PT0-003 · Question #91
During an assessment, a penetration tester obtains an NTLM hash from a legacy Windows machine. Which of the following tools should the penetration tester use to continue the attack?
The correct answer is D. CrackMapExec. CrackMapExec (CME) is a post-exploitation tool commonly used for lateral movement, credential validation, and network enumeration in Windows environments. It supports using NTLM hashes to authenticate (pass-the-hash) across systems, making it ideal for continuing an attack with a
Question
During an assessment, a penetration tester obtains an NTLM hash from a legacy Windows machine. Which of the following tools should the penetration tester use to continue the attack?
Options
- AResponder
- BHydra
- CBloodHound
- DCrackMapExec
How the community answered
(24 responses)- A8% (2)
- B13% (3)
- C4% (1)
- D75% (18)
Explanation
CrackMapExec (CME) is a post-exploitation tool commonly used for lateral movement, credential validation, and network enumeration in Windows environments. It supports using NTLM hashes to authenticate (pass-the-hash) across systems, making it ideal for continuing an attack with a
Topics
Community Discussion
No community discussion yet for this question.