ssh-key-scanner
Installation
SKILL.md
SSH Key Scanner
Post-exploitation SSH credential hunting — finds private keys, authorized_keys, cloud credentials, and known_hosts for lateral movement.
Quick Start
# Hunt current user's SSH keys
find ~/.ssh -type f -readable 2>/dev/null
# Hunt all users' SSH keys (requires root)
find /home -name ".ssh" -type d 2>/dev/null | while read dir; do echo "=== $dir ==="; ls -la "$dir" 2>/dev/null; done
# Check for SSH configs (hosts, keys, passwords)
cat ~/.ssh/config 2>/dev/null
# Extract hosts from known_hosts
cut -d' ' -f1 ~/.ssh/known_hosts 2>/dev/null | cut -d',' -f1