// HackTricks · CC BY-NC 4.0

Linux

69 pages · adapted from upstream with source attribution on every page.

001 Linux Android Rooting Frameworks (KernelSU/Magisk) Manager Auth Bypass & Syscall Hook Abuse software-information 002 Linux AppArmor protections 003 Linux Arbitrary File Write to Root interesting-files-permissions 004 Linux Assessment And Hardening container-security 005 Linux Bypass FS protections: read-only / no-exec / Distroless bypass-fs-protections-read-only-no-exec-distroless 006 Linux Bypass Linux Restrictions bypass-linux-restrictions 007 Linux cgroup Namespace namespaces 008 Linux cgroups protections 009 Linux Cisco - vmanage network-information 010 Linux Container Protections Overview protections 011 Linux Container Runtimes, Engines, Builders, And Sandboxes container-security 012 Linux Container Security container-security 013 Linux Containerd (ctr) Privilege Escalation containers-namespaces 014 Linux Copy Fail: AFALG + splice page-cache overwrite (CVE-2026-31431) kernel-lpe-cves 015 Linux D-Bus Enumeration & Command Injection Privilege Escalation processes-crontab-systemd-dbus 016 Linux DDexec / EverythingExec bypass-fs-protections-read-only-no-exec-distroless 017 Linux Distroless Containers container-security 018 Linux Escaping From --privileged Containers container-security 019 Linux Escaping from Jails main-system-information 020 Linux euid, ruid, suid user-information 021 Linux Filesystem, Inodes and Recovery main-system-information 022 Linux FreeIPA Pentesting software-information 023 Linux Image Security, Signing, And Secrets container-security 024 Linux Interesting Groups - Linux Privesc interesting-groups-linux-pe 025 Linux IPC Namespace namespaces 026 Linux Kernel Modules and modprobe Abuse main-system-information 027 Linux ld.so privesc exploit example interesting-files-permissions 028 Linux Linux Active Directory user-information 029 Linux Linux Capabilities interesting-files-permissions 030 Linux Linux Capabilities In Containers protections 031 Linux Linux Environment Variables linux-basics 032 Linux Linux Post-Exploitation linux-post-exploitation 033 Linux Linux Privilege Escalation linux-privilege-escalation 034 Linux Linux Privilege Escalation Checklist main-system-information 035 Linux Linux ptrace exit-race pidfdgetfd() FD theft kernel-lpe-cves 036 Linux Local Network and Socket Triage network-information 037 Linux Logstash Privilege Escalation software-information 038 Linux lxd/lxc Group - Privilege escalation interesting-groups-linux-pe 039 Linux Masked Paths protections 040 Linux Mount Namespace namespaces 041 Linux Namespaces namespaces 042 Linux Network Namespace namespaces 043 Linux NFS No Root Squash Misconfiguration Privilege Escalation interesting-files-permissions 044 Linux Node inspector/CEF debug abuse software-information 045 Linux nonewprivs protections 046 Linux PAM - Pluggable Authentication Modules software-information 047 Linux Payloads to execute processes-crontab-systemd-dbus 048 Linux PID Namespace namespaces 049 Linux POSIX CPU Timers TOCTOU race (CVE-2025-38352) kernel-lpe-cves 050 Linux Read-Only System Paths protections 051 Linux RunC Privilege Escalation containers-namespaces 052 Linux Runtime API And Daemon Exposure container-security 053 Linux Runtime Authorization Plugins container-security 054 Linux seccomp protections 055 Linux SELinux interesting-files-permissions 056 Linux SELinux protections 057 Linux Sensitive Host Mounts container-security 058 Linux Socket Command Injection network-information 059 Linux Splunk LPE and Persistence software-information 060 Linux SSH Agent Forwarding Exploitation user-information 061 Linux Sudo Command Abuse main-system-information 062 Linux SUID Shared Library and Linker Abuse interesting-files-permissions 063 Linux Time Namespace namespaces 064 Linux Trojanized System Daemons and Reverse Proxies linux-post-exploitation 065 Linux Useful Linux Commands linux-basics 066 Linux User Namespace namespaces 067 Linux UTS Namespace namespaces 068 Linux VMware Tools service discovery LPE (CWE-426) via regex-based binary discovery (CVE-2025-41244) kernel-lpe-cves 069 Linux Wildcards Spare Tricks interesting-files-permissions