Self-hosted service
Ignitetechnologies/Privilege-Escalation avatar
Ignitetechnologies/Privilege-Escalation

Ignitetechnologies/Privilege-Escalation: a CTF cheat sheet with one markdown file per technique

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

3,640 stars642 forksUnknownLicense varies

At a glance

What is it?
The repository is a set of markdown notes that map Linux privilege escalation techniques to specific VulnHub machines and the binaries each one abuses. It is study material for CTF players and OSCP candidates, not tooling, and it has no install step, no licence file and no release history.
Who is it for?
Adopt it as a reading list if you are working through CTF boxes or OSCP-style labs and want a technique index that points back to writeups. Do not adopt it if you need a runnable enumeration tool, a maintained script collection, or anything with a stated licence; the repository has no LICENSE file, no releases, and its last push was on 2026-03-14.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Activity is slowing. The repository last received commits 6 months ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the Privilege-Escalation repository actually is

This is a cheat sheet, and the README says so in its own words: a "practical Privilege Escalation cheat sheet and reference guide designed for CTF players, penetration testers, and cybersecurity learners." That framing matters, because the repository contains no scripts, no Makefile, no package manifest and no exploit code. It is 22 markdown files plus the README, each named after a technique: "Abusing Sudo Rights.md", "SUID Bit.md", "Kernel Exploit.md", "Path Variable.md", "Cronjob" (stored as "Crontab.md"), "Wildcard Injection.md", "Capabilities.md", "Writable etc passwd file.md", "Writable files or script as root.md", "Buffer Overflow.md", "Docker.md", "Chkrootkit.md", "Bruteforce.md", "Cracking etc shadow.md", "NFS.md", "Json.md", "Redis.md", "LXD.md", "Exim.md", "Apache2 Writable.md", "Enumeration.md" and "All.md".

The intended reader is someone who already has a shell on a lab machine and is deciding what to check next. The README's table of contents links to anchors such as #sudo, #suid, #kernel and #capabilities, and the top of the README also carries links to the author's Telegram, Twitter/X, Discord and LinkedIn accounts plus a paid training program form. That commercial framing is worth noting up front: this is a marketing-adjacent study aid published by HackingArticles, not a community-maintained reference with an issue tracker full of corrections.

How the sudo table maps machines to abusable binaries

The largest concrete structure in the README is the "Abusing Sudo Rights" table, and it is a good illustration of how the whole repository is organised. Each row pairs a VulnHub machine with the binary or file that the walkthrough abuses on that machine. Row 1 is Ted:1 with apt-get. Row 2 is KFIOFan:1 with awk. Rows 3 and 4 are 21 LTR: Scene1 and Skytower, both with cat. Rows 5 and 6 are Matrix:1 with cp and Sputnik 1 with ed. Further down: DC-2 with git, symfonos:2 with MySQL, DC6 and SP ike with nmap, Wakanda:1 with pip, Zico 2 and HA: Dhanush with zip, vim on Serial: 1, wine on Sunset-Sunrise, dpkg on Symfonos:5, Five86:2 and DevRandom CTF:1.1, and gcc on nyx:1. A few rows list "script", "All" or "Diffrent for every user" instead of a single binary.

That structure is the useful part. It is not a taxonomy of privilege escalation in the abstract; it is an index from a technique to a worked example you can go read. If you want to know what sudo rights on tcpdump lead to, the table points you at Breach 2.1, Temple of Doom and Web Developer: 1. The weakness is equally clear. The table is flat, it carries no date column, and the binary names are not normalised ("MySQL" and "mysql", " service " with stray spaces). Nothing in the README states when a row was added or whether the linked walkthrough still reflects a current distribution. The table also mixes categories: apt-get, dpkg and pip are package managers, while tcpdump, strace and nmap are diagnostic tools, and the abuse pattern for each group differs enough that a reader cannot generalise from one row to the next.

Reading the notes and making a first real use of them

There is nothing to install. The repository is documentation, so the README gives no install command, no package name, no port and no environment variable. The only acquisition step is getting the files onto your machine, and the only "first use" is opening the file that matches what you are looking at on your target.

The README's table of contents is the entry point. It links to anchors such as #sudo for Abusing Sudo Rights, #suid for SUID Bit, #kernel for Kernel Exploit and #capabilities for Capabilities, so you can jump straight to the technique you need rather than scrolling the machine table. The README also links each listed machine to its HackingArticles walkthrough, for example Ted:1, KFIOFan:1, 21 LTR: Scene1, Skytower, Matrix:1, Sputnik 1, DC-2, symfonos:2, DC6, SP ike, Wakanda:1, Zico 2, HA: Dhanush, Serial: 1, Sunset-Sunrise, Symfonos:5, Five86:2, DevRandom CTF:1.1 and nyx:1. Those links are where the command sequences live.

