶
What to Enumerate¶
| Goal | Why |
|---|---|
| Current user and privileges | id, sudo -l: what you can already do |
| Network connections | ss -tunap: established sessions point to lateral movement targets |
| Running processes and services | ps aux: find services, agents, and running credentials |
| Scheduled tasks | cron and systemd timers: common escalation and persistence points |
| Host role | Is it domain-joined, a server, or a workstation; what applications it runs |
Useful Commands¶
id; sudo -l # current privileges
ss -tunap # network connections
ps aux # processes
cat ~/.bash_history # recent commands
cat ~/.ssh/config ~/.ssh/known_hosts # where this host connects
find / -name "FILE" -type f 2>/dev/null # locate files of interest
SSH keys, config, and known_hosts often reveal other hosts and users to pivot to.
Automated Enumeration¶
| Tool | Use |
|---|---|
| LinPEAS | Thorough local enumeration and privilege-escalation checks |
| LinEnum | Classic enumeration script |
| linux-smart-enumeration | Leveled enumeration with context |
How I Use It¶
I run the manual checks above first to understand where I am, then an automated script like LinPEAS for breadth. SSH keys and history frequently hand over the next host. Findings feed Linux Privilege Escalation and Movement.