{"enrichment":{"faq":[{"a":"linux-lateral-movement covers SSH agent hijacking, private key harvesting from user home directories and process memory, credential extraction from system files, and abuse of D-Bus services. After initial compromise, these techniques enable attackers to move between hosts using stolen credentials, hijacked SSH agents, and service exploitation to expand control across the infrastructure.","q":"What are the main linux lateral movement techniques?"},{"a":"linux-lateral-movement teaches SSH agent hijacking by locating the SSH_AUTH_SOCK environment variable pointing to the agent socket, then connecting to it to reuse the victim's loaded private keys. This allows lateral movement to systems the compromised user can access without needing to steal or crack the actual key files.","q":"How does SSH agent hijacking work in linux-lateral-movement?"},{"a":"linux-lateral-movement covers multiple SSH key harvesting methods: scanning ~/.ssh directories for private keys, extracting keys from process memory using ptrace, harvesting credentials from shell history and config files, and exploiting world-readable key permissions. These techniques enable attackers to collect authentication material for multi-host compromise.","q":"What methods does linux-lateral-movement teach for SSH key harvesting?"},{"a":"linux-lateral-movement teaches internal network pivoting through multi-hop SSH tunneling, where compromised hosts become jump servers to reach deeper network segments. Attackers establish local port forwarding and SOCKS proxies through intermediate hosts, combined with network reconnaissance to map internal topology and identify additional targets.","q":"How can I pivot across linux servers using SSH tunneling?"},{"a":"linux-lateral-movement covers D-Bus service abuse for privilege escalation and lateral access, including polkit exploitation and sudo token reuse attacks. It also teaches systemd service backdooring to establish persistent access and create tunnels for continued lateral movement across the compromised infrastructure.","q":"What D-Bus and systemd exploitation techniques does linux-lateral-movement cover?"},{"a":"linux-lateral-movement teaches harvesting credentials from multiple sources: extracting SSH keys from ~/.ssh and system directories, recovering passwords from process memory and shell history, exploiting shared filesystems with no_root_squash, and abusing sudo tokens. These harvested credentials enable reuse across multiple hosts for infrastructure-wide compromise.","q":"How does linux-lateral-movement address credential harvesting from Linux hosts?"}],"shadow_tags":["post-compromise-movement","credential-reuse-attack","inter-host-pivoting","unix-socket-hijacking","service-exploitation","network-tunneling","filesystem-abuse","session-token-theft","internal-reconnaissance"],"summary_rewrite":"This skill teaches advanced techniques for moving between Linux hosts after initial compromise. Master SSH agent hijacking, private key discovery, credential extraction from system files and process memory, D-Bus service abuse, and internal network tunneling to expand your foothold across infrastructure."},"files":[{"bytes":11239,"path":"skills/linux-lateral-movement/SKILL.md","sha256":"24f79f9637f06dac6e99c0b78289ffb753224b0c47c38323af5dbb7db867cf1e","url":"https://skillfed.io/files/yaklang/hack-skills/linux-lateral-movement/1b8be410/SKILL.md"}],"id":"yaklang/hack-skills/linux-lateral-movement","links":{"html":"https://skillfed.io/yaklang/hack-skills/linux-lateral-movement","md":"https://skillfed.io/yaklang/hack-skills/linux-lateral-movement.md","repo":"https://github.com/yaklang/hack-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":196,"language":"CSS","last_updated":"2026-06-16","license":"MIT","name":"linux-lateral-movement","publisher":"yaklang","stars":1480},"relations":{"similar":[{"id":"blacklanternsecurity/red-run/linux-cron-service-abuse"},{"id":"blacklanternsecurity/red-run/linux-sudo-suid-capabilities"},{"id":"yaklang/hack-skills/tunneling-and-pivoting"},{"id":"blacklanternsecurity/red-run/linux-discovery"},{"id":"hypnguyen1209/offensive-claude/privesc-linux"},{"id":"AI-Shell-Team/aish/deepin-sysassist"},{"id":"yaklang/hack-skills/linux-privilege-escalation"},{"id":"zebbern/claude-code-guide/ssh-penetration-testing"},{"id":"Aradotso/security-skills/server-security-init-skill"},{"id":"joelhooks/joelclaw/three-body"}]},"slug":{"owner":"yaklang","repo":"hack-skills","skill":"linux-lateral-movement"},"version":"1b8be410"}
