CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has established a Meterpreter session on a Windows workstation. The tester wants to ensure continued access by creating a new local administrator account without leaving obvious traces in the event logs. Which Meterpreter post-exploitation module could best assist with this goal?
- Apost/windows/manage/hide_user
- Bpost/windows/manage/add_user
- Cpost/windows/manage/enable_rdp
- Dpost/windows/gather/enum_logged_on_users
Show answer & explanationAnswer & explanation
Correct answer: A. post/windows/manage/hide_user
The `post/windows/manage/hide_user` module in Meterpreter is designed to create a new user and then hide it from the Windows login screen and other common user enumeration methods, making it a stealthier persistence mechanism than simply adding a visible user.
Why the other options are wrong
- B. This module adds a user, but it does not hide the user, making it easily detectable.
- C. This module enables RDP but does not create or hide users.
- D. This module enumerates logged-on users, it does not create or hide users.
Hidden Windows Local User
A persistence technique involving the creation of a new local user account that is then hidden from standard Windows user enumeration interfaces (e.g., login screen, Control Panel), making it less likely to be discovered.
- Often achieved by modifying registry keys (e.g., `HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names`).
- Requires administrator privileges to create and hide the account.
- Meterpreter's `hide_user` module automates this process.
Memory trick: Hidden users keep access unseen.