ssh-key-scanner

Installation
SKILL.md

SSH Key Scanner

Post-exploitation SSH credential hunting — finds private keys, authorized_keys, cloud credentials, and known_hosts for lateral movement.

Quick Start

# Hunt current user's SSH keys
find ~/.ssh -type f -readable 2>/dev/null

# Hunt all users' SSH keys (requires root)
find /home -name ".ssh" -type d 2>/dev/null | while read dir; do echo "=== $dir ==="; ls -la "$dir" 2>/dev/null; done

# Check for SSH configs (hosts, keys, passwords)
cat ~/.ssh/config 2>/dev/null

# Extract hosts from known_hosts
cut -d' ' -f1 ~/.ssh/known_hosts 2>/dev/null | cut -d',' -f1
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
ssh-key-scanner — aeondave/malskill