GPEN › Password Attacks and Formats
This GPEN domain covers how credentials are stored, captured, and cracked during penetration tests. You must recognize hash formats, understand salting and cleartext exposure risks, and select appropriate tools such as Hashcat, John the Ripper, and Mimikatz to recover or reuse credentials.
GPEN Password Attacks and Formats — All 27 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning