Pivoting and Lateral Movement Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Pivoting and Lateral Movement flashcards as text
What technique does 'Pass-the-Hash' exploit to authenticate to Windows services without knowing the plaintext password?
Answer: Using the captured NTLM hash directly for authentication
Pass-the-Hash abuses NTLM's challenge-response protocol by supplying the captured hash directly, since NTLM does not require the plaintext password.
Which tool is commonly used for Pass-the-Hash attacks to get a shell on a remote Windows machine over SMB?
Answer: pth-winexe
pth-winexe is a modified version of winexe that accepts NTLM hashes directly, enabling remote command execution over SMB without a plaintext password.
During lateral movement, a pentester discovers a Windows service account password hash. To move laterally using WMI, which Impacket script is most appropriate?
Answer: wmiexec.py
Impacket's wmiexec.py executes commands on remote Windows hosts via WMI, a stealthier alternative to psexec that doesn't drop a service binary.
What network protocol does PsExec primarily use to move laterally between Windows hosts?
Answer: SMB (port 445)
PsExec creates a service on the target by uploading an executable over SMB's admin share (ADMIN$), then starts it remotely.
Which Metasploit module can dump password hashes from a compromised Windows host to facilitate lateral movement?
Answer: post/windows/gather/hashdump
The hashdump post module extracts NTLM password hashes from a Windows host's SAM database, which can then be used for Pass-the-Hash attacks.
A pentester has valid credentials for a Windows domain account. Which technique allows them to execute commands on a remote Windows host using those credentials without a pre-existing shell?
Answer: PsExec lateral movement via SMB
PsExec-style lateral movement uses valid credentials to authenticate over SMB, upload a service binary, and execute commands on the remote host.
When enumerating a newly reached internal subnet through a pivot, which Metasploit scanner quickly identifies live hosts?
Answer: auxiliary/scanner/discovery/udp_sweep
The udp_sweep scanner sends UDP packets to identify live hosts on a subnet, useful for quick discovery when routed through a pivot.