Post-Exploitation and Privilege Escalation
Post-exploitation is the work an authorized tester does after obtaining initial access. Privilege escalation asks whether that access can reach permissions or data beyond its intended boundary, while keeping the test within its agreed scope.
itOffensive security and application security | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Post-Exploitation and Privilege Escalation
A foothold is a place to start, not a verdict about how far someone can go. Post-exploitation asks what an authorized starting identity can actually reach after initial access. Privilege escalation is the narrower case where an action produces higher-level permissions. The account name may sound impressive, but the permission check gets the final word.
The useful mental picture is an access path: an identity, an action it is allowed to take, a resource, and a resulting security context. Each connection needs evidence. A writable service file looks promising. It only becomes an elevation path if a more privileged process consumes that exact file in a way that changes authority. If the process never reads it, the diagram is a fine diagram and a poor finding.
There are several kinds of permission boundary. Linux has user and group IDs plus capability sets. Windows processes carry access tokens with groups and privileges, and an administrator can run under a filtered token. A cloud request meets applicable policies, where an explicit deny can defeat an apparent allow. These models all ask who can do what, but they do not award the same prize. Root on one host does not grant control of a directory or cloud tenant.
Several neighboring activities can be mistaken for elevation. Discovery reveals who and what is present. Finding a password is credential access; using an existing identity on a second machine is lateral movement. Preserving access after the current session is persistence. None of these observations alone demonstrates higher privilege. A report that blends them into one success story hides the transition that mattered.
A permission that looks dangerous is a candidate. Check its target, trigger, and remaining restrictions. Then choose the smallest proof the engagement allows. If that proof needs a service restart, production credentials, or an excluded system, stop and write down the untested condition. A careful hypothesis is more useful than a confident claim that cannot be defended.
The Cheatsheet gives the edge-by-edge model and the difference between candidate and confirmed. The Practice Reference shows how to inspect a context and select a proof grade. The exercise lets you apply that reasoning to a fictional service without touching a machine. Start there if the phrase "privilege escalation" currently suggests one universal button. There is no such button, which is inconvenient but also the reason the evidence matters.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/115/final
Supports
- Scope, rules of engagement, controlled validation, evidence, and reporting
- Candidate and confirmed findings in the intro, practice reference, quiz, and exercise
- Reference path and Updates source rationale
- https://pentest-standard.readthedocs.io/en/latest/post_exploitation.html
Supports
- Post-exploitation purpose and phase-specific rules of engagement
- Data handling, cleanup, and tradeoff Field Note
- Reference path and quiz scope decisions
- https://attack.mitre.org/tactics/TA0007/
Supports
- Discovery objective and distinction from privilege escalation
- Slides, cheatsheet, and reference path
- https://attack.mitre.org/tactics/TA0004/
Supports
- Definition and examples of higher-level permissions
- Quiz answer and objective distinctions
- https://attack.mitre.org/techniques/T1548/
Supports
- Sudo, setuid, Windows, and cloud elevation-control families
- Cross-platform candidate-edge examples
- https://attack.mitre.org/tactics/TA0008/
Supports
- Meaning of lateral movement and distinction from privilege escalation
- Quiz answers and cheatsheet outcome table
- https://attack.mitre.org/tactics/TA0003/
Supports
- Persistence as continued access
- Intro, slides, cheatsheet, and script distinctions
- https://man7.org/linux/man-pages/man7/capabilities.7.html
Supports
- Effective Linux capability set and file capability behavior
- Linux context checks, reference link, and quiz answer
- https://learn.microsoft.com/en-us/windows/win32/secauthz/access-tokens
Supports
- Windows process token contents
- Windows context checks, reference link, and quiz answer
- https://learn.microsoft.com/en-us/windows/win32/secauthz/privileges
Supports
- Difference between privileges and object access rights
- Disabled privileges and hero quiz answer
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works
Supports
- Filtered token for administrator account
- Difficulty Field Note and intermediate quiz answer
- https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
Supports
- Applicable policies and explicit deny
- Cloud boundary examples, reference link, Field Note, and quiz answers
- https://github.com/enaqx/awesome-pentest
Supports
- Discovery of GTFOBins, LOLBAS, and pspy
- Selection for Awesome Links
- https://gtfobins.org/
Supports
- Unix-like executable functions and restriction contexts
- Awesome Links rationale
- https://lolbas-project.github.io/
Supports
- Windows native binary and script catalog
- Awesome Links rationale
- https://github.com/DominicBreuker/pspy
Supports
- Unprivileged Linux process observation
- Awesome Links rationale
- https://www.rapid7.com/products/metasploit/
Supports
- Metasploit Pro post-exploitation module placement in Landscape
- https://www.fortra.com/products/penetration-testing-software
Supports
- Core Impact penetration testing placement in Landscape
- https://static.fortra.com/core-security/pdfs/datasheets/cs-core-impact-technical-ds.pdf
Supports
- Core Impact agent chaining, privilege escalation, and pivoting
- https://www.cobaltstrike.com/
Supports
- Cobalt Strike post-exploitation agent and adversary simulation
- https://specterops.io/bloodhound-enterprise/
Supports
- BloodHound Enterprise identity attack-path analysis
- Landscape placement and hero quiz distractor
- https://pentera.io/
Supports
- Pentera internal exposure validation and privilege escalation placement
- https://learn.microsoft.com/en-us/security/ransomware/dart-ransomware-case-study
Supports
- Firsthand account of discovery, credential theft, and remote movement
- Mistake Field Note
