For una herramienta de enumeración para escalada de privilegios, the strongest matches are carlospolop/privilege-escalation-awesome-scripts-suite (This is the well-known PEASS suite linPEAS and winPEAS), ghostpack/sharpup (SharpUp is a Windows-focused privilege escalation auditing tool ported) and peass-ng/peass-ng (PEASS-ng systematically scans Linux and Windows systems for privilege). rebootuser/linenum and diego-treitos/linux-smart-enumeration round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Estas herramientas identifican configuraciones de seguridad erróneas y vulnerabilidades para automatizar pruebas de escalada de privilegios en Linux y Windows.
This project is a post-exploitation framework and privilege escalation script suite designed to scan local system configurations for security gaps. It serves as a system enumeration toolset used to identify paths for gaining higher administrative privileges on a target host. The suite incorporates capabilities for security penetration testing and vulnerability assessment reporting. It uses shell-based system enumeration and pattern-based vulnerability matching to detect misconfigurations, while employing heuristic-based permission analysis to evaluate system flags. Findings are gathered thro
This is the well-known PEASS suite (linPEAS and winPEAS), a comprehensive cross-platform privilege escalation auditing tool that automates checks for misconfigurations and common escalation vectors, exactly matching your search.
SharpUp is a C# port of various PowerUp functionality. Currently, only the most common checks have been ported; no weaponization functions have yet been implemented.
SharpUp is a Windows-focused privilege escalation auditing tool ported from PowerUp, so it fits the category but currently only scans Windows, not Linux—it covers common checks but lacks the cross‑platform coverage you need.
PEASS-ng is an automated penetration testing framework designed to identify privilege escalation vectors on local systems. It functions as a security assessment utility that scans environments for misconfigurations, sensitive files, and insecure permissions to uncover paths for unauthorized privilege elevation. The project distinguishes itself through a modular script-based enumeration engine that adapts to the target environment. It utilizes environment-aware capability detection and cross-platform shell abstraction to normalize data collection across diverse operating systems, while operati
PEASS-ng systematically scans Linux and Windows systems for privilege escalation vectors, misconfigurations, and weak permissions, making it exactly the kind of automated cross-platform auditing tool you're looking for.
LinEnum is a suite of security utilities for auditing Linux systems, scanning for privilege escalation paths, and enumerating local vulnerabilities. It functions as a system security audit tool, a local enumeration utility, and a scanner for identifying misconfigurations that could allow a user to gain root access. The project includes specialized auditing for containerized environments, specifically detecting Docker and LXC signatures to identify potential escape vectors to the host system. Its broader capabilities cover the analysis of kernel versions, the identification of SUID binaries a
LinEnum is a dedicated Linux privilege escalation auditing tool that covers enumeration, container escape detection, and misconfiguration scanning, but it does not support Windows systems, so it only partially satisfies the cross-platform requirement.
This project is a comprehensive toolkit for Linux security auditing and system enumeration. It functions as a framework for identifying configuration weaknesses, gathering system information, and detecting vulnerabilities to assist in gaining higher administrative access levels on Linux systems. The toolkit includes specialized capabilities for version-based vulnerability scanning, which matches installed software against known affected releases, and time-window process monitoring to track recurring system patterns and periodic tasks. It also provides infrastructure for hosting and delivering
This Linux enumeration tool specializes in privilege escalation detection, making it exactly the right category for automated privesc auditing, but it only covers Linux and lacks Windows support, so it only partially meets the cross-platform requirement.
BeRoot(s) is a post exploitation tool to check common Windows misconfigurations to find a way to escalate our privilege. \ A compiled version is available here.
BeRoot is a post-exploitation tool that checks Windows systems for common privilege escalation misconfigurations, but it lacks Linux support, making it a narrower fit for your cross-platform requirement.
Next-Generation Linux Kernel Exploit Suggester
This repository is a Linux-specific kernel exploit suggester that automates the search for known privilege escalation vulnerabilities, so it fits the core auditing need but lacks the cross-platform Windows support and broader misconfiguration checks you asked for.
linuxprivchecker.py -- a Linux Privilege Escalation Check Script
This is a dedicated Linux privilege escalation auditing script, so it squarely fits the category for Linux systems but does not cover Windows as your cross-platform requirement demands.
Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities
Watson is a Windows-only tool that checks for missing patches linked to privilege escalation vulnerabilities and suggests exploits, fitting the category but lacking the requested Linux coverage and broader misconfiguration scanning.
Windows-privesc-check is an automated security auditing tool designed to identify misconfigurations and vulnerabilities that may allow for unauthorized privilege escalation on Windows systems. It functions by scanning local system configurations, including file system permissions, registry settings, and service configurations, to detect security weaknesses that could lead to elevated administrative access. The tool distinguishes itself by providing both local auditing and remote assessment capabilities. It can query remote Windows hosts to enumerate network shares, user accounts, and domain t
This tool is a dedicated Windows privilege escalation checker, which fits your need for an automated auditing tool, but it does not cover Linux systems as your cross-platform requirement specifies.
PEASS-ng is a Linux privilege escalation scanner and post-exploitation enumeration tool. It identifies security vulnerabilities and misconfigurations on Linux systems that could lead to unauthorized elevated access. The tool functions as a security audit utility that discovers system weaknesses and sensitive information after initial access is gained. It scans operating systems to identify specific privilege escalation paths. Findings are converted into structured security audit reports. The tool supports exporting scan results into JSON, HTML, and PDF formats for formal analysis and documen
PEASS-ng is a dedicated Linux privilege escalation scanner that automates security checks and generates structured reports, fitting the core need, but it does not cover Windows systems as your cross-platform requirement specifies.
| Repositorio | Estrellas | Lenguaje | Licencia | Último push |
|---|---|---|---|---|
| carlospolop/privilege-escalation-awesome-scripts-suite | 20K | C# | NOASSERTION | |
| ghostpack/sharpup | 1.5K | C# | NOASSERTION | |
| peass-ng/peass-ng | 19.3K | C# | other | |
| rebootuser/linenum | 7.8K | Shell | mit | |
| diego-treitos/linux-smart-enumeration | 3.9K | Shell | GPL-3.0 | |
| alessandroz/beroot | 2.6K | Python | LGPL-3.0 | |
| jondonas/linux-exploit-suggester-2 | 2K | Perl | GPL-2.0 | |
| sleventyeleven/linuxprivchecker | 1.8K | Python | MIT | |
| rasta-mouse/watson | 1.7K | C# | GPL-3.0 | |
| pentestmonkey/windows-privesc-check | 1.5K | Python | — |