Skip to content
64

Awesome Privilege Escalation

A curated list of awesome privilege escalation

1.6k stars176 forks186 entriesLast push Mar 23, 2026 (6 months ago)License none

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Linux

A guide to Linux Privilege Escalation

by Rashid-Feroze

Attack and Defend: LinuxPrivilege Escalation Techniques of 2016

This paper will examine Linux privilege escalation techniques used throughout 2016 in detail, highlighting how these techniques work and how adversaries are using them.

Back To The Future: Unix Wildcards Gone Wild

This article will cover one interesting old-school Unix hacking technique, that will still work in 2013.

Basic Linux Privilege Escalation

by g0tmi1k

In 3 lists

Enumeration is the Key

by Marcos Tolosa

Hackers Hut

Some random hacking hints, mainly from a Linux point of view.

Hacking Linux Part I: Privilege Escalation

How privileges work in operating systems?

Linux elevation of privileges ToC

Linux - Privilege Escalation

Methodology from PayloadsAllTheThings

In 12 listsDetails

Linux Privilege Escalation

an introduction to Linux escalation techniques, mainly focusing on file/process permissions, but along with some other stuff too.

Linux Privilege Escalation

Linux Privilege Escalation by lamontns.

Linux Privilege Escalation

by HackTricks

Linux Privilege Escalation

by reboare.

Local Priv Esc - Linux

by Offsec Journey.

PrivilageEsc Linux

by h4rithd.

Linux Privilege Escalation – Exploiting User Groups

by Steflan Security.

Linux Privilege Escalation via Dynamically Linked Shared Object Library

How RPATH and Weak File Permissions can lead to a system compromise.

Local Linux Enumeration & Privilege Escalation Cheatsheet

a few Linux commands that may come in useful when trying to escalate privileges on a target system.

Local Linux Enumeration & Privilege Escalation

a few Linux commands that may come in useful when trying to escalate privileges on a target system.

Local Linux privilege escalation overview

This article will give an overview of the basic Linux privilege escalation techniques. It separates the local Linux privilege escalation in different scopes: kernel, process, mining credentials, sudo, cron, NFS, and file permission.

Penetration-Testing-Grimoire/Privilege Escalation/linux.md

PENETRATION TESTING PRACTICE LAB - VULNERABLE APPS / SYSTEMS

Pentest Book - Privilege Escalation

common Linux privilege escalation techniques.

POST CATEGORY : Privilege Escalation

Privilege escalation post category in Raj Chandel's Blog.

Privilege Escalation Cheatsheet (Vulnhub)

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

Privilege escalation: Linux

Privilege Escalation & Post-Exploitation

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

In 6 listsDetails

Reach the root! How to gain privileges in Linux?

Understanding Privilege Escalation

Some techniques malicious users employ to escalate their privileges on a Linux system.

Linux >Escape restricted shells

Breaking out of rbash using scp

Escaping from Restricted Shell and Gaining Root Access to SolarWinds Log & Event Manager (SIEM) Product

Escaping Restricted Linux Shells

Resource for penetration testers to assist them when confronted with a restricted shell.

Linux Restricted Shell Bypass

Restricted Linux Shell Escaping Techniques

The focus of this article is on discussing and summarizing different techniques to escape common Linux restricted shells and also simple recommendations for administrators to protect against it.

Linux >SUDO and SUID

Abusing SUDO

Some of the binary which helps you to escalate privilege using the sudo command.

Gaining a Root shell using MySQL User Defined Functions and SETUID Binaries

How a MySQL User Defined Function (UDF) and a SETUID binary can be used to elevate user privilege to a root shell.

GTFOBins

GTFOBins is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.

In 4 listsDetails

How I got root with Sudo

Sudo (LD_PRELOAD)

Privilege Escalation from an LD_PRELOAD environment variable.

Linux >Capabilities

An Interesting Privilege Escalation vector (getcap/setcap)

Capabilities

Exploiting capabilities

Parcel root power, the dark side of capabilities

getcap, setcap and file capabilities

Spicing up your own access with capabilities

Linux >TTY Pushback / TIOCSTI injection

The oldest privesc: injecting careless administrators' terminals using TTY pushback

By Guillaume Quéré

TIOCSTI injection

Abusing TIOCSTI to manipulate process file descriptors and execute arbitrary commands. By Krystian Bajno

TIOCSTI is a kernel problem.

By Jonathan de Boyne Pollard.

TTY Input Pushback Privilege Escalation

When user working as root switches to another user with su and happens to execute the pushback program as that user, the tty input data pushed back is executed in the shell and context of user root.

Linux >Tools

AutoLocalPrivilegeEscalation

An automated script that download potential exploit for linux kernel from exploitdb, and compile them automatically.

BeRoot

BeRoot Project is a post exploitation tool to check common misconfigurations to find a way to escalate our privilege. exploits.

exploit-suggester

This tool reads the output of “showrev -p” on Solaris machines and outputs a list of exploits that you might want to try. is intended to be executed locally on a Linux box to enumerate basic system info and search for common privilege escalation vectors such as word writable files,…

GTFONow

Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.

kernelpop

kernelpop is a framework for performing automated kernel vulnerability enumeration and exploitation.

LES

LES: Linux privilege escalation auditing tool

In 2 lists

LinEnum

Scripted local Linux enumeration & privilege escalation checks

In 3 lists

LinPEAS

Linux Privilege Escalation Awesome Script

In 2 lists

Linux Exploit Suggester 2

Next-generation exploit suggester based on Linux_Exploit_Suggester

In 2 lists

Linux_Exploit_Suggester

Linux Exploit Suggester; based on operating system release number.

In 2 lists

linux-kernel-exploits

linux-kernel-exploits Linux平台提权漏洞集合

In 3 lists

Linuxprivchecker.py

This script is intended to be executed locally on a Linux box to enumerate basic system info and search for common privilege escalation vectors such as world writable files, misconfigurations, clear-text passwords and applicable exploits.

Linux Privilege Escalation Check Script

Originally forked from the linuxprivchecker.py (Mike Czumak), this script is intended to be executed locally on a Linux box to enumerate basic system info and search for common privilege escalation vectors such as word writable files, misconfigurations, clear-text password and applicable exploits.

linux-smart-enumeration

Linux enumeration tools for pentesting and CTFs

linux-soft-exploit-suggester

linux-soft-exploit-suggester finds exploits for all vulnerable software in a system helping with the privilege escalation.

In 2 lists

PrivEsc

A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.

pspy

unprivileged Linux process snooping

In 3 lists

SUDO_KILLER

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems.

In 2 lists

traitor

Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy!

In 3 lists

ttyinject

Alice gets ROOT when ROOT does 'su alice'.

unix-privesc-check

Shell script to check for simple privilege escalation vectors on Unix systems

In 2 lists

Unix-Privilege-Escalation-Exploits-Pack

Exploits for getting local root on Linux, BSD, AIX, HP-UX, Solaris, RHEL, SUSE etc.

uptux

Specialized privilege escalation checks for Linux systems.

active-cve-check

Checks a list of packages against the "active" (not yet patched) CVE's as listed in the Ubuntu CVE Tracker.

Arch-Audit

A tool to check vulnerable packages in Arch Linux.

cve-check-tool

Original Automated CVE Checking Tool.

LPVS

Linux Package Vulnerability Scanner for CentOS and Ubuntu.

Linux >NFS

Exploiting a Mis-Configured NFS Share

Linux Privilege Escalation using Misconfigured NFS

How to exploit a misconfigured NFS share to gain root access to a remote host machine.

NFS weak permissions

Linux Privilege Escalation using weak NFS permissions

t Linux Privilege Escalation using weak NFS permissions in “/etc/exports”. by Haider Mahmood

Linux >Presentations

Linux privilege escalation for fun, profit, and all around mischief

Examine opportunities for privilege escalation that can vault you from zero to hero in a few easy steps.

Linux Privilege Escalation - Tradecraft Security Weekly #22

Methodology for performing various privilege escalation techniques against Linux-based systems.

Privilege Escalation FTW

Demonstrate various privilege escalation techniques that are possible primarily due to misconfigurations.

Windows

awesome-windows-security

LOLBAS

Living Off The Land Binaries and Scripts (and also Libraries)

In 3 lists

OSCP Windows PrivEsc - Part 1

Privilege Escalation

There are also various other (local) exploits that can be used to also escalate privileges.

Privilege Escalation Windows

Privilege escalation: Windows

Windows elevation of privileges ToC

Windows Local Privilege Escalation

by HackTricks

Windows Local Privilege Escalation Cookbook

Windows Local Privilege Escalation Cookbook by nickvourd.

Windows Post Gather Modules

Metasploit offers a number of post exploitation modules that allow for further information gathering on your target network.

Windows Priv Esc

Windows Privilege Escalation Fundamentals

Windows Privilege Escalation Guide

Windows-Privilege-Escalation

Step-by-step windows privlege escalation methodology.

In 2 lists

Windows-Privilege-Escalation-Resources

Compilation of Resources from TCM's Windows Priv Esc Udemy Course. By Gr1mmie

Linux - Privilege Escalation

Methodology from PayloadsAllTheThings

In 12 listsDetails

Windows Privilege Escalation

Linux Privilege Escalation

Linux Privilege Escalation by lamontns.

Windows Privilege Escalations

Windows >DLL Hijacking

DLL Hijacking

DLL Search Order Hijacking for privilege escalation, code execution, etc. by Red Teaming Experiments

DLL Hijacking

by PentestLab

DLL Search Order Hijacking

by MITRE

PrivEsc: DLL Hijacking

by GracefulSecurity

Windows Privilege Escalation via DLL Hijacking

Crystal-clear view on one of the most used techniques for privilege escalation by the Threat Actors. by HacknPentest

Windows >Potato

CertPotato

Using ADCS to privesc from virtual and network service accounts to local system.

Coerced potato

From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10, Windows 11 and Server 2022.

Hot Potato

Hot potato is the code name of a Windows privilege escalation technique that was discovered by Stephen Breen. This technique is actually a combination of two known windows issues like NBNS spoofing and NTLM relay with the implementation of a fake WPAD proxy server which is running locally on the…

Hot Potato

Windows 7, 8, 10, Server 2008, Server 2012 Privilege Escalation in Metasploit & PowerShell.

Hot Potato – Windows Privilege Escalation

Privilege Escalation on Windows 7, 8, 10, Server 2008, Server 2012 … and a new network attack.

Juicy Potato (abusing the golden privileges)

No more JuicyPotato? Old story, welcome RoguePotato!

by decoder_it and splinter_code/antonioCoco

Remote Potato

Remote Potato – From Domain User to Enterprise Admin

Rotten Potato – Privilege Escalation from Service Accounts to SYSTEM

Windows >Unquoted services with spaces

Practical Guide to exploiting the unquoted service path vulnerability in Windows

PrivEsc: Unquoted Service Path

Unquoted Service Path

UNQUOTED SERVICE PATHS

Windows Privilege Escalation — Part 1 (Unquoted Service Path)

Windows Privilege Escalation – Unquoted Services

Windows Privilege Escalation via Unquoted Service Paths

Windows >Groups.xml

Finding Passwords in SYSVOL & Exploiting Group Policy Preferences

gpp-decrypt Package Description

A simple ruby script that will decrypt a given GPP encrypted string.

Windows >PrintNightmare

Universal Privilege Escalation and Persistence

The Print Spooler is responsible to manage and process printer jobs. It runs as a service with SYSTEM level privileges on windows environments.

Windows >NoFilter

#NoFilter - Abusing Windows Filtering Platform for Privilege Escalation

An evasive and undetected privilege escalation technique that abuses the Windows Filtering Platform (WFP).

Windows >Tools

ADAPE-Script

Active Directory Assessment and Privilege Escalation Script by hausec

In 2 lists

GodPotato

GodPotato enables privilege escalation in Windows 2012 - Windows 2022, now as long as you have "ImpersonatePrivilege" permission.

In 2 lists

JAWS - Just Another Windows (Enum) Script

JAWS is PowerShell script designed to help penetration testers (and CTFers) quickly identify potential privilege escalation vectors on Windows systems. It is written using PowerShell 2.0 so 'should' run on every Windows version since Windows 7.

juicy-potato

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.

In 2 lists

NoFilter

Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as "NT AUTHORITY\SYSTEM" or as another user that is logged on to the machine.

Potato

Potato Privilege Escalation on Windows 7, 8, 10, Server 2008, Server 2012.

PowerSploit

PowerSploit is a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment.

In 7 listsDetails

PrivescCheck

Enumerate common Windows security misconfigurations which can be leveraged for privilege escalation and gather various information which might be useful for exploitation and/or post-exploitation, by itm4n.

RemotePotato0

Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin by antonioCoco.

In 2 lists

RoguePotato

Another Windows Local Privilege Escalation from Service Account to System by splinter_code/antonioCoco

In 2 lists

RottenPotato

RottenPotato local privilege escalation from service account to SYSTEM. (No longer maintained)

RottenPotatoNG

New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

In 2 lists

Seatbelt

Project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

In 2 lists

SessionGopher

SessionGopher is a PowerShell tool that finds and decrypts saved session information for remote access tools.

Sherlock

PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities. (Deprecated)

In 2 lists

SweetPotato

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 by CCob

In 2 lists

Tater

Tater is a PowerShell implementation of the Hot Potato Windows Privilege Escalation exploit.

Watson

Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities.

In 3 lists

WindowsEnum

A Powershell Privilege Escalation Enumeration Script.

Windows-Exploit-Suggester

This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. By AonCyberLabs

Windows Exploit Suggester - Next Generation (WES-NG)

WES-NG is a tool based on the output of Windows' systeminfo utility which provides the list of vulnerabilities the OS is vulnerable to, including any exploits for these vulnerabilities. Every Windows OS between Windows XP and Windows 10, including their Windows Server counterparts, is supported.…

windows-privesc-check

Standalone executable that runs on Windows systems. It tries to find misconfigurations that could allow local unprivileged users to escalate privileges to other users or to access local apps (e.g. databases).

