Post-Exploitation Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Post-Exploitation Techniques flashcards as text
Which Metasploit module type is used for post-exploitation tasks after a session is established?
Answer: Post
Post modules in Metasploit are designed to run against existing sessions to gather information, escalate privileges, or maintain persistence.
What is credential harvesting in post-exploitation?
Answer: Collecting usernames, passwords, and hashes from a compromised system
Credential harvesting involves extracting stored credentials—such as passwords, hashes, and tokens—from memory, files, or the registry of a compromised system.
Which Windows registry hive stores user account password hashes locally?
Answer: HKEY_LOCAL_MACHINE\SAM
The SAM (Security Account Manager) hive under HKEY_LOCAL_MACHINE stores NTLM hashes for local Windows user accounts.
What is lateral movement in the context of post-exploitation?
Answer: Moving from one compromised system to other systems in the same network
Lateral movement refers to techniques attackers use to progressively move through a network, compromising additional systems using harvested credentials or exploits.
Which Meterpreter command allows you to search for files on the target system?
Answer: search
The `search` command in Meterpreter lets you search for files by name or pattern across the target filesystem, useful for finding sensitive data.
What is the main advantage of using a bind shell over a reverse shell in some scenarios?
Answer: It works when the attacker cannot receive inbound connections from the target
A bind shell opens a port on the target that the attacker connects to, which is useful when the attacker's IP is behind NAT or a firewall blocking inbound connections.
Which technique is used to maintain persistence on a Windows system by adding entries to the registry Run keys?
Answer: Registry persistence
Adding malicious executables to HKCU or HKLM Run keys causes them to execute automatically each time the system starts or a user logs in.