ZeroBox

Phase 05: Shell Stabilization & Context Triage

Upgrade the raw socket into a full interactive TTY terminal, assess current user permissions, and verify sandbox or container constraints. This phase has 4 checklist items. Placeholders such as {TARGET_IP} are values for your target.

TTY Upgrade & Environment Triage

Interactive TTY Upgrade (Python PTY / stty raw -echo)

Enable tab-completion, clear screen, arrow keys, and Ctrl+C interrupt handling.

python3 -c 'import pty; pty.spawn("/bin/bash")'
# Ctrl+Z
stty raw -echo; fg
export TERM=xterm-256color

Identity & Privilege Context Inspection

Confirm current UID/GID, security groups, and enabled privileges.

id; whoami; whoami /priv

Container & Sandbox Detection (Docker / LXC / WSL)

Verify whether access is restricted to a container environment requiring breakout.

cat /proc/1/cgroup | grep docker; ls -la /.dockerenv

Internal Network Interfaces & Routing Table

Detect secondary subnets, internal VLANs, and loopback adapters.

ip a or ifconfig; ip route or route print

All phases

  1. Host Discovery & Surface Mapping
  2. Protocol & Service Enumeration
  3. Vulnerability Identification & Threat Modeling
  4. Foothold Execution & Initial Access
  5. Shell Stabilization & Context Triage
  6. Internal System & Network Reconnaissance
  7. Privilege Escalation & Lateral Movement
  8. Post-Exploitation, Flag Vault & Artifact Collection

Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist