Optional Features
Privilege Escalation
Privilege Escalation can be configured to work with the ARCON integration within the SSH credential type. You can add privilege escalation while configuring an SSH credentialed scan with the ARCON integration using the Elevate Privileges with field option, which lets you select the privilege account type used for privileged access to the target machine.
Here is a list of the privilege account types for selections:
-
Nothing (This is the default option)
-
.k5login
-
Cisco 'enable'
-
Dzdo
-
Pbrun
-
Su
-
su+sudo
-
sudo
-
Checkpoint Gaia 'expert'
Each escalation account type above can be further configured with a combination of credential options detailed in the following table.
| Option | Description | Required |
|---|---|---|
| Escalation Username | The username within ARCON that contains the Escalation account secret. Configurable within: .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo, Checkpoint Gaia 'expert'. | Yes |
| Escalation Account Name | The username for the account with elevated privileges (the account to escalate to). Configurable within: .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo, Checkpoint Gaia 'expert'. | Yes |
| Location of [account type] (directory) | The directory path for the [account type] command. Configurable within: dzdo, pbrun, su, su+sudo, sudo. | No |