<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Privilege-Escalation on Solvere Labs</title>
    <link>https://solvere.app/tags/privilege-escalation/</link>
    <description>Recent content in Privilege-Escalation on Solvere Labs</description>
    <language>en-us</language>
    <managingEditor>contact@solvere.app (Solvere Labs)</managingEditor>
    <webMaster>contact@solvere.app (Solvere Labs)</webMaster>
    <copyright>© 2026 Solvere Labs</copyright>
    <lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate>
    <image>
      <url>https://solvere.app/icon-512.png</url>
      <title>Solvere Labs</title>
      <link>https://solvere.app/tags/privilege-escalation/</link>
    </image><atom:link href="https://solvere.app/tags/privilege-escalation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Operation Promotion Walkthrough</title>
      <link>https://solvere.app/ctfs/thm/operation-promotion/</link>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
      <dc:creator>naval0505</dc:creator>
      <category>thm</category><category>web</category><category>command-injection</category><category>privilege-escalation</category><category>rce</category><category>reverse-shell</category><category>sqli</category><category>apache</category><category>enum4linux</category>
      <guid>https://solvere.app/ctfs/thm/operation-promotion/</guid>
      <description>You are up for promotion at Hadron Security. Your senior lead, Mara, has handed you a solo engagement against RecruitCorp, a small recruiting firm with a public-facing portal.</description>
    </item>
    
    <item>
      <title>WinPEAS</title>
      <link>https://solvere.app/tutorials/guides/winpeas/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      <dc:creator>Solvere Labs</dc:creator>
      <category>windows</category><category>privilege-escalation</category><category>enumeration</category><category>post-exploitation</category>
      <guid>https://solvere.app/tutorials/guides/winpeas/</guid>
      <description>A practical WinPEAS guide: get the Windows privilege-escalation enumerator onto a target, read its color-coded output, focus on the high-signal findings, and avoid drowning in noise.</description>
    </item>
    
    <item>
      <title>Pspy</title>
      <link>https://solvere.app/tutorials/guides/pspy/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      <dc:creator>Solvere Labs</dc:creator>
      <category>linux</category><category>privilege-escalation</category><category>enumeration</category><category>cron</category><category>post-exploitation</category>
      <guid>https://solvere.app/tutorials/guides/pspy/</guid>
      <description>The pspy quick reference: flags, a modular copy-paste cheat sheet, and a worked breakdown of every real situation. Transfer the static binary, watch processes and cron fire in real time without root, catch a UID=0 root timer, save and grep the feed for root commands, and turn a writable cron script into a privilege-escalation lead.</description>
    </item>
    
    <item>
      <title>PowerUp</title>
      <link>https://solvere.app/tutorials/guides/powerup/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      <dc:creator>Solvere Labs</dc:creator>
      <category>windows</category><category>privilege-escalation</category><category>enumeration</category><category>powershell</category><category>post-exploitation</category><category>unquoted-service-path</category>
      <guid>https://solvere.app/tutorials/guides/powerup/</guid>
      <description>A practical PowerUp guide: run the PowerSploit Windows privesc auditor, read its check output honestly, focus on the high-signal service and path findings, and keep it lab-safe.</description>
    </item>
    
    <item>
      <title>LinPEAS</title>
      <link>https://solvere.app/tutorials/guides/linpeas/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      <dc:creator>Solvere Labs</dc:creator>
      <category>linux</category><category>privilege-escalation</category><category>enumeration</category><category>linpeas</category><category>post-exploitation</category><category>sudo</category><category>suid</category>
      <guid>https://solvere.app/tutorials/guides/linpeas/</guid>
      <description>The LinPEAS quick reference: the flags that matter, a modular copy-paste cheat sheet, and a worked breakdown of every real situation. Deliver the script to a target, run and save a clean no-color report, tune the depth (stealth, all-checks, extra, regex), scope checks by group or MITRE technique, grep the high-signal findings, and read the color legend honestly.</description>
    </item>
    
