Linux (GTFOBins) & Windows (LOLBAS) Privilege Escalation Finder (2026)

Search 50+ GTFOBins SUID/Sudo/Capabilities binaries and Windows LOLBAS living-off-the-land executables alongside interactive post-exploitation enumeration checklists.

Linux (GTFOBins) & Windows (LOLBAS) Privilege Escalation Finder — Interactive Console
Runs locally in your browser • Instant output
Selected Vector: find (SUID)
Enumeration / Discovery Check
$ find / -perm -4000 -type f 2>/dev/null
Privilege Escalation Payload
$ find . -exec /bin/sh -p \; -quit
Defensive Remediation

sudo chmod u-s $(which find) && remove NOPASSWD sudoers entries for find

Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Linux (GTFOBins) & Windows (LOLBAS) Privilege Escalation Finder](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/linux-windows-privesc-checklist/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/linux-windows-privesc-checklist/">Linux (GTFOBins) & Windows (LOLBAS) Privilege Escalation Finder — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Linux (GTFOBins) & Windows (LOLBAS) Privilege Escalation Finder

Quick Answer & 2026 Technical Summary (privilege escalation checklist gtfobins lolbas)Updated 2026 Standard

Horizontal privilege escalation (lateral movement on the same host) occurs when a standard user accesses resources or shells belonging to another standard user account (e.g., moving from www-data to developer). Vertical privilege escalation elevates permissions from a low-privileged account to full administrative control (root on Linux or NT AUTHORITY\SYSTEM / Administrator on Windows). Use this interactive privilege escalation checklist gtfobins lolbas above to test gtfobins suid sudo lookup, lolbas windows binaries cheat sheet, and linux privilege escalation checklist locally in your browser with zero server uploads.

Target Keyword Spec: privilege escalation checklist gtfobins lolbas | Modules: Instant GTFOBins Binary Exploit Lookup • Windows LOLBAS & Token Abuse Explorer • Interactive Linux & Windows Audit Checklists
Primary Focus: privilege escalation checklist gtfobins lolbas
Core Capability: gtfobins suid sudo lookup
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Instant GTFOBins Binary Exploit Lookupgtfobins suid sudo lookupFilter Linux binaries (find, vim, python3, bash, tar, awk, env, perl, opens...Post-Exploitation Vertical Privilege Escalation
Windows LOLBAS & Token Abuse Explorerlolbas windows binaries cheat sheetLook up native Microsoft-signed binaries (certutil, bitsadmin, mshta, rundl...Windows Service & Token Misconfiguration Auditing
Interactive Linux & Windows Audit Checklistslinux privilege escalation checklistTrack post-foothold enumeration progress across Kernel CVEs, Cron wildcards...Endpoint Hardening & SUID/LOLBin Lockdown
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is a Privilege Escalation Attack? Vertical vs Horizontal PrivEsc

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Linux (GTFOBins) & Windows (LOLBAS) Privilege Escalation Finder

01

Select Target OS (Linux GTFOBins or Windows LOLBAS)

Switch between the Linux and Windows tabs or view both side-by-side to match your target environment.

02

Search by Binary Name or Escalation Vector

Type a binary discovered during enumeration (e.g., 'find', 'python', 'certutil', 'mshta') or filter by SUID, Sudo, Capabilities, or Download.

03

Copy the Exact Escalation One-Liner

Click any binary card to copy the exact command sequence needed to spawn a privileged shell or read restricted files.

04

Work Through the Interactive PrivEsc Checklist

Check off completed enumeration vectors (Cron jobs, PATH hijacking, Token privileges, Registry Autoruns) and copy the built-in discovery commands.

Key Capabilities & Technical Architecture

Instant GTFOBins Binary Exploit Lookup

Filter Linux binaries (find, vim, python3, bash, tar, awk, env, perl, openssl, systemctl) by SUID, Sudo, Capabilities, File Read, or Limited SUID breakout vectors.

Windows LOLBAS & Token Abuse Explorer

Look up native Microsoft-signed binaries (certutil, bitsadmin, mshta, rundll32, regsvr32, wmic, msiexec) for payload download, Alternate Data Streams (ADS), and AWL bypass.

Interactive Linux & Windows Audit Checklists

Track post-foothold enumeration progress across Kernel CVEs, Cron wildcards, Writable /etc/passwd, SeImpersonatePrivilege (Potato family), AlwaysInstallElevated, and Unquoted Service Paths.

One-Liner Automated Recon Script Generator

Copy exact find SUID/SGID, getcap -r, sudo -l, icacls, whoami /priv, and memory-resident LinPEAS/WinPEAS execution commands.

Practical Use Cases

Post-Exploitation Vertical Privilege Escalation

Paste the output concepts from `sudo -l` or `find / -perm -4000 2>/dev/null` to immediately identify which installed binary yields an elevated root shell.

Windows Service & Token Misconfiguration Auditing

Verify whether IIS/SQL service accounts holding `SeImpersonatePrivilege` or `SeBackupPrivilege` can escalate to `NT AUTHORITY\SYSTEM` via PrintSpoofer, GodPotato, or registry hive dumps.

Endpoint Hardening & SUID/LOLBin Lockdown

Audit container images and golden server templates to strip unnecessary SUID bits (`chmod u-s`) and enforce AppLocker/WDAC rules against abused LOLBAS utilities.

Frequently Asked Questions (FAQs)

What is the difference between Horizontal and Vertical Privilege Escalation?+

Horizontal privilege escalation (lateral movement on the same host) occurs when a standard user accesses resources or shells belonging to another standard user account (e.g., moving from www-data to developer). Vertical privilege escalation elevates permissions from a low-privileged account to full administrative control (root on Linux or NT AUTHORITY\SYSTEM / Administrator on Windows).

Why does bash drop privileges when a SUID binary executes unless the -p flag is used?+

When standard GNU Bash starts and detects that its Effective UID (EUID, set to 0 by the SUID bit) does not match its Real UID (RUID, the calling user), it automatically resets EUID back to RUID as a security precaution. Passing '/bin/bash -p' (privileged mode) instructs Bash to preserve the SUID root effective user ID.

How do Linux Capabilities (cap_setuid+ep) cause root privilege escalation without SUID?+

Linux Capabilities break root privileges into granular units. If an administrator grants 'cap_setuid+ep' to an interpreter like /usr/bin/python3 or /usr/bin/node (visible via 'getcap -r / 2>/dev/null'), that binary does not show an 's' in ls -l permissions, yet any user can call os.setuid(0) inside Python to spawn a root shell.

What is SeImpersonatePrivilege on Windows and why is it critical?+

SeImpersonatePrivilege ('Impersonate a client after authentication') is granted by default to local service accounts (LOCAL SERVICE, NETWORK SERVICE, IIS APPPOOL). Tools like PrintSpoofer, RoguePotato, and GodPotato coerce the Windows SYSTEM account to authenticate to a local named pipe or DCOM listener and then impersonate that SYSTEM token to execute arbitrary commands.

How does an Unquoted Windows Service Path vulnerability work?+

If a Windows service binary path contains spaces and is not wrapped in quotation marks (for example, C:\Program Files\Custom App\Service Engine\srv.exe), the Service Control Manager attempts to execute C:\Program.exe, then C:\Program Files\Custom.exe, and then C:\Program Files\Custom App\Service.exe in order. If a standard user has write permissions to any of those parent directories, placing a payload at that path executes it as SYSTEM on service restart.