A fully read-only, passive audit of a Linux workstation — 10 domains, 46 findings, mapped to the NIST Cybersecurity Framework.
A replayable recording of the evaluation — snapshot collection → ten domain audits → de-duplication → report. Press play, or scrub the progress bar to step through every command.
asciinema recording · generated from the real audit commands & findings
This workstation's posture is dominated by an un-firewalled, multi-product remote-access surface layered on poor secrets hygiene and unencrypted storage.
The host firewall is installed but disabled, while three independent remote-control products (RDP, TeamViewer, NoMachine) are simultaneously bound to the wildcard address — two of them running with root-level daemons and recoverable or world-readable credentials.
Live API keys, a bot token, and deployment credentials sit in world/group-readable plaintext files and have leaked into logs and session transcripts. The root partition and swap are unencrypted, so a single disk theft exposes everything at rest.
The interactive user holds lxd group membership (a well-known unprivileged→root vector), SUID core dumps are enabled, and a third-party remote-access suite contributes a large setuid/setgid surface.
34 stale packages, unattended-upgrades silently skipping the point-release suite, no kernel audit trail, no brute-force lockout, and no backup process — harder to detect an incident and potentially unrecoverable after one.
No malware, no reverse shells, no covert persistence (crontab, systemd timers, authorized_keys, and RC hooks all stock).
No secrets committed to any git repository. Core memory-protection controls (ASLR, dmesg_restrict,
mmap_min_addr, ptrace scope) correctly configured. Default/legacy accounts locked, root password locked.
Host firewall disabled — ufw installed but inactive; no nftables/iptables rules enforced. Every wildcard-bound listener is LAN-reachable (and internet-reachable if forwarded).
Remote Desktop exposed with recoverable credentials — RDP enabled on all interfaces, full control, password auth, plaintext-recoverable credentials, and a world-readable TLS private key.
World-readable credentials file — a .netrc (mode 0664) holds a live deployment password in plaintext.
TeamViewer unattended daemon running as root on the wildcard address, two releases out of date.
NoMachine NX server exposed, installed from an unverified source (no apt repo → no patch path), with a setuid/setgid service account.
SUID core dumps enabled (fs.suid_dumpable=2) piped into a world-writable crash dir.
Interactive user is a member of the lxd group — trivial unprivileged→root escalation.
No encryption at rest — root partition and swap are unencrypted (no LUKS full-disk encryption).
Multiple live, long-lived API keys and a bot token stored in plaintext environment/config files.
Secrets leaked into persistent logs and session transcripts (deployment token, bot token).
The 46 findings aren't independent problems — they compose into a short, reliable path from nothing to root and credential theft. This exploitability narrative maps each finding to a kill-chain stage so remediation can be prioritized by real risk. It is a thought experiment on the host's own findings — not an operational how-to.
watch it happen — scripted, anonymized red-team demo
C-01 (firewall off) + C-16 (mDNS broadcast) +
C-24 (dual-stack :: binds) mean the box
announces its three remote-control daemons to the LAN with no filtering. Discovery is a single scan pass.
suid_dumpable=2) + kernel pointer leak (kptr_restrict=1) → info-leak primitives that feed a kernel exploit.~/.netrc → live deployment credential.→ These extend the compromise beyond the host: connected cloud, chat, and email services fall via the stolen tokens.
C-18 (no auditd) + C-40 (default logging, no central collector)
→ no kernel audit trail and blind detection; privileged actions leave no record.
C-11 / C-12 (stale packages, unattended-upgrades skipping
the point-release suite) keep the host vulnerable for easy re-entry.
C-08 (no disk encryption) — physical theft or a full disk read exposes everything, including the plaintext secrets above. C-19 (no backups) — ransomware or a wipe is unrecoverable.
Reach RDP:3389 on the LAN — firewall off, no lockout, weak/recoverable credentials → interactive session as the user.
Abuse lxd group membership → mount the host filesystem → root (or, landing on TeamViewer's root daemon via CVE, already root).
Read .netrc / .env / logs → exfiltrate every token.
No auditd, no backups → silent, untraceable, unrecoverable.
The CRITICAL/HIGH findings form one short chain, not 46 items to triage independently. A handful of fixes collapse most of it at once:
Enable the default-deny firewall — kills all three access doors at the network layer.
Retire two of the three remote-control products.
Remove lxd group membership — kills the trivial root path.
Rotate the leaked credentials immediately.
Every finding is mapped to a NIST Cybersecurity Framework (CSF 2.0) Function and Category. The distribution below is itself a finding: Protect is over-weighted, while Detect, Respond, and Recover are nearly unrepresented.
Interpretation: the audit is almost entirely a Protect-function gap assessment (76% of findings). There is no incident-response (Respond) capability evidenced at all, and only a single Recover finding — meaning the organization's ability to detect, respond to, and recover from an incident lags well behind its prevention posture. A mature program would rebalance toward Detect (audit logging, monitoring) and Recover (backups, tested restore).
| ID | Finding | Sev | Function | CSF Category |
|---|---|---|---|---|
| Govern (GV) — organizational context, risk strategy, supply chain | ||||
| C-04 | NoMachine installed from unverified source, setuid service account | HIGH | GV | GV.SC — Supply Chain Risk Mgmt |
| C-21 | Out-of-tree NVIDIA module taints the kernel | LOW | GV | GV.SC — Supply Chain Risk Mgmt |
| C-25 | Three overlapping remote-access products | INFO | GV | GV.RM — Risk Management Strategy |
| C-33 | sudo-rs setuid binaries in non-standard path | LOW | GV | GV.SC — Supply Chain Risk Mgmt |
| Identify (ID) — asset management, risk assessment | ||||
| C-35 | Orphaned files owned by a non-existent UID | LOW | ID | ID.AM — Asset Management |
| C-43 | Persistent agent gateway service (outbound) | INFO | ID | ID.AM — Asset Management |
| C-46 | Kernel CVE status (report-only) | INFO | ID | ID.RA — Risk Assessment |
| Protect (PR) — identity/access, data security, platform security, resilience | ||||
| C-01 | Host firewall disabled | CRIT | PR | PR.IR — Technology Infrastructure Resilience |
| C-02 | Remote Desktop exposed, recoverable credentials, world-readable key | CRIT | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-03 | TeamViewer root daemon, outdated | HIGH | PR | PR.PS — Platform Security |
| C-05 | World-readable .netrc with plaintext credential | CRIT | PR | PR.DS — Data Security |
| C-06 | SUID core dumps enabled | HIGH | PR | PR.PS — Platform Security |
| C-07 | User in lxd group (privilege escalation) | HIGH | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-08 | No encryption at rest | HIGH | PR | PR.DS — Data Security |
| C-09 | Live API keys in plaintext env/config files | HIGH | PR | PR.DS — Data Security |
| C-10 | Secrets leaked into logs/transcripts | HIGH | PR | PR.DS — Data Security |
| C-11 | 34 stale packages | MED | PR | PR.PS — Platform Security |
| C-12 | unattended-upgrades skips point-release suite | MED | PR | PR.PS — Platform Security |
| C-13 | No brute-force lockout / fail2ban | MED | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-14 | Weak password policy (no expiry, no complexity) | MED | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-15 | Default umask 0002 | MED | PR | PR.DS — Data Security |
| C-16 | mDNS/DNS-SD broadcast on LAN | MED | PR | PR.PS — Platform Security |
| C-17 | World-readable config backup with secrets | MED | PR | PR.DS — Data Security |
| C-20 | kernel.kptr_restrict=1 (should be 2) | MED | PR | PR.PS — Platform Security |
