Lateral movement is the set of techniques attackers use to move through a network from an initial compromise to other systems. This module covers pass-the-hash (PtH), pass-the-ticket (PTT), remote service exploitation (SMB, RDP, SSH, WinRM), pivoting techniques, credential dumping, and Metasploit post-exploitation modules.
The CEHStudy app carries 13 flashcards for Module 18 across 3 sections — one heads-up: the app's Module 18 deck currently covers the paired IoT & OT domain, so read it as a companion to this page and drill lateral movement itself with the Module 18 practice questions.
Key Topics Covered
Pass-the-Hash (PtH): using NTLM hashes instead of passwords
Pass-the-Ticket (PTT): using stolen Kerberos tickets
Remote service attacks: SMB, RDP, SSH, WinRM, WMI
Pivoting: using compromised host as jump point
Credential dumping: Mimikatz, LSASS extraction
Lateral movement detection and prevention
Metasploit post-exploitation modules
Important Terms & Concepts
Pass-the-Hash (PtH): Attacker captures NTLM hash and uses it to authenticate to remote services without knowing the plaintext password. Tools: Mimikatz, Impacket (psexec.py, smbexec.py).
Pass-the-Ticket (PTT): Attacker extracts Kerberos TGT (ticket-granting ticket) and uses it to authenticate without credentials. More advanced than PtH — works in pure Kerberos environments.
Pivoting: Using a compromised host as a jump point to reach otherwise inaccessible internal networks. Tools: Metasploit port forwards, ssh -L/-D, Chisel, Ligolo.
Mimikatz: Most widely known credential dumping tool. Extracts passwords, hashes, PINs, and Kerberos tickets from memory. Can perform PtH and PTT attacks.
Credential Dumping: Extracting credentials from memory (LSASS on Windows). Methods: lsass.exe injection, token manipulation, registry extraction of cached credentials.
WinRM (Windows Remote Management): Microsoft's implementation of WS-Management protocol. Commonly abused for lateral movement via PowerShell Invoke-Command and Impacket's winrm.py.
How to Study This Module
Understand the difference between PtH and PTT attacks
Know which remote services are commonly abused for lateral movement
Learn pivoting techniques and tools
Understand how credential dumping works and detection methods
Frequently Asked Questions
What is lateral movement? The process attackers use to move through a network from an initial compromise to other systems, escalating privileges and expanding access.
How do you prevent lateral movement? Network segmentation, least privilege access, disable SMB/RDP where possible, LSA protection, Credential Guard, MFA, endpoint detection (EDR), and monitoring for anomalous authentication patterns.
Lateral Movement is a post-exploitation phase and a dedicated topic on the Certified Ethical Hacker v13 (CEH v13) exam. After initial access (phishing, web exploitation, or vulnerability exploitation), the attacker traverses the internal network to reach high-value targets: domain controllers, databases, executive workstations, sensitive file servers. It exploits the trust relationships built into enterprise networks — credentials (or their hashes/tickets) valid on one machine are likely valid on many more. On the CEH v13 exam, questions related to Module 18 account for approximately 7% of total questions.
Key Concepts in Lateral Movement
Pass-the-Hash (PtH) & NTLM Vulnerability: NTLM fundamentally trusts the hash as proof of knowledge: a client authenticates by proving possession of its NTLM hash (NTOWFv1 = MD4 of UTF-16LE password), not the plaintext — so anyone who captures the hash can authenticate as that user without ever knowing the password. Attack flow: (1) dump NTLM hashes from LSASS memory with Mimikatz (sekurlsa::logonpasswords) or read the SAM database on disk; (2) use the hash to reach remote services over SMB (psexec.py, smbexec.py), WMI (wmiexec.py), or WinRM (winrm.py, Impacket). In domains, a Domain Admin's NTLM hash grants access to every system. Mitigations: LSA Protection (blocks remote reads of lsass.exe memory), Credential Guard (isolates authentication secrets in a VSM enclave), disable NTLM where Kerberos suffices. Key distinction: PtH works without the plaintext but requires NTLM enabled — it fails in pure Kerberos environments.
Pass-the-Ticket (PTT) & Kerberos Ticket Stealing: Kerberos uses tickets: the TGT (from the KDC after the AS-REQ/AS-REP exchange) and TGS (service tickets obtained with the TGT). PTT extracts a valid TGT from LSASS memory and replays it to request service tickets for any domain service — an admin's TGT means domain-wide access equivalent to Domain Admin privileges. Exam points: (1) TGTs are AES-encrypted with the user's NT hash as key, so PTT effectively requires knowledge of the NT hash; (2) default TGT lifetime is 10 hours, after which the ticket expires; (3) Rubeus (by Andy Robbins) adds AS-REP roasting (accounts without pre-authentication) and golden ticket forging (the krbtgt account's NT hash forges valid TGTs for any user, forever); (4) PTT is harder to detect than PtH because stolen and legitimate Kerberos logons look alike in the logs. Mitigations: Credential Guard, monitor service ticket requests from unusual source IPs, tiered administration (no Domain Admins logging onto workstations).
Pivoting Techniques & Network Tunneling: Pivoting uses a compromised host as a proxy/jump box when internal subnets are unreachable from the attacker's external position. Techniques: (1) SSH tunneling — ssh -L (local port forward), ssh -D (dynamic SOCKS proxy); (2) Metasploit — route add and portfwd add for TCP/UDP forwarding through the host; (3) Chisel — lightweight TCP/UDP tunneling over HTTP(S), harder to detect than raw SSH; (4) Ligolo-ng — multi-hop chaining and DNS tunneling; (5) SOCKS5 proxy on the compromised host, with tools like ProxyChains routing all attacker traffic through the pivot. Legal in authorized penetration tests; illegal without written scope authorization. The key concept: you don't need direct reachability to a target if your foothold can reach it. Detection: one internal IP making many distinct connections to other internal IPs, workstation-to-workstation outbound, DNS tunneling patterns.
Credential Dumping & LSASS Memory Extraction: Credential dumping is the prerequisite for PtH/PTT — without extracted credentials, you can't move laterally. On Windows the primary target is LSASS (Local Security Authority Subsystem Service), which holds authentication secrets in memory: plaintext passwords, NTLM hashes, Kerberos tickets, PINs. Methods: (1) read lsass.exe process memory via OpenProcess/ReadProcessMemory (requires SeDebugPrivilege — typically SYSTEM or admin on the target); (2) inject a DLL into LSASS that calls LsaFetchCredentials; (3) create an LSASS minidump and analyze offline with Mimikatz or Hashdump; (4) registry extraction — read the SAM hive from disk for local account hashes (requires SYSTEM access to C:\Windows\System32\config\SAM); (5) DPAPI-based extraction of browser-saved passwords and Windows Credential Manager. Modern EDRs detect LSASS memory access attempts (process injection, ReadProcessMemory against the lsass.exe PID); Credential Guard blocks this by running authentication in an isolated VSM enclave unreadable even by SYSTEM.
Common Exam Mistakes in Module 18
Mixing up Pass-the-Hash and Pass-the-Ticket: both skip normal authentication but live at different protocol layers. PtH authenticates directly with a stolen NTLM/NT hash — many SMB logons accept the hash itself, so a dumped value is as good as the password. PTT replays a stolen Kerberos ticket (TGT or TGS) from the ticket cache, authenticating to services until that ticket expires. Exam stems name the artifact (hash vs ticket); the artifact picks the layer.
Assuming credential dumping needs disk access: modern Windows protects the on-disk copies of secrets, so attackers read process memory instead — NTLM hashes and Kerberos tickets sit in LSASS, which is why sekurlsa::logonpasswords targets the live process. That same fact drives the defense: Credential Guard and LSA protection exist to keep that memory out of reach.
Underestimating what a golden ticket lasts: a forged TGT signed with the KRBTGT key is trusted by every KDC in the forest until that hash changes — so IR rotates the krbtgt account (twice, to invalidate tickets from the previous rotation) after any such compromise. Related stem: AS-REP roasting (Rubeus asreproast) needs no user password at all, only accounts with pre-authentