Linux privesc via sudo / SUID / capabilities (GTFOBins)
SkillFiles & storageLinux privilege escalation via sudo rules, SUID/SGID binaries, and capabilities using GTFOBins techniques. Load with a Linux shell needing root, on `sudo -l` output, SUID/`getcap` findings, or "escalate on Linux". Signals: allowed sudo commands, SUID binaries, file capabilities, cron/PATH abuse.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Linux privesc via sudo / SUID / capabilities (GTFOBins) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/privesc/privesc-linux-gtfobins/SKILL.md and read by ahel’s review.
When it applies
You have a low-priv Linux shell. The fastest root is almost always a misconfig — a sudo rule, a SUID binary, or a file capability that a known GTFOBins technique turns into a root shell or file read/write. Do this before kernel exploits.
Why it works
Many normal binaries can spawn shells, read/write files, or run commands. When such a binary runs
with elevated rights — via sudo, the SUID bit, or a capability like cap_setuid — that power
becomes yours. GTFOBins catalogs the exact escape for each binary.
Method
- Enumerate the three vectors:
sudo -l— commands you can run as root/another user (even NOPASSWD).find / -perm -4000 -type f 2>/dev/null— SUID binaries.getcap -r / 2>/dev/null— file capabilities (cap_setuid,cap_dac_read_search).
- Look up the binary on GTFOBins for the matching function (sudo / suid / capabilities) and
run the exact escape (e.g.
sudo vim -c ':!/bin/sh',find . -exec /bin/sh \;if SUID, a capability-basedpython -c 'import os;os.setuid(0);...'). - Also check: writable cron jobs / scripts run as root (
pspyto watch), writablePATHentries a root process calls,LD_PRELOAD/env_keepin sudo, wildcard injection in root scripts. - Stabilize the root shell and grab proof.
Gotchas
sudo -lNOPASSWD entries are the quickest win — check first.- A SUID binary that drops privileges is safe; GTFOBins tells you which escapes actually keep root.
linpeasfinds all three fast, but understand the vector before firing — some escapes need exact args.
Verify success
A shell/command running as root (id shows uid=0), or root-only file read/write, via the misconfig.
References
GTFOBins; linpeas; "Linux privilege escalation" (HackTricks); pspy.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
privesc-linux-gtfobins- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · wshobson
The pick for Pythonpython-pro
Skill · jeffallan
The pick for Pythonpptx
Skill · anthropics
More in Files & storagedocx
Skill · anthropics
More in Files & storageresearch
Skill · mattpocock
More in Files & storageto-tickets
Skill · mattpocock
More in Files & storage