π§Services & Internals Enumeration
π― Overview
Deep enumeration of running services, internal processes, user activities, and system internals to identify privilege escalation vectors and attack opportunities.
π Network Internals
Network Interfaces & Connectivity
# Network interfaces (pivot opportunities)
ip a
ifconfig -a
# Hosts file analysis
cat /etc/hosts
# Check for internal networks and additional interfacesπ₯ User Activity Analysis
Login History & Current Users
Look for:
Active admin users
Login patterns and timing
Remote connections (SSH sessions)
Shared accounts
Command History Investigation
Search for Sensitive Commands:
β° Scheduled Tasks & Automation
Cron Job Enumeration
Analysis Points:
Scripts running as root
Writable paths in cron jobs
File permission issues
Backup scripts with credentials
π¦ Installed Software & Packages
Package Analysis
GTFObins Cross-Reference
π Process & Service Analysis
Running Processes
Process Investigation
π Configuration & Script Discovery
Configuration Files
Script Discovery
π System Internals
/proc Filesystem Analysis
File System Details
π οΈ Available Tools Assessment
Development Tools
Useful Binaries for Privesc
π Quick Enumeration Script
π― Key Targets to Identify
High-Value Information
Active admin sessions - Target for credential stealing
Vulnerable services - Running as root with known CVEs
Scheduled tasks - Cron jobs with misconfigurations
Config files - Containing passwords or sensitive data
Development tools - Compilers for exploit compilation
Network tools - For lateral movement and pivoting
Attack Vector Prioritization
SUID/SGID binaries with GTFObins entries
Root processes with configuration vulnerabilities
Writable cron jobs or scripts executed by root
Readable config files with embedded credentials
Development environments with compilation capabilities
Services and internals enumeration reveals the operational heartbeat of the system - identifying running processes, user activities, and system configurations that can be leveraged for privilege escalation.
Last updated