linux-lateral-movement
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMPERSISTENCEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PERSISTENCE]: The playbook outlines methods for maintaining access via systemd service manipulation, specifically demonstrating how to construct a backdoor service that executes a bash reverse shell on startup.
- [PRIVILEGE_ESCALATION]: The skill details instructions for acquiring elevated access, including abusing NFS mounts with no_root_squash to create SUID shell binaries and utilizing ptrace-based process injection to hijack active sudo tokens.
- [COMMAND_EXECUTION]: The playbook guides the agent on running shell commands for reverse connections (
/dev/tcpnetwork streams), creating local/remote network tunnels, and deploying SOCKS proxies with external utilities like chisel. - [DATA_EXFILTRATION]: The instructions command the searching and harvesting of sensitive user data, targeting system configuration credentials, environment variables, history logs, database access files, and unencrypted SSH private keys.
Audit Metadata