โ† All EJPT Flashcard Decks

Post-Exploitation Techniques Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Post-Exploitation Techniques flashcards as text
  1. What does token impersonation allow an attacker to do in a Windows post-exploitation context?

    Answer: Assume the identity and privileges of another logged-in user

    Token impersonation lets an attacker steal an access token from a higher-privileged process and use it to act as that user, gaining their permissions.

  2. Which Meterpreter command is used to migrate to another running process?

    Answer: migrate

    The `migrate` command moves the Meterpreter session into another running process, which can provide stability or elevated privileges if the target process runs as SYSTEM.

  3. What is the NTDS.dit file and why is it targeted in post-exploitation?

    Answer: The Active Directory database containing all domain user hashes

    NTDS.dit is the Active Directory database on a Domain Controller that contains password hashes for all domain accounts, making it a high-value target.

  4. Which command in a Windows shell would an attacker use to add a new local administrator account for persistence?

    Answer: net user /add hacker Pass123! && net localgroup administrators hacker /add

    The `net user /add` command creates a new account, and `net localgroup administrators /add` grants it local administrator privileges for persistent access.

  5. What is the purpose of clearing Windows event logs during post-exploitation?

    Answer: To remove evidence of attacker activity and avoid detection

    Clearing event logs removes records of attacker activity such as failed logins, process creation, and privilege escalation, helping evade forensic investigation.

  6. Which Metasploit post module can be used to gather comprehensive system information on a Windows target?

    Answer: post/windows/gather/enum_system

    The `post/windows/gather/enum_system` module collects detailed information about the Windows target including OS version, installed patches, and running services.

  7. What is a scheduled task in Windows and how can it be abused for persistence?

    Answer: An automated job that can be configured to run malicious executables at set times or events

    Windows scheduled tasks (via `schtasks`) can be created or modified by attackers to execute malware at boot, login, or regular intervals for persistence.