CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementEasy
A penetration tester has compromised an internal Windows server and established a Meterpreter session. The tester identifies that the server is part of an Active Directory domain. To facilitate lateral movement, the tester wants to obtain credentials from memory. Which Meterpreter command should the tester use for this purpose?
- Ahashdump
- Bmimikatz
- Cps
- Dgetsystem
Show answer & explanationAnswer & explanation
Correct answer: B. mimikatz
Mimikatz is a powerful tool integrated within Meterpreter that can extract plaintext passwords, NTLM hashes, and Kerberos tickets from memory, which is crucial for lateral movement in an Active Directory environment.
Why the other options are wrong
- A. `hashdump` extracts NTLM and LM hashes from the SAM database, not plaintext passwords or Kerberos tickets from memory.
- C. `ps` lists running processes, it does not extract credentials.
- D. `getsystem` attempts to escalate privileges to SYSTEM, not extract credentials.
Mimikatz for Credential Extraction
A post-exploitation tool primarily used to extract credentials (plaintext passwords, hashes, Kerberos tickets) from memory on Windows systems, crucial for lateral movement.
- Integrated into Metasploit's Meterpreter as a post-exploitation module.
- Targets the Local Security Authority Subsystem Service (LSASS) process.
- Requires elevated privileges (e.g., SYSTEM) to function effectively.
Memory trick: Mimikatz extracts keys from memory's maze.