Linux
Linux TTPs
Table of Contents
System Enumeration / Post Exploitation (T1082)
Linux Miscellaneous Commands / Covering Tracks (T1070.003)
Efficient Linux CLI Navigation

Fork Bomb (T1499.002)
TCPDump (T1040)
One Liner to Add Persistence on a Box via Cron (T1053.003)
Systemd User Level Persistence (T1543.002)
Udev Rules Persistence (T1546)
Systemd Timer Persistence (T1053.006)
Backdooring Sudo (T1548.003)
ICMP Tunneling One Liner (T1572)
One Liner to Add Persistence on a Box via Sudoers File (T1548.003)
Find Server Strings from HTTP Responses (T1082)
Enumerating File Capabilities with Getcap (T1548.001)
Enumerating User Files for Interesting Information (T1552.001)
Finding World-Writable Files (T1083)
Search GitHub for Personal Access Tokens (T1552.001)
Search for OpenAI API Keys (T1552.001)
Search for Google API Keys (T1552.001)
Search for Slack Tokens (T1552.001)
Search for Hardcoded Passwords (T1552.001)
Search for Passwords in Memory and Core Dumps (T1003)
Searching Man Pages
Username Enumeration with Getent (T1087.001)
Utilize Crt.sh and EyeWitness to Enumerate Web Pages (T1596)
Nmap TTPs (T1046)
Nmap Scan Every Interface that is Assigned an IP (T1046)
Nmap IPv6 Nodes (T1046)
Nmap to Evaluate HTTPS Support (T1046)
Encrypt Files with Vim (T1027)
Testssl.sh (T1046)
Apache Flink Directory Traversal (T1083)
LD_PRELOAD Hijacking (T1574.006)
Bash Keylogger (T1056.001)
Strace Keylogger (T1056.001)
Netcat UDP Scanner (T1046)
Recon for Specific Device Before Enumerating (T1040)
TTL Fingerprinting (T1082)
Cisco IOS 11.2 - 12.2 Vulnerability (T1190)
FTP Through Non-Interactive Shell (T1071.002)
NetCat Listeners (T1095)
Python Reverse Shell (T1059.006)
Bash Reverse Shell (T1059.004)
Turn Nmap into a Vulnerability Scanner (T1595.002)
Nmap Privilege Escalation (T1548)
Nmap Using Multiple Scripts on One Target (T1046)
IDS/IPS Nmap Evasion (T1046)
Scanning Large Networks and Avoiding Sensitive IP Ranges (T1046)
Finding Open FTP Servers (T1046)
Scalable Heartbleed Hunting with Shodan (T1595.002)
Extract Passwords from HTTP POST Requests (T1040)
BPF'ing DNS Records (T1040)
Important Files (T1083)
Backdooring Systemd Services (T1543.002)
Old-Fashioned Log Cleaning (T1070.002)
ASLR Enumeration (T1082)
Reverse Shells (T1059)
Encrypted Reverse Shells with OpenSSL (T1573)
Bash (T1059.004)
PERL (T1059.006)
Python (T1059.006)
PHP (T1059.006)
Ruby (T1059.006)
Netcat (T1095)
Socat (T1095)
Java (T1059)
Password Harvesting (T1552)
Unusual Accounts (T1087.001)
Enumerating with Finger (T1087)
Enumerating with Traceroute (T1016)
Changing MAC Addresses (T1036.005)
Routers (T1018)
Metasploit Callback Automation (T1219)
Metasploit Resource Script Creation (T1219)
Metasploit Session Management (T1219)
Metasploit Tips I Discovered Too Late (T1219)
Confluence CVE-2022-26134 (T1190)
POP Syntax (T1071.003)
SSH Dynamic Port Forwarding (T1572)
Dominating Samba with pdbedit (T1087)
Encrypted File Transfers with Ncat (T1573)
Tsharking for Domain Users (T1040)
IP Information (T1016)
Cloning Websites for Social Engineering with Wget (T1189)
Spidering the Web with Wget (T1213)
Hiding PID Listings From Non-Root Users (T1564)
Exporting Objects with Tshark (T1040)
Rogue APs with Karmetasploit (T1557.002)
Passive Fingerprinting with P0f (T1040)
Advanced Mitm Attacks with Bettercap Filters (T1557)
Rust Reverse Shell (T1059)
Fake Sudo Program to Harvest Credentials (T1056)
TruffleHog GitHub Organizations (T1552.001)
Bypass File System Protections (Read-Only and No-Exec) for Containers (T1611)
Dumping Printer NVRAM (T1552)
Slash Proc Magic (T1564.001)
Linux Timestomping (T1070.006)
Linux Bash History Stomping (T1070.003)
Taking Apart URL Shorteners with cURL (T1082)
Email Spoofing PHP (T1566)
Linux SIEM Bypass (T1006)
Last updated