QuestionQ248

Attacks and Exploits

During an assessment, a penetration tester acquires an NTLM hash from a legacy Windows machine. Which of the following tools should the tester use to continue the attack?

  • A Responder
  • B Hydra
  • C BloodHound
  • D CrackMapExec
Explanation

CrackMapExec supports pass-the-hash authentication using an NTLM hash, including authentication to SMB services, which can enable authenticated enumeration and lateral movement without knowing the plaintext password.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!