Privilege Escalation

Linux Privesc

Credential Hunting on Linux: From .bash_history to Config Files

A practical guide to hunting cleartext credentials on Linux hosts via history files, config files, and grep, plus defenses.
Linux Privesc

Baron Samedit: Exploiting the sudo Heap Overflow (CVE-2021-3156)

A practical walkthrough of Baron Samedit (CVE-2021-3156), the sudo heap overflow that yields local root, plus detection and defense.
Linux Privesc

Linux Enumeration Cheat Sheet for Privilege Escalation

A practical Linux post-exploitation enumeration cheat sheet covering id, uname -a, sudo -l, SUID hunting, and process inspection.
Tools & Defense

Breaking Out: A Practical Guide to Linux Container Escape Techniques

How privileged containers, host mounts, cgroups, and CAP_SYS_ADMIN lead to container escape, plus blue-team defenses.
Cloud Security

AWS IAM Privilege Escalation Paths: From Low-Priv Credentials to Account Takeover

A practical look at common AWS IAM privilege escalation paths, PoC commands, and the blue-team controls that shut them down.
Cloud Security

Enumerating and Exploiting AWS with Pacu

A practical walkthrough of using Pacu to enumerate AWS identities, IAM permissions, and discover privilege escalation paths.
Cloud Security

Azure & Entra ID Attack Paths: Hunting Privilege Escalation with AzureHound

Advanced Entra ID attack paths: AzureHound enumeration, role assignment abuse, dynamic group injection, and OAuth consent grants.
Cloud Security

GCP Privilege Escalation: Abusing Service Account Impersonation and IAM Misconfigurations

How attackers abuse actAs, setIamPolicy, and service account impersonation to escalate privileges in Google Cloud, with blue-team defenses.
Containers & DevSecOps

Advanced Container Escape Techniques: From CAP_SYS_ADMIN to Host Root

A practical look at advanced container escape primitives — release_agent, /proc abuse, host mounts, and runc CVEs.
Containers & DevSecOps

Kubernetes RBAC Attacks: Privilege Escalation from a Compromised Service Account

How attackers abuse Kubernetes RBAC roles, bindings, and service account tokens to escalate to cluster-admin, and how to defend.
Vulnlab

Vulnlab Feedback Walkthrough by Yunolay (Apache Tomcat Log4Shell)

OverviewFeedback (Solo, Linux)Junior Level Linux MachineYou will learn about exploiting a popular Java CVEUserThis box w...
Vulnlab

Vulnlab Data Walkthrough by Yunolay (LFI with path traversal, Docker privileged user)

OverviewData (Solo, Linux)Junior Level Linux MachineYou will learn about getting a foothold through a CVE, cracking cust...
Vulnlab

Vulnlab Sync Walkthrough by Yunolay (Rsync, Custom Hash Crack, Writable files executed by a privileged user)

OverviewSync (Solo, Linux)Junior Level Linux Machine.You will learn about exploiting custom applications & misconfigurat...
Vulnlab

Vulnlab Baby Walkthrough by Yunolay (LDAP Enumeration, SMB Password Spraying, Privilege escalation using SeBackupPrivilege and SeRestorePrivilege)

OverviewActive Directory PentestingBaby (Solo, Windows)Junior Level Windows Active Directory MachineYou will learn about...