Establishing Persistence Flashcards

(29 cards)

1
Q

Name two browser extension PenTesting tools

A

Neto and Tarnish

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does EPP stand for?

A

Endpoint protection platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does EDR stand for?

A

Endpoint detection and response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does NGAV stand for?

A

Next Generation Anti-Virus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does pwncat do?

A

simplifies tasks such as privilege escalation, file transfer and tunneling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does sshuttle do?

A

combines the features of a VPN and SSH.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do SMB Relay Attacks work?

A

attacker captures and relays a users NTML hash

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some famous SMB attacks?

A

WannaCry
Trickbot trojan
Emotet trojan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Is Kerberos authentication recommended for SMB

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SDP stands for?

A

Service Discovery Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

SSDP stands for?

A

Simple Service Discovery Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

MDNS stands for?

A

Multicast DNS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

LPD stands for?

A

Line Printer Daemon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

WMI stands for?

A

Windows Management Instrumentation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is WMI (Windows Management Instrumentation) used for?

A

To configure systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

WinRM stands for?

A

Windows Remote Management

17
Q

What is WinRM used for?

A

management protocol used by windows to communicate with servers remotely

18
Q

What protocol does WinRM use?

A

built on SOAP-based and communicate over HTTP/HTTPS

19
Q

What standard ports does WinRM use?

A

5985 for HTTP and 5986 for HTTPS

20
Q

What does this command do: winrm get winrm/config

A

show current config

21
Q

What does this command do: winrm quickconfigu

A

set up default configuration vales on a local machine

22
Q

What are LOLBins (Living of the Land Binaries)?

A

are binaries that use legitmate commands to execute malicious activities

23
Q

What is Covenant?

A

open-source C2 framework

24
Q

What is Covenant developed with?

25
Is Covenant CLI or Web-based?
Web-based
26
What is CrackMapExec(CME)?
Post-exploitation tool designed for pen testing in Windows
27
What can CrackMapExec enumerate?
Active Directory
28
What is Impact?
Collection of Python classes focused on low-level networking protocols
29
What is Mimikatz?
Password retrieval