Phase 07: Privilege Escalation & Lateral Movement
Exploit system misconfigurations, abuse Active Directory access rights, or escalate privileges to achieve full administrative control. This phase has 11 checklist items. Placeholders such as {TARGET_IP} are values for your target.
Branch F: Linux Privilege Escalation Playbook
Sudo Capabilities & Permissions Check (sudo -l)
Check binaries allowed to run as root with or without password; cross-reference GTFOBins.
sudo -lSUID / SGID Binary Discovery & GTFOBins Exploitation
Search for binaries running with root effective UID.
find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;Linux Binary Capabilities (getcap)
Audit dangerous capabilities like cap_setuid, cap_dac_read_search, or cap_sys_admin.
getcap -r / 2>/dev/nullWritable Cron Script or Wildcard Injection Abuse
Hijack cron scripts or exploit tar/rsync wildcard command execution.
cat /etc/crontab; ps -ef | grep cronWritable Sensitive Files (/etc/passwd, /etc/shadow)
Write a new root user entry with custom crypted password hash if /etc/passwd is writable.
ls -l /etc/passwd /etc/shadowKernel Exploitation (PwnKit, DirtyPipe) [Verified Option]
Cross-reference kernel release against stable local privilege escalation exploits.
uname -a
Branch G: Windows & Active Directory PrivEsc Playbook
Token Privileges Abuse (SeImpersonate, SeBackupPrivilege)
Abuse impersonation privileges via PrintSpoofer, GodPotato, or JuicyPotato.
whoami /priv; GodPotato-NET4.exe -cmd "cmd.exe /c whoami"Stored Credentials, DPAPI & Registry AutoLogon
Extract saved RDP credentials, RunAs records, or plaintext autologon passwords.
cmdkey /list or reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"Service Exploitation (Unquoted Paths, Weak ACLs)
Replace writable binary paths or hijack unquoted executable spaces.
wmic service get name,displayname,pathname,startmode |findstr /i "Auto" |findstr /i /v "C:\Windows\"Active Directory Kerberoasting & AS-REP Roasting
Request service ticket TGS hashes and crack offline with hashcat.
impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {DC_IP} -requestBloodHound Path Exploration & Attack Chains
Collect domain graph and uncover shortest path to Domain Admins or DCSync rights.
.\SharpHound.exe -c All --zipfilename loot.zip
All phases
- Host Discovery & Surface Mapping
- Protocol & Service Enumeration
- Vulnerability Identification & Threat Modeling
- Foothold Execution & Initial Access
- Shell Stabilization & Context Triage
- Internal System & Network Reconnaissance
- Privilege Escalation & Lateral Movement
- Post-Exploitation, Flag Vault & Artifact Collection
Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist