linux-smart-enumeration
Priv2Admin
linux-smart-enumeration | Priv2Admin | |
---|---|---|
2 | 7 | |
3,198 | 1,734 | |
- | - | |
6.2 | 1.2 | |
4 months ago | about 1 year ago | |
Shell | ||
GNU General Public License v3.0 only | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
linux-smart-enumeration
-
I passed with 100 points on second attempt AMA
Linux privesc is a bunch of manual checks from my notes that I have built over time. I also like https://github.com/diego-treitos/linux-smart-enumeration (lse.sh) which is similar to linpeas but the output is less busy.
- diego-treitos/linux-smart-enumeration - Linux enumeration tool for pentesting and CTFs with verbosity levels
Priv2Admin
- Passed with 90 points (incl report)
-
I passed with 100 points on second attempt AMA
things like checking whoami /priv + https://github.com/gtworek/Priv2Admin
- GitHub - gtworek/Priv2Admin: Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
- gtworek/Priv2Admin: Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS. Handy reference for technical defenders also.
- Token impersonations
What are some alternatives?
airgeddon - This is a multi-use bash script for Linux systems to audit wireless networks.
juicy-potato - A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
owasp-mastg - The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
PEASS-ng - PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
SUDO_KILLER - A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
Seatbelt - Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
CapProcess - A simple and useful script for capturing the processes running on a machine and some basic information about the system
OSCP-Bash-Scripts - Some handy bash scripts I used for the OSCP
pdfcrack - An Advanced tool to Crack Any Password Protected PDF file. A very user friendly script especially for noob hackers.
pspy - Monitor linux processes without root permissions
ActiveDirectoryAttackTool - ADAT is a small tool used to assist CTF players and Penetration testers with easy commands to run against an Active Directory Domain Controller. This tool is is best utilized using a set of known credentials against the host.
AutoRecon - AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.