Linux: low-priv shell to root and pivot
You have a low-privilege shell on a Linux host. This path walks enumeration, a privilege-escalation primitive (SUID/sudo/capabilities), credential looting and an onward pivot.
Scenario
Continuing an authorized engagement, you have landed an unprivileged shell on an in-scope Linux server (for example via the web path). The objective is local root and lateral reach, documented for remediation.
- 1
Discovery
Enumerate the host for escalation paths
T1082 System Information DiscoveryT1083 File and Directory DiscoveryT1033 System Owner/User DiscoverySystematically review the kernel and OS version, running services, scheduled jobs, writable paths, SUID/SGID binaries and file capabilities, and the current user's sudo rights — building a ranked list of candidate primitives.
DetectionMass enumeration (reading /etc, listing SUID files, dumping environment) from an interactive shell is visible to auditd and EDR.
MitigationBaseline and monitor command execution, limit shell access, and alert on enumeration one-liners and SUID discovery sweeps.
- 2
Privilege Escalation
Escalate to root with a known primitive
T1548.001 Abuse Elevation Control Mechanism: Setuid and SetgidT1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo CachingT1068 Exploitation for Privilege EscalationAbuse a concrete, confirmed primitive — a dangerous SUID binary, a sudo rule, a file capability, or a patchable kernel/service flaw — choosing the lowest-risk reliable option (consult GTFOBins for the exact binary behaviour).
DetectionUnexpected euid=0 transitions, known GTFOBins invocation patterns, and setuid calls from unusual binaries are strong signals.
MitigationRemove unnecessary SUID bits and capabilities, scope sudo tightly with NOPASSWD off, and patch promptly.
- 3
Credential Access
Loot credentials now that you are root
T1552.001 Unsecured Credentials: Credentials In FilesT1003.008 OS Credential Dumping: /etc/passwd and /etc/shadowWith root, collect credentials from configuration files, histories, keys and the local password store to enable movement to other systems, recording each secret handled.
DetectionRoot reads of /etc/shadow, SSH keys and app config in quick succession stand out in file-access auditing.
MitigationVault secrets, rotate keys, use short-lived credentials, and audit access to shadow and key material.
- 4
Persistence
Establish controlled persistence
Where the rules of engagement require durable access, add a clearly-labelled, reversible mechanism (a scheduled job or service) and document it for removal.
DetectionNew cron entries and systemd units, especially owned by services, are easy to diff against a known-good baseline.
MitigationFile-integrity monitoring on cron and unit directories, and immutable infrastructure that is rebuilt rather than patched in place.
References linuxprivilegeesc - 5
Lateral Movement
Pivot to the next host
Use the looted keys and a tunnel to reach the next in-scope system, repeating the loop. Keep a clear map of every host touched.
DetectionSSH from a server to many internal hosts, key reuse, and new tunnels are visible in auth logs and NetFlow.
MitigationPer-host keys, bastion-only SSH, network segmentation, and alerting on server-initiated lateral SSH.
Key takeaways
- Local root on Linux usually comes from a misconfiguration (SUID, sudo, capabilities), not an exploit.
- GTFOBins turns an innocuous binary into a root shell — inventory and remove unnecessary SUID/caps.
- Credential reuse is what turns one rooted host into many; vault secrets and segment the network.