CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium

A penetration tester has established a Meterpreter session on a Windows workstation. The tester wants to ensure continued access by creating a new local administrator account without leaving obvious traces in the event logs. Which Meterpreter post-exploitation module could best assist with this goal?

  1. Apost/windows/manage/hide_user
  2. Bpost/windows/manage/add_user
  3. Cpost/windows/manage/enable_rdp
  4. Dpost/windows/gather/enum_logged_on_users
Show answer & explanation

Correct answer: A. post/windows/manage/hide_user

The `post/windows/manage/hide_user` module in Meterpreter is designed to create a new user and then hide it from the Windows login screen and other common user enumeration methods, making it a stealthier persistence mechanism than simply adding a visible user.

Why the other options are wrong

  • B. This module adds a user, but it does not hide the user, making it easily detectable.
  • C. This module enables RDP but does not create or hide users.
  • D. This module enumerates logged-on users, it does not create or hide users.

Hidden Windows Local User

A persistence technique involving the creation of a new local user account that is then hidden from standard Windows user enumeration interfaces (e.g., login screen, Control Panel), making it less likely to be discovered.

  • Often achieved by modifying registry keys (e.g., `HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names`).
  • Requires administrator privileges to create and hide the account.
  • Meterpreter's `hide_user` module automates this process.

Memory trick: Hidden users keep access unseen.

More Post-exploitation and Lateral Movement questions