Chains
TTPs
Blog
Login
Prelude chain browser
Baron Samedit (Spawn Agent)
Identify the sudo binary version on the local system, compare it against the last known vulnerable version of Sudo for CVE-2021-3156, then spawn an elevated Pneuma agent.
2021-08-10
Professional
This is a professional attack chain. A professional subscription automatically gives you access to this chain + 50 more, with direct integration inside of Operator.
Authors:
khyberspache, worawit wangwarunyoo
Execute this chain
Download Operator (1.7.1)
Learn about Operator
TTPs
Identify sudo binary version
Compare software versions for exploitation
Spawn elevated pneuma via CVE-2021-3156
Tactics
Discovery
Privilege-escalation
User-Set Custom Variables
exploitable.version: 1.9.5p1