SSH Penetration Testing

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions for performing network-wide SSH service discovery and brute-force credential attacks using tools such as Nmap, Hydra, and Medusa.
  • [DATA_EXFILTRATION]: Instructions are included for locating and exfiltrating SSH private keys and sensitive configuration files from the target's filesystem and command history.
  • [COMMAND_EXECUTION]: Provides specific commands to establish persistence on a target system by modifying the authorized_keys configuration to maintain unauthorized access.
  • [REMOTE_CODE_EXECUTION]: Includes a Python script implementation using the paramiko library, which allows for the automated execution of arbitrary shell commands on remote systems.
  • [COMMAND_EXECUTION]: Details techniques for network pivoting using local, remote, and dynamic SSH port forwarding.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — SSH Penetration Testing