Post-Exploitation Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Post-Exploitation Techniques flashcards as text
Which Meterpreter command is used to dump password hashes from a compromised Windows system?
Answer: hashdump
The `hashdump` command in Meterpreter extracts NTLM password hashes from the SAM database on Windows systems.
What is the primary purpose of pivoting in a post-exploitation scenario?
Answer: Using a compromised host to attack other internal network segments
Pivoting uses a compromised machine as a relay to reach and attack otherwise inaccessible internal network segments.
Which tool is commonly used to perform Pass-the-Hash attacks on Windows networks?
Answer: Mimikatz
Mimikatz can perform Pass-the-Hash by injecting NTLM hashes directly into authentication sessions without needing the plaintext password.
What does the Meterpreter command `run post/multi/recon/local_exploit_suggester` do?
Answer: Suggests local privilege escalation exploits based on system info
The local_exploit_suggester module analyzes the target's OS version and patch level to suggest applicable local privilege escalation exploits.
Which technique involves injecting malicious code into a legitimate running process to hide from defenders?
Answer: Process hollowing
Process hollowing replaces the memory of a legitimate process with malicious code, making detection harder since the process appears normal.
After gaining a Meterpreter shell, which command would you run first to check your current user context?
Answer: getuid
`getuid` returns the username and domain of the account running the Meterpreter session, confirming your current privilege level.
What is the purpose of running `getsystem` in a Meterpreter session?
Answer: Attempt to escalate privileges to SYSTEM level
`getsystem` attempts several techniques to elevate the current Meterpreter session to NT AUTHORITY\SYSTEM on Windows.