    <item>
      <title>LinEnum</title>
      <link>https://solvere.app/tutorials/guides/linenum/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      <dc:creator>Solvere Labs</dc:creator>
      <category>linux</category><category>privilege-escalation</category><category>enumeration</category><category>bash</category><category>suid</category><category>sudo</category>
      <guid>https://solvere.app/tutorials/guides/linenum/</guid>
      <description>The LinEnum quick reference: flags, a modular copy-paste cheat sheet, and a worked breakdown of every real situation. Deliver the script to a foothold, run default vs thorough, hunt keywords, export files, write a report, and read the sudo, SUID/SGID, cron, and creds sections that matter.</description>
    </item>
    
    <item>
      <title>Mr Robot Walkthrough</title>
      <link>https://solvere.app/ctfs/vulnhub/mr-robot/</link>
      <pubDate>Fri, 24 Jan 2025 00:00:00 +0000</pubDate>
      <dc:creator>neospl0it</dc:creator>
      <category>vulnhub</category><category>reversing</category><category>web</category><category>brute-force</category><category>cron</category><category>gtfobins</category><category>password-cracking</category><category>privilege-escalation</category><category>reverse-shell</category>
      <guid>https://solvere.app/ctfs/vulnhub/mr-robot/</guid>
      <description>The Mr. Robot virtual machine (VM) is an exciting challenge inspired by the hit TV series Mr. Robot. It features three hidden keys, progressively increasing in difficulty.</description>
    </item>
    
    <item>
      <title>DriftingBlues 5 Walkthrough</title>
      <link>https://solvere.app/ctfs/vulnhub/driftingblues-5/</link>
      <pubDate>Thu, 12 Sep 2024 00:00:00 +0000</pubDate>
      <dc:creator>sagar-sehrawat</dc:creator>
      <category>vulnhub</category><category>wordpress</category><category>wpscan</category><category>ssh</category><category>brute-force</category><category>steganography</category><category>hash-cracking</category><category>cron</category><category>privilege-escalation</category>
      <guid>https://solvere.app/ctfs/vulnhub/driftingblues-5/</guid>
      <description>WordPress user enumeration via wpscan plus SSH brute-force gain a foothold, then a cracked KeePass database yields a filename that triggers a root cron job for root credentials.</description>
    </item>
    
    <item>
      <title>DriftingBlues 4 Walkthrough</title>
      <link>https://solvere.app/ctfs/vulnhub/driftingblues-4/</link>
      <pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate>
      <dc:creator>sagar-sehrawat</dc:creator>
      <category>vulnhub</category><category>linux</category><category>ftp</category><category>ssh</category><category>brute-force</category><category>suid</category><category>path-hijacking</category><category>privilege-escalation</category><category>linpeas</category>
      <guid>https://solvere.app/ctfs/vulnhub/driftingblues-4/</guid>
      <description>Layered web encoding (Base64/Brainfuck/QR) leaks usernames for FTP brute-force, an SSH key upload yields a shell, then a PATH-hijacked SUID binary gives root.</description>
    </item>
    
    <item>
      <title>DriftingBlues 2 Walkthrough</title>
      <link>https://solvere.app/ctfs/vulnhub/driftingblues-2/</link>
      <pubDate>Wed, 11 Sep 2024 00:00:00 +0000</pubDate>
      <dc:creator>sagar-sehrawat</dc:creator>
      <category>vulnhub</category><category>wordpress</category><category>wpscan</category><category>brute-force</category><category>reverse-shell</category><category>ssh</category><category>gtfobins</category><category>privilege-escalation</category><category>linux</category>
      <guid>https://solvere.app/ctfs/vulnhub/driftingblues-2/</guid>
      <description>A WordPress login brute-forced with wpscan plants a PHP reverse shell in a theme&#39;s 404.php, then passwordless sudo nmap escalates to root.</description>
    </item>
    
  </channel>
</rss>