LinPEAS

Linux Privilege Escalation Awesome Script

In 2 lists

WinPwnage

UAC bypass, Elevate, Persistence and Execution methods. The goal of this repo is to study the Windows penetration techniques.

Windows >Presentations

Level Up! Practical Windows Privilege Escalation - Andrew Smith

In 2 lists

Level Up! - Practical Windows Privilege Escalation (Presentation Slides)

SANS Webcast: Pen Testing with PowerShell - Local Privilege Escalation Techniques

Windows Privilege Escalation Techniques (Local) - Tradecraft Security Weekly #2

Windows Privilege Escalation Unquoted Service - Part 1

Windows Privilege Escalation Unquoted Service - Part 2

Windows Privilege Escalation Unquoted Service - Part 3

Linux and Windows

Awesome-Hacking-Resources (Privilege escalation section)

A collection of hacking / penetration testing resources to make you better!

Metasploit Local Exploit Suggester: Do Less, Get More!

My 5 Top Ways to Escalate Privileges

Bruno Oliveira's top 5 favorite ways for accomplishing privilege escalation in the most practical ways possible.

Privilege Escalation

Privilege Escalation category by pentestlab.blog

Recipe for Root

Your Cookbook for Privilege Escalation

Windows / Linux Local Privilege Escalation Workshop

The Privilege Escalation Workshop covers all known (at the time) attack vectors of local user privilege escalation on both Linux and Windows operating systems and includes slides, videos, test VMs.

In 4 lists

Docker

Bypassing Docker Authz Plugin and Using Docker-Containerd for Privesc

by Staaldraad.

Container security notes

Dirty COW - (CVE-2016-5195) - Docker Container Escape

Docker Breakout

by HackTricks

Docker security checklist

Don't expose the Docker socket (not even to a container)

Escaping Docker Privileged Containers

by Vickie Li

Escaping Containers to Execute Commands on Play with Docker Servers

Escaping Docker container using waitid() – CVE-2017-5123

Escaping privileged containers for fun

by Jordy/Oblivion/pwning.systems

Escaping the Whale: Things you probably shouldn’t do with Docker (Part 1)

Hack Allows Escape of Play-with-Docker Containers

Hacking Docker the Easy way

Understanding Docker container escapes

by Trail of Bits

Docker >Tools

BOtB

BOtB is a container analysis and exploitation tool designed to be used by pentesters and engineers while also being CI/CD friendly with common CI/CD technologies.

CDK

CDK is an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency.

In 3 lists

Deepce

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Dokcer-escape-tool

This tool will help identify if you're in a Docker container and try some quick escape techniques to help assess the security of your containers.

PrivilegedDockerEscape

A bash script to create an interactive shell from a privileged docker container to the container host

Docker >Presentations

Introduction to Docker Hacking

by NahamSec

Cloud >AWS

AWS-IAM-Privilege-Escalation

A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.

Pacu

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. By RhinoSecurityLabs.

In 4 lists

Cloud >GCP

Tutorial on privilege escalation and post exploitation tactics in Google Cloud Platform environments

Very deep-dive into manual post-exploitation tactics and techniques for GCP.

GCP-IAM-Privilege-Escalation

IAM Privilege Escalation in GCP by RhinoSecurity.

GCPBucketBrute

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated. By RhinoSecurity.

In 3 lists
See category
94

Awesome Mac

jaywcjlove/awesome-mac

 This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.

Fresh★ 115k1316 entriesPushed today
91

Open Source Mac Os Apps

serhii-londar/open-source-mac-os-apps

🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps

Fresh★ 51k700 entriesPushed 20 days ago
91

Awesome-Kubernetes

ramitsurana/awesome-kubernetes

A curated list for awesome kubernetes sources :ship::tada:

Fresh★ 16k47 entriesPushed 8 days ago
90

Awesome Nodejs

sindresorhus/awesome-nodejs

:zap: Delightful Node.js packages and resources [BECAUSE OF TOO MUCH SPAM AND LOW-QUALITY SUBMISSIONS, SUBMISSIONS ARE PAUSED TEMPORARILY]

Fresh★ 67k588 entriesPushed 28 days ago
90

Awesome Home Assistant

frenck/awesome-home-assistant

A curated list of amazingly awesome Home Assistant resources.

Fresh★ 8.5k312 entriesPushed 2 days ago
90

Awesome Ios

vsouza/awesome-ios

A curated list of awesome iOS ecosystem, including Objective-C and Swift Projects

Fresh★ 53k1812 entriesPushed 1 month ago