TryHackMe rooms
- Linux Privilege Escalation: Enumeration
- Linux Privilege Escalation: Basics
- Stretch challenge: Jump
- Reporting reference or follow-on room: Writing Pentest Reports
Corresponding practice
- On the authorised room target, enumerate identity, groups, sudo rights, SUID files, capabilities, scheduled tasks, services, writable paths, and credentials.
- Rank possible escalation paths by evidence, required access, reliability, and impact before trying one.
- Attempt Jump independently for 60 minutes and preserve an ordered attack log.
- Write one report finding with title, severity rationale, affected asset, evidence, reproduction steps, impact, remediation, and retest guidance.
Evidence to capture
- Manual Linux enumeration checklist
- Escalation hypothesis table and root-session evidence from the room
- Cleanup notes and a concise client-facing finding
- Continuation queue for Windows privilege escalation, Active Directory, Python, reporting, and remaining capstones
What I learned
Summarise how the workflow changed from Day 1 and which techniques now feel reproducible.
Problems and dead ends
Document every escalation path that was rejected and the evidence behind that decision.
What I will revisit
Choose the first post-journal module and define a measurable next milestone.