1
Create TUN interface (attacker, one-time setup)
Run once on your attack box to create the kernel tunnel interface.
2
Start the proxy listener (attacker)
3
Deploy and run the agent (target)
Drop the agent binary on the compromised host and connect back to your proxy.
4
Select session and start tunnel (Ligolo console)
In the interactive Ligolo shell, select the connected session then start routing.
5
Add route for the internal subnet (attacker)
Route the target’s internal network through the ligolo interface so your tools reach it directly.