Optional Features

Privilege Escalation

Privilege Escalation can be configured to work with the Delinea Secret Server integration within the SSH credential type. You can add privilege escalation while configuring an SSH credentialed scan with the Delinea Secret Server integration using the Elevate Privileges with field option, which lets users select the privilege account type used for privileged access to the target machine.

The following privilege account types are available for selection:

  • Nothing (default)

  • .k5login

  • Cisco 'enable'

  • Dzdo

  • Pbrun

  • Su

  • su+sudo

  • sudo

  • Checkpoint Gaia 'expert'

You can configure each escalation account type above with a combination of the credential options detailed in the following table.

Option Description Required
Escalation Credential ID The secret name within Delinea Secret Server that contains the escalation account secret. Configurable within .k5login, Cisco 'enable', dzdo, pbrun, su, su+sudo, sudo, and Checkpoint Gaia 'expert'. Yes
su user (su+sudo only) The username for the account with elevated privileges. No
Escalation Account Name The username for the account with elevated privileges. Configurable within .k5login, Cisco 'enable', dzdo, pbrun, su, sudo, and Checkpoint Gaia 'expert'. Yes
Location of [account type] (directory) The directory path for the [account type] command. Configurable within dzdo, pbrun, su, su+sudo, and sudo. No