Create TUN interface (attacker, one-time setup)
Run once on your attack box to create the kernel tunnel interface.
Deploy and run the agent (target)
Drop the agent binary on the compromised host and connect back to your proxy.
Select session and start tunnel (Ligolo console)
In the interactive Ligolo shell, select the connected session then start routing.