home/toolvault/priv-esc & post-exploitation/linpeas-winpeas

LinPEAS / WinPEAS //

Priv-Esc & Post-Exploitationprivesc enum

Got a low-privilege shell? PEASS scripts paint privilege-escalation paths in screaming color โ€” misconfigs you'd never find manually, in seconds.

difficulty ยท easy
10 min
time to first win
5
guided steps
0
students started here*

HOW TO USE LINPEAS / WINPEAS

Follow the steps โ€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

linpeas-winpeas โ€” guided lab session
static view
step 01

Get it onto the lab target

python3 -m http.server (kali) โ†’ curl -O linpeas.sh (target)

Host on attacker, pull from victim โ€” standard tradecraft.

step 02

Run + save output

./linpeas.sh | tee linpeas.txt

tee keeps evidence while you watch.

step 03

Read the colors

search: 'Highly probable' (RED/YELLOW)

Red/yellow highlights are the algorithm's 'look here'.

step 04

Windows edition

winPEASx64.exe quiet > out.txt

quiet mode + capture for careful reading.

step 05

Confirm & exploit one finding

cat /etc/sudoers โ†’ allowed: (ALL) NOPASSWD: /usr/bin/vim

Every PEAS finding links logically to escalation โ€” practice the full loop.

THE WORKFLOW AT A GLANCE

๐Ÿš
Foothold
low-priv shell
๐Ÿ“ค
Upload
peas to target
๐Ÿ”
Scan
100 checks/sec
๐ŸŽจ
Highlights
red/yellow
๐Ÿชœ
Escalate
root/system
LEARNING CURVE
easy โ€” 10 min to first win

FLAGS & SUPER-MOVES

linpeas.shLinux enum
winPEAS*.exeWindows enum
-a / -sdeep checks / faster
tee outsave output
RED/YELLOWhigh-probability paths

PRO TIPS

01

Run them on every single CTF box โ€” it's the standard first move after foothold.

Run them on every single CTF box โ€” it's the standard first move after foothold.

02

Read PEASS output top-to-bottom once fully; it teaches what to check manually.

Read PEASS output top-to-bottom once fully; it teaches what to check manually.

03

sudo -l alone finds ~30% of lab escalations before any script runs.

sudo -l alone finds ~30% of lab escalations before any script runs.

04

Defenders

Defenders: PEASS findings = your hardening to-do list, verbatim.

โš–๏ธ

Golden rule

Use LinPEAS / WinPEAS only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
โœ๏ธ Author LDM ยท ldmhub4u@gmail.com
full guide v1 ยท v2 immersive ยท latest news
Made for learners, everywhere ยท 2026
*plausibly. verify commands with official docs.