The bible of Unix binaries you can abuse when sudo/SUID/capabilities misconfigure. Turns 'sudo can run vim' into 'I have root' three visits a month.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Any sudo binary = lookup time.
Each binary page lists escape snippets per context.
You just used a sysadmin's convenience as a ladder.
SUID-bit binaries are fair game for the same abuse.
Modern Linux caps are SUID 2.0 โ always check.
| sudo context | no password? escape |
| SUID context | bit + binary |
| capabilities | cap_setuid etc. |
| LOLBAS | the Windows sibling |
| search by binary | instant recipes |
Bookmark the trio: GTFOBins (linux), LOLBAS (windows), WADComs (workflow).
When sudo -l shows ANYTHING nonstandard โ GTFOBins first, thinking second.
Blue team: every GTFOBin-able sudo rule is a defect; inventory yours.
TryHackMe 'Linux PrivEsc' room is the perfect companion.
Use GTFOBins only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.