Linux Discovery
Linux Discovery helps penetration testers systematically identify privilege escalation opportunities on Linux hosts through enumeration of system configuration, sudo settings, group memberships, and kernel vulnerabilities. The skill gathers baseline system information, analyzes user context and permissions, and maps exploitable vectors while respecting scope boundaries and engagement logging.
Linux Discovery enumerates Linux systems for local privilege escalation vectors and misconfigurations under authorized testing.
AI-generated summary based on this skill's SKILL.md
Decision gist · record as of 2026-04-01
Linux Discovery enumerates Linux systems for local privilege escalation vectors and misconfigurations under authorized testing. Linux Discovery helps penetration testers systematically identify privilege escalation opportunities on Linux hosts through enumeration of system configuration, sudo settings, group memberships, and kernel vulnerabilities. The skill gathers baseline system information, analyzes user context and permissions, and maps exploitable vectors while respecting scope boundaries and engagement logging.
Use it when
- Yes.
- Linux Discovery performs Linux host enumeration by gathering detailed system information including configuration details, sudo settings.
Install
blacklanternsecurity/red-run/linux-discovery · repository language: Python
generated, unverified - the skill's exact subdirectory could not be determined; check the repository on GitHub
Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.
Frequently asked questions
AI-generated answers based on this skill's SKILL.md and metadata
What does Linux Discovery help identify on target systems?
Linux Discovery helps penetration testers systematically identify privilege escalation opportunities on Linux hosts through enumeration of system configuration, sudo settings, group memberships, and kernel vulnerabilities. The skill gathers baseline system information, analyzes user context and permissions, and maps exploitable vectors while respecting scope boundaries and engagement logging.
Can Linux Discovery enumerate linux servers across a network?
Yes. Linux Discovery is designed to enumerate Linux servers and hosts across network infrastructure. It automates the identification and discovery of Linux systems, enabling testers to map Linux infrastructure and assets systematically rather than manually searching for individual machines.
How does Linux Discovery perform linux host enumeration?
Linux Discovery performs Linux host enumeration by gathering detailed system information including configuration details, sudo settings, group memberships, and kernel data. This enumeration process identifies both the presence of Linux hosts and the specific privilege escalation vectors available on each discovered system.
What reconnaissance capabilities does Linux Discovery provide?
Linux Discovery performs Linux-focused network reconnaissance by discovering and identifying Linux devices and systems on target networks. It combines host discovery with detailed system analysis to map the complete Linux infrastructure landscape while maintaining engagement scope and logging requirements.
Is Linux Discovery open source?
Yes. Linux Discovery is released under the GPL-3.0 license, making it open source software available for review, modification, and distribution in accordance with GPL-3.0 terms.
Let your AI agent find skills like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.
wish › “Discover and enumerate Linux systems on a network”
Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →
Related skills
Systematically identify and exploit sudo weaknesses, SUID/SGID binaries, and Linux capability misconfigurations to gain root access. The skill covers GTFOBins-based escapes, environment variable injection, CVE exploitation, and polkit vulnerabilities across multiple attack vectors.
Windows Discovery maps privilege escalation vectors on compromised Windows hosts through systematic enumeration of system configuration, user context, services, and misconfigurations. It gathers baseline OS details, token privileges, and group memberships to identify immediate escalation paths, then reports findings to the orchestrator without crossing into exploitation.
This skill covers systematic Linux privilege escalation from low-privilege shell access to root. It walks through enumeration, SUID/SGID binary exploitation, capability abuse, cron job manipulation, NFS misconfigurations, writable system files, LD_PRELOAD tricks, Docker group abuse, and library hijacking—with specific commands and exploitation tables for each vector.
Privesc Linpeas runs comprehensive post-exploitation scans to uncover privilege escalation opportunities on Linux systems, checking for SUID/SGID binaries, sudo misconfigurations, exposed credentials, and kernel vulnerabilities. Results are color-coded by severity and mapped to exploitation techniques, enabling rapid identification of the highest-confidence escalation paths during authorized penetration tests and red team engagements.
This skill guides you through methodical privilege escalation assessments on Linux systems, covering enumeration of kernel exploits, sudo misconfigurations, SUID binaries, capabilities, cron jobs, PATH hijacking, and NFS weaknesses. It provides workflows for identifying attack vectors and executing exploitation techniques to achieve root-level access from a low-privilege shell.
Linux Pentester Practical Commands is a reference collection of command-line operations organized by penetration testing phase. It covers reconnaissance, enumeration, exploitation, privilege escalation, and post-exploitation workflows with real-world examples used in security assessments and CTF exercises.
More skills Linux File Path Abuse (GPL-3.0) · Linux Cron Service Abuse (GPL-3.0) · Linux Pentester Notes (NOASSERTION) · Windows Credential Harvesting (GPL-3.0) · Exploitation (NOASSERTION) · Pivoting Tunneling (GPL-3.0) · Server Security Init Skill (NOASSERTION) · linux-lateral-movement (MIT)