Privesc Linux

Linux local privilege escalation from a low-privilege shell to root. Covers quiet vs loud enumeration, sudo/GTFOBins, CVE-2025-32463 chwoot and CVE-2025-32462 host bypass, polkit/udisks CVE-2025-6018/6019, SUID/capabilities, systemd timers/units, cron/PATH/LD_PRELOAD, dangerous groups and docker.sock, host-local container escape, and version-gated kernel LPE including Copy Fail CVE-2026-31431. Use when the operator has a Linux foothold and needs root. Kubernetes RBAC stays in /k8s. Endpoint blocks hand off to /edr-bypass then return here.

pale-knight 2d5001a 6 files · 33.3 KB Updated

File contents

pale-knight/redteam-skill/tree/main/skills/privesc-linux commit 2d5001acdf

Frequently asked questions

npx skillmds@latest add pale-knight/privesc-linux