| C-22 | Unprivileged user namespaces enabled | LOW | PR | PR.PS — Platform Security |
| C-23 | Kernel attack-surface locks at defaults | LOW | PR | PR.PS — Platform Security |
| C-24 | Services dual-stack IPv6 bound, no IPv6 firewall | LOW | PR | PR.IR — Technology Infrastructure Resilience |
| C-26 | OpenSSH server absent (positive) | INFO | PR | PR.IR — Technology Infrastructure Resilience |
| C-27 | Orphaned SSH host keys | LOW | PR | PR.PS — Platform Security |
| C-28 | SSH client GSSAPI enabled unconditionally | LOW | PR | PR.PS — Platform Security |
| C-29 | authorized_keys hygiene clean (positive) | INFO | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-30 | sssd enabled but unconfigured | INFO | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-31 | sudo delegation needs review | LOW | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-32 | Default/legacy accounts locked (positive) | INFO | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-34 | World-writable venv lock files | LOW | PR | PR.DS — Data Security |
| C-36 | World-readable agent database files | LOW | PR | PR.DS — Data Security |
| C-37 | Non-standard world-writable metrics dir | INFO | PR | PR.DS — Data Security |
| C-38 | Leftover removed-package configs | LOW | PR | PR.PS — Platform Security |
| C-41 | ComfyUI installed without auth (loopback-bound) | LOW | PR | PR.AA — Identity Mgmt, Auth & Access Control |
| C-42 | CUPS browsing active with dnssd | LOW | PR | PR.PS — Platform Security |
| C-44 | Shell RC files modified (benign PATH hook) | INFO | PR | PR.PS — Platform Security |
| C-45 | Plaintext proxy password in client config | LOW | PR | PR.DS — Data Security |
| Detect (DE) — continuous monitoring, adverse event analysis | ||||
| C-18 | auditd not installed (no kernel audit trail) | MED | DE | DE.CM — Continuous Monitoring |
| C-39 | World-readable files under /var/log | LOW | DE | DE.CM — Continuous Monitoring |
| C-40 | journald persistence relies on default | INFO | DE | DE.CM — Continuous Monitoring |
| Recover (RC) — recovery planning & execution | ||||
| C-19 | No backup process for user data | MED | RC | RC.RP — Recovery Planning |
| Respond (RS) — incident management & mitigation | ||||
| — | No findings map to the Respond function — no incident-response capability was evidenced on this host | — | RS | (gap) |
78 raw finding records across 10 domains, de-duplicated into the 46 canonical findings above.
Firewall off; RDP, TeamViewer, NoMachine bound to all interfaces; mDNS broadcast. 1 CRIT / 3 HIGH
ASLR/memory mitigations correct; SUID core dumps and kptr leak remain. 1 HIGH
lxd-group escalation path; weak password policy; no lockout. 2 HIGH
No SSH server (clean); RDP key world-readable; no rate-limiting. 1 HIGH
World-readable .netrc; NoMachine setuid surface; permissive umask. 2 HIGH
NoMachine without repo; outdated root daemons; 34 stale packages. 2 HIGH
Live keys in plaintext files; secrets in logs/transcripts. 1 CRIT / 3 HIGH
RDP credentials recoverable in plaintext; ComfyUI unauth (loopback). 1 CRIT / 4 HIGH
Clean — no malware, reverse shells, or covert persistence found.
No auditd, no backups, no disk encryption. 2 HIGH
≤ 30 min · no root
needs sudo/owner
planning / reimage
This assessment was read-only, passive, and localhost-only: no exploitation, no privilege-escalation attempts, no system modification, no network scanning of other hosts, and no use of elevated privileges. A collection harness snapshotted the machine into structured JSON; ten domain auditors (one per domain) produced the 78 raw findings, which were then consolidated to 46. Every finding is tagged with severity, confidence, remediation effort, and a CIS reference. The audit is re-runnable and framework-based — the same harness and domain decomposition can be applied to any Linux host.