GPEN › Advanced Password Attacks
This domain covers credential theft and cracking on Windows/AD networks: LLMNR/NBT-NS poisoning to capture Net-NTLMv2, Kerberos pre-auth attacks (AS-REP roasting, Kerberoasting), and offline hash recovery with Hashcat/John. GPEN tests your ability to choose the right capture technique, hash mode, and post-capture step under time pressure.
GPEN Advanced Password Attacks — All 35 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Pen Test Planning