{"enrichment":{"faq":[{"a":"privilege-escalation-methods covers systematic local escalation paths on Linux, including exploiting misconfigured sudo binaries, abusing SUID setuid binaries, leveraging cron job misconfigurations, and manipulating capabilities. The skill examines how to identify and chain these vectors from a low-privilege shell to achieve root access on compromised systems.","q":"How to escalate privileges on Linux systems?"},{"a":"privilege-escalation-methods addresses Windows-specific escalation vectors including token impersonation exploits, service abuse, and SeBackupPrivilege misuse. It covers post-exploitation methods to transition from initial shell access to administrator or SYSTEM-level privileges on compromised Windows hosts.","q":"What Windows privilege escalation techniques does this skill teach?"},{"a":"privilege-escalation-methods includes domain-focused escalation techniques such as Kerberoasting to harvest service account credentials, golden ticket creation for persistent access, LLMNR poisoning for credential interception, and Mimikatz DCSync attacks. These methods enable lateral movement and privilege elevation within compromised Active Directory environments.","q":"What Active Directory attacks like kerberoasting are included?"},{"a":"privilege-escalation-methods teaches establishing persistent access after initial shell compromise through privilege escalation, credential harvesting for lateral movement, and maintaining elevated access in compromised networks. It integrates escalation techniques with post-exploitation workflows for sustained red team operations.","q":"How does privilege-escalation-methods address post-exploitation access?"},{"a":"privilege-escalation-methods identifies exploitable misconfigurations including NFS root squash vulnerabilities, misconfigured sudo rules, overprivileged service accounts, and weak Active Directory delegation settings. It demonstrates how to systematically discover and chain these weaknesses to gain root or administrator access.","q":"What misconfigurations can privilege-escalation-methods help exploit?"}],"shadow_tags":["post-exploitation","lateral-movement","credential-dumping","domain-compromise","persistence-mechanism","red-team-ops","active-directory-attack","system-hardening-bypass"],"summary_rewrite":"This skill covers systematic approaches to elevate from low-privilege shells to root or administrator access on compromised systems. It addresses both local escalation paths\u2014such as exploiting misconfigured sudo, capabilities, and scheduled tasks on Linux\u2014and Windows-specific vectors including token impersonation and service abuse. For domain environments, it includes Active Directory attacks like Kerberoasting, golden tickets, and credential harvesting via LLMNR poisoning."},"files":[{"bytes":8115,"path":"skills/privilege-escalation-methods/SKILL.md","sha256":"19c03ff3e1b8214ffc097355ded17f3c5cf1183710187bc76c930150bb0cf657","url":"https://skillfed.io/files/zebbern/claude-code-guide/privilege-escalation-methods/0ccc58f5/SKILL.md"}],"id":"zebbern/claude-code-guide/privilege-escalation-methods","links":{"html":"https://skillfed.io/zebbern/claude-code-guide/privilege-escalation-methods","md":"https://skillfed.io/zebbern/claude-code-guide/privilege-escalation-methods.md","repo":"https://github.com/zebbern/claude-code-guide"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":447,"language":"Python","last_updated":"2026-07-26","license":"MIT","name":"privilege-escalation-methods","publisher":"zebbern","stars":4440},"relations":{"similar":[{"id":"zebbern/claude-code-guide/active-directory-attacks"},{"id":"blacklanternsecurity/red-run/trust-attacks"},{"id":"blacklanternsecurity/red-run/kerberos-ticket-forging"},{"id":"yaklang/hack-skills/active-directory-kerberos-attacks"},{"id":"hypnguyen1209/offensive-claude/active-directory-attack"},{"id":"blacklanternsecurity/red-run/ad-persistence"},{"id":"blacklanternsecurity/red-run/kerberos-delegation"},{"id":"blacklanternsecurity/red-run/pass-the-hash"},{"id":"blacklanternsecurity/red-run/adcs-persistence"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"}]},"slug":{"owner":"zebbern","repo":"claude-code-guide","skill":"privilege-escalation-methods"},"version":"0ccc58f5"}