What you should expect from the topic files is prose and commands tied to named walkthroughs, not a script you can pipe into a shell. If a file names a binary you do not recognise, the repository does not explain what that binary does in general terms; it assumes you will read the linked walkthrough. Treat each file as a set of leads to verify on your own target.

Where the cheat sheet stops being useful

The repository has no LICENSE file. That is the first practical limitation and it is not a small one: without a licence, the default position is that the author retains all rights, so copying the notes into internal training material or a paid course is not something the repository grants you permission to do. The README does not discuss licensing at all, and there is no releases page, so there is no versioned artefact to pin.

Maintenance is the second limitation. The last push was on 2026-03-14, which is recent enough that the repository is not abandoned, but there is no changelog and no release, so a push tells you nothing about which technique files changed. Kernel exploit content ages fastest of all: the "Kernel Exploit.md" file cannot tell you whether a given kernel CVE applies to the build in front of you, and the README offers no guidance on that.

The third limitation is scope. The README's framing is Linux privilege escalation on CTF and VulnHub machines. If your problem is Windows token abuse, Active Directory escalation, or Kubernetes and Ansible privilege contexts, this is the wrong reference; the topic list has no Windows file and no cloud or container-orchestration file beyond Docker and LXD. The repository also assumes you already have a foothold. It is not a scanning or exploitation framework, and it will not enumerate a host for you.

Compared with GTFOBins and PEASS-ng

The obvious alternative for the sudo and SUID material is GTFOBins, a website that catalogues Unix binaries and the ways each can be abused when you have sudo rights, a SUID bit, or a capability. The difference in approach is that GTFOBins is organised by binary and kept as a single reference site, whereas this repository is organised by machine and technique, with each entry pointing at a HackingArticles walkthrough. If you know the binary name and want the abuse method, GTFOBins is the faster lookup. If you want to see the technique inside a full box walkthrough, the mapping table here is the thing GTFOBins does not give you.

For the enumeration step, PEASS-ng (LinPEAS and WinPEAS) is the other real alternative, and it is a different category of tool entirely: it is a script you run on the target that reports findings. This repository is text you read on your own machine. Neither replaces the other, and the README does not mention either project.

Frequently asked questions about the Privilege-Escalation cheat sheet

The repository answers a narrow set of questions well and leaves the rest to its linked walkthroughs. It is strongest on the mechanics of a specific technique once you already know which one you are facing, and weakest on anything that requires a decision about your own environment, such as whether a kernel exploit you read about is safe to run on a production-adjacent host. The README's own framing is the honest guide here: it is aimed at CTF players and beginners, and the machine names in the table are all lab machines.

If you are looking for a definition of privilege escalation, a list of its types, or advice on defending against it, this is not the repository for that. The files are offensive in orientation and assume an authorised test or a lab. Use the index to find the technique, then read the linked walkthrough before you run anything.

Editorial conclusion

Adopt it as a reading list if you are working through CTF boxes or OSCP-style labs and want a technique index that points back to writeups. Do not adopt it if you need a runnable enumeration tool, a maintained script collection, or anything with a stated licence; the repository has no LICENSE file, no releases, and its last push was on 2026-03-14. Before relying on any file, open the one that matches the technique you are studying, confirm the commands it gives are still valid on your target distribution, and check whether the linked machine is still downloadable from VulnHub.

Frequently asked questions

What is meant by privilege escalation in the context of this repository?

The README describes the project as a cheat sheet for understanding how attackers escalate privileges on compromised systems, aimed at CTF players, penetration testers and cybersecurity learners. Every topic file covers one technique for going from a lower-privileged foothold to a higher-privileged one on a lab machine.

What are the two types of privilege escalation?

The repository does not define a two-type taxonomy. Its README indexes techniques instead, listing entries such as Abusing Sudo Rights, SUID Bit, Kernel Exploit, Path Variable, Cronjob, Wildcard Injection, Capabilities, NFS, Docker and LXD, each in its own markdown file.

Can you give me an example of a privilege escalation attack from this project?

The README's Abusing Sudo Rights table pairs a machine with the binary abused on it, for example Ted:1 with apt-get, KFIOFan:1 with awk, DC-2 with git, symfonos:2 with MySQL, and nyx:1 with gcc. Each row links to a HackingArticles walkthrough for that machine.

Is the Privilege-Escalation repository a vulnerability or a tool?

It is neither. It is a documentation repository containing 22 markdown files plus a README, with no scripts, no package manifest and no releases. The README calls it a cheat sheet and reference guide.

How do you stop a privilege escalation attack?

The repository does not cover defence or hardening. Its files are offensive in orientation and assume an authorised test or a lab, so any remediation guidance has to come from elsewhere.

Official sources

  1. Ignitetechnologies/Privilege-Escalation on GitHub
  2. Issues
  3. Project website
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/ignitetechnologies-privilege-escalation.svg)](https://hysenlabs.com/projects/ignitetechnologies-privilege-escalation)