← All walkthroughs

Linux: low-priv shell to root and pivot

You have a low-privilege shell on a Linux host. This path walks enumeration, a privilege-escalation primitive (SUID/sudo/capabilities), credential looting and an onward pivot.

Linux server Intermediate LinuxPrivilege EscalationPost-exploitation
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

Continuing an authorized engagement, you have landed an unprivileged shell on an in-scope Linux server (for example via the web path). The objective is local root and lateral reach, documented for remediation.

  1. 1

    Discovery

    Enumerate the host for escalation paths

    Systematically review the kernel and OS version, running services, scheduled jobs, writable paths, SUID/SGID binaries and file capabilities, and the current user's sudo rights — building a ranked list of candidate primitives.

    Detection

    Mass enumeration (reading /etc, listing SUID files, dumping environment) from an interactive shell is visible to auditd and EDR.

    Mitigation

    Baseline and monitor command execution, limit shell access, and alert on enumeration one-liners and SUID discovery sweeps.

  2. 2

    Privilege Escalation

    Escalate to root with a known primitive

    Abuse a concrete, confirmed primitive — a dangerous SUID binary, a sudo rule, a file capability, or a patchable kernel/service flaw — choosing the lowest-risk reliable option (consult GTFOBins for the exact binary behaviour).

    Detection

    Unexpected euid=0 transitions, known GTFOBins invocation patterns, and setuid calls from unusual binaries are strong signals.

    Mitigation

    Remove unnecessary SUID bits and capabilities, scope sudo tightly with NOPASSWD off, and patch promptly.

  3. 3

    Credential Access

    Loot credentials now that you are root

    With root, collect credentials from configuration files, histories, keys and the local password store to enable movement to other systems, recording each secret handled.

    Detection

    Root reads of /etc/shadow, SSH keys and app config in quick succession stand out in file-access auditing.

    Mitigation

    Vault secrets, rotate keys, use short-lived credentials, and audit access to shadow and key material.

    References linuxprivilegeesc · john
  4. 4

    Persistence

    Establish controlled persistence

    Where the rules of engagement require durable access, add a clearly-labelled, reversible mechanism (a scheduled job or service) and document it for removal.

    Detection

    New cron entries and systemd units, especially owned by services, are easy to diff against a known-good baseline.

    Mitigation

    File-integrity monitoring on cron and unit directories, and immutable infrastructure that is rebuilt rather than patched in place.

  5. 5

    Lateral Movement

    Pivot to the next host

    Use the looted keys and a tunnel to reach the next in-scope system, repeating the loop. Keep a clear map of every host touched.

    Detection

    SSH from a server to many internal hosts, key reuse, and new tunnels are visible in auth logs and NetFlow.

    Mitigation

    Per-host keys, bastion-only SSH, network segmentation, and alerting on server-initiated lateral SSH.

Key takeaways

  • Local root on Linux usually comes from a misconfiguration (SUID, sudo, capabilities), not an exploit.
  • GTFOBins turns an innocuous binary into a root shell — inventory and remove unnecessary SUID/caps.
  • Credential reuse is what turns one rooted host into many; vault secrets and segment the network.