Privilege Escalation

You can add privilege escalation while creating a credentialed scan if the scan uses the following authentication methods found in the Elevate Privileges With portion of the Settings tab for your selected Authentication Method.

Authentication Methods that Support Escalation Supported Escalation Methods

Arcon
certificate
CyberArk
Kerberos
password
public key
Thycotic Secret Server

.k5login
Cisco 'enable'
dzdo
pbrun
su
su+sudo
sudo

The tables below describe the additional credential options you must configure for privilege escalation.

Note: BeyondTrust's PowerBroker (pbrun) and Centrify's DirectAuthorize (dzdo) are proprietary root task delegation methods for Unix and Linux systems.

Tip: Scans run using su+sudo allow the user to scan with a non-privileged account and then switch to a user with sudo privileges on the remote host. This is important for locations where remote privileged login is prohibited.

Note: Scans run using sudo vs. the root user do not always return the same results because of the different environmental variables applied to the sudo user and other subtle differences. For more information, see: https://www.sudo.ws/docs/man/sudo.man/.