Got a low-privilege shell? PEASS scripts paint privilege-escalation paths in screaming color โ misconfigs you'd never find manually, in seconds.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Host on attacker, pull from victim โ standard tradecraft.
tee keeps evidence while you watch.
Red/yellow highlights are the algorithm's 'look here'.
quiet mode + capture for careful reading.
Every PEAS finding links logically to escalation โ practice the full loop.
| linpeas.sh | Linux enum |
| winPEAS*.exe | Windows enum |
| -a / -s | deep checks / faster |
| tee out | save output |
| RED/YELLOW | high-probability paths |
Run them on every single CTF box โ it's the standard first move after foothold.
Read PEASS output top-to-bottom once fully; it teaches what to check manually.
sudo -l alone finds ~30% of lab escalations before any script runs.
Defenders: PEASS findings = your hardening to-do list, verbatim.
Use LinPEAS / WinPEAS only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.