> For the complete documentation index, see [llms.txt](https://heathen.gitbook.io/oscp+-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://heathen.gitbook.io/oscp+-notes/enumeration/services/ssh.md).

# SSH

## Manual

```bash
ssh IP -p 22
```

Header

```bash
nc -nv IP 22
```

## Nmap SSH Enumeration

**Scripts**

```bash
ls -lh /usr/share/nmap/scripts/ | grep ssh
```

```bash
nmap IP -p 22 -sV ssh-hostkey --script-args ssh_hostkey=full
```

```bash
nmap IP -p 22 -sV ssh-auth-methods --script-args="ssh.user=root"
```

## Netexec

```bash
netexec ssh 172.21.0.0 -u user -p password/passwordfile --no-bruteforce
```

```bash
netexec ssh 172.21.0.0 -u user -p password/passwordfile --no-bruteforce -x whoami
```

## Resources

[SSH Audit - GitHub](https://github.com/jtesta/ssh-audit)<br>
