A penetration tester has successfully compromised a Windows machine and wants to perform lateral movement to another machine using captured NTLM hashes. Which tool would allow the tester to pass the hash and execute commands remotely?
Trap 1: John the Ripper
John the Ripper is a dedicated password/hash cracking tool that works offline against captured NTLM or Net-NTLMv2 hashes; it has no built-in capability to authenticate to a remote Windows host or execute commands on the target. While it can break weak passwords, it does not perform pass-the-hash attacks, which require substituting a hash as a credential in an active network authentication session.
Trap 2: Metasploit
Metasploit does contain modules such as exploit/windows/smb/psexec_psh that can authenticate with an NTLM hash, but it is a broad exploitation framework rather than a purpose-built lateral movement utility. Using it for pass-the-hash often requires session management, payload generation, and target-by-target invocation, whereas the attacker in this scenario simply needs to execute commands across multiple hosts quickly; CrackMapExec is more streamlined and is the go-to tool for this exact task.
Trap 3: pth-winexe
pth-winexe is a tool from the Samba suite that can indeed perform pass-the-hash operations by launching winexe to execute commands over SMB using an NTLM hash. However, it is less commonly used in modern penetration testing because it lacks the multi-host automation, protocol diversity (SMB/WMI/WinRM), and built-in post-exploitation helpers that CrackMapExec provides; pth-winexe is also older and not as actively maintained, making CME the more comprehensive and efficient choice for lateral movement.
- A
John the Ripper
Why it fails: John the Ripper is a dedicated password/hash cracking tool that works offline against captured NTLM or Net-NTLMv2 hashes; it has no built-in capability to authenticate to a remote Windows host or execute commands on the target. While it can break weak passwords, it does not perform pass-the-hash attacks, which require substituting a hash as a credential in an active network authentication session.
- B
Metasploit
Why it fails: Metasploit does contain modules such as exploit/windows/smb/psexec_psh that can authenticate with an NTLM hash, but it is a broad exploitation framework rather than a purpose-built lateral movement utility. Using it for pass-the-hash often requires session management, payload generation, and target-by-target invocation, whereas the attacker in this scenario simply needs to execute commands across multiple hosts quickly; CrackMapExec is more streamlined and is the go-to tool for this exact task.
- C
CrackMapExec
CrackMapExec (CME) is the correct choice because it natively supports pass-the-hash via the -H flag and can execute arbitrary commands over SMB, WMI, and WinRM without requiring a clear-text password. It also provides built-in features for enumerating shared resources, dumping SAM hashes, and testing credentials across an entire subnet, making it the standard utility for pentesters performing post-exploitation lateral movement after obtaining an NTLM hash from a compromised Windows host.
- D
pth-winexe
Why it fails: pth-winexe is a tool from the Samba suite that can indeed perform pass-the-hash operations by launching winexe to execute commands over SMB using an NTLM hash. However, it is less commonly used in modern penetration testing because it lacks the multi-host automation, protocol diversity (SMB/WMI/WinRM), and built-in post-exploitation helpers that CrackMapExec provides; pth-winexe is also older and not as actively maintained, making CME the more comprehensive and efficient choice for lateral movement.