ALL PASS, NO FAIL!

CEH v13 Module 18: Lateral Movement

Lateral movement is the set of techniques attackers use to move through a network from an initial compromise to other systems. This module covers pass-the-hash (PtH), pass-the-ticket (PTT), remote service exploitation (SMB, RDP, SSH, WinRM), pivoting techniques, credential dumping, and Metasploit post-exploitation modules.

The CEHStudy app carries 13 flashcards for Module 18 across 3 sections — one heads-up: the app's Module 18 deck currently covers the paired IoT & OT domain, so read it as a companion to this page and drill lateral movement itself with the Module 18 practice questions.

Key Topics Covered

Important Terms & Concepts

Pass-the-Hash (PtH): Attacker captures NTLM hash and uses it to authenticate to remote services without knowing the plaintext password. Tools: Mimikatz, Impacket (psexec.py, smbexec.py).
Pass-the-Ticket (PTT): Attacker extracts Kerberos TGT (ticket-granting ticket) and uses it to authenticate without credentials. More advanced than PtH — works in pure Kerberos environments.
Pivoting: Using a compromised host as a jump point to reach otherwise inaccessible internal networks. Tools: Metasploit port forwards, ssh -L/-D, Chisel, Ligolo.
Mimikatz: Most widely known credential dumping tool. Extracts passwords, hashes, PINs, and Kerberos tickets from memory. Can perform PtH and PTT attacks.
Credential Dumping: Extracting credentials from memory (LSASS on Windows). Methods: lsass.exe injection, token manipulation, registry extraction of cached credentials.
WinRM (Windows Remote Management): Microsoft's implementation of WS-Management protocol. Commonly abused for lateral movement via PowerShell Invoke-Command and Impacket's winrm.py.

How to Study This Module

Frequently Asked Questions

What is lateral movement?
The process attackers use to move through a network from an initial compromise to other systems, escalating privileges and expanding access.

How do you prevent lateral movement?
Network segmentation, least privilege access, disable SMB/RDP where possible, LSA protection, Credential Guard, MFA, endpoint detection (EDR), and monitoring for anomalous authentication patterns.

Related Modules

What is Lateral Movement in Ethical Hacking?

Lateral Movement is a post-exploitation phase and a dedicated topic on the Certified Ethical Hacker v13 (CEH v13) exam. After initial access (phishing, web exploitation, or vulnerability exploitation), the attacker traverses the internal network to reach high-value targets: domain controllers, databases, executive workstations, sensitive file servers. It exploits the trust relationships built into enterprise networks — credentials (or their hashes/tickets) valid on one machine are likely valid on many more. On the CEH v13 exam, questions related to Module 18 account for approximately 7% of total questions.

Key Concepts in Lateral Movement

Common Exam Mistakes in Module 18

Mixing up Pass-the-Hash and Pass-the-Ticket: both skip normal authentication but live at different protocol layers. PtH authenticates directly with a stolen NTLM/NT hash — many SMB logons accept the hash itself, so a dumped value is as good as the password. PTT replays a stolen Kerberos ticket (TGT or TGS) from the ticket cache, authenticating to services until that ticket expires. Exam stems name the artifact (hash vs ticket); the artifact picks the layer.
Assuming credential dumping needs disk access: modern Windows protects the on-disk copies of secrets, so attackers read process memory instead — NTLM hashes and Kerberos tickets sit in LSASS, which is why sekurlsa::logonpasswords targets the live process. That same fact drives the defense: Credential Guard and LSA protection exist to keep that memory out of reach.
Underestimating what a golden ticket lasts: a forged TGT signed with the KRBTGT key is trusted by every KDC in the forest until that hash changes — so IR rotates the krbtgt account (twice, to invalidate tickets from the previous rotation) after any such compromise. Related stem: AS-REP roasting (Rubeus asreproast) needs no user password at all, only accounts with pre-authentication disabled.

Tools Used in Lateral Movement

Lateral movement tooling the CEH v13 exam references, by job:

Worked Example: One Shell, Then the Whole Domain, Hop by Hop

The attacker lands on a workstation with code execution. Mimikatz against LSASS dumps the user's NTLM hashes — no plaintext crosses the wire again. Authentication itself becomes the movement method: sekurlsa::pth (or Impacket's psexec.py) uses the NT hash directly to start a process on the next host; kerberos::ptt replays a captured TGT to open RDP or WinRM sessions across the tier. Each new host is both destination and launch point — SSH tunnels, SOCKS proxies, or Ligolo-ng chains turn the fleet into a relay reaching the segmented subnet where the file servers and domain controller sit.

The twist: every hop is also a detection opportunity, which is why the exam pairs the attack with its brakes. EDR flags Mimikatz's LSASS access almost universally; least-privilege and tiered administration (JEA) mean a workstation shell carries no domain-admin hash at all; segmentation stops the relay from reaching the core; monitoring for anomalous cross-host logons — one account authenticating to forty machines in an hour — turns slow lateral movement into an alert. If a golden ticket is found in play, krbtgt rotation is the incident's signature cleanup step.

How to Study Lateral Movement for the CEH v13 Exam

To effectively study Module 18 for the Certified Ethical Hacker exam:

  1. Create a comparison table: Attack Type (PtH vs PTT vs Golden Ticket) | What's Stolen (NTLM hash / TGT / krbtgt hash) | Protocol Required (NTLM / Kerberos / Kerberos) | Scope (single system / domain-wide / domain-wide perpetual) | Tool Used (Mimikatz pth / Rubeus ptt / Mimikatz golden) | Detection Method (SMB auth anomaly / ticket reuse / impossible ticket lifetime). Stems ask you to identify the attack from its mechanism
  2. Hands-on exercise: set up a two-VM Active Directory lab (DC + workstation, VirtualBox or GNS3). On the workstation, run Mimikatz logonpasswords as admin to dump NTLM hashes, then use psexec.py from a Kali VM to connect to the DC with the harvested hash — document each step and the exact commands. For PTT: capture a TGT with Rubeus dump /credentialtype:tgt and inject it with Rubeus ptt
  3. Memorize the defense-in-depth mitigations: (1) LSA Protection (LocalSecurityAuthority\RestrictRemoteSAM registry key) — blocks remote access to lsass.exe; (2) Credential Guard (VBS-protected) — isolates secrets in a VSM enclave; (3) Tiered Administration Model (T0=Domain Controllers, T1=member servers, T2=workstations) — prevents admin credentials on all tiers; (4) network segmentation restricting workstation-to-workstation SMB (445); (5) EDR with LSASS memory access alerts and behavioral detection of unusual authentication patterns
  4. Review related modules: Module 5 (System Hacking) for the initial compromise techniques that provide the foothold, and Module 19 (Post-Exploitation & IR) for what happens once lateral movement reaches its objective — exfiltration, C2 establishment, detection and containment

Frequently Asked Questions About Lateral Movement

What is a golden ticket attack and how does it differ from Pass-the-Ticket?

A golden ticket forges a Kerberos TGT from scratch using the krbtgt account's NTLM hash; Pass-the-Ticket replays a legitimately issued TGT stolen from memory. Golden Ticket: dump the krbtgt NT hash (typically via DCSync or LSASS access on a Domain Controller), then forge a TGT for any user with Mimikatz (kerberos::golden /user:Administrator /rc4:krbtgt_hash). The forged ticket is valid until the krbtgt password changes — or forever if never changed — granting persistent, domain-wide access that survives logoff, password changes, and service restarts. Exam points: (1) it requires the krbtgt hash, so you already have Domain Admin-level access; (2) detection is hard — the ticket looks cryptographically valid and the KDC cannot distinguish forged from legitimate; (3) mitigation: rotate krbtgt twice, monitor for TGTs with impossible encryption types or lifetimes, enable Kerberos pre-authentication on all accounts. Key difference from PTT: PTT is ephemeral (expires per normal policy); a golden ticket persists until krbtgt rotation.

How does LSA Protection prevent lateral movement attacks?

LSA Protection (LSASS protection) restricts which processes can access the memory of the LSASS (Local Security Authority Subsystem Service) process, via the registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RestrictRemoteSAM: 0 (default — any authenticated user), 1 (only LocalSystem and services), 2 (only LocalSystem). At level 1+, it blocks remote access to LSASS memory from other machines — remote process injection into lsass.exe, ReadProcessMemory calls from remote contexts, network-based credential dumping. It's a defense-in-depth measure alongside Credential Guard and EDR, but it does NOT stop a local process already running on the same machine with SYSTEM privileges — for that, Credential Guard (VBS-based isolation) is required. Together they form a layered defense against the most common lateral movement prerequisite: credential dumping. Practical implication: in a well-protected environment the attacker cannot easily read NTLM hashes from memory and must resort to DCSync (requiring existing domain admin) or offline attacks.

Related CEH v13 Modules

Related Glossary Terms