Linux MOC
Sections Linux MOC
Lifecycle flow for a Linux host. Scan top to bottom.
Enumerate
Access
Escalate
- Local Enum
- PrivEsc - SUID & Sudo
- PrivEsc - Cron & Timers
- PrivEsc - Capabilities
- PrivEsc - Services & Sockets
- PrivEsc - Kernel & Exploits
- PrivEsc - Credentials & Files
Move
Decision order
Enum surface, grab cheapest privesc win (sudo, suid, caps), only reach for kernel exploits when nothing else lands.