linux-lateral-movement

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMPERSISTENCEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PERSISTENCE]: The playbook outlines methods for maintaining access via systemd service manipulation, specifically demonstrating how to construct a backdoor service that executes a bash reverse shell on startup.
  • [PRIVILEGE_ESCALATION]: The skill details instructions for acquiring elevated access, including abusing NFS mounts with no_root_squash to create SUID shell binaries and utilizing ptrace-based process injection to hijack active sudo tokens.
  • [COMMAND_EXECUTION]: The playbook guides the agent on running shell commands for reverse connections (/dev/tcp network streams), creating local/remote network tunnels, and deploying SOCKS proxies with external utilities like chisel.
  • [DATA_EXFILTRATION]: The instructions command the searching and harvesting of sensitive user data, targeting system configuration credentials, environment variables, history logs, database access files, and unencrypted SSH private keys.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:12 PM
Security Audit — agent-trust-hub — linux-lateral-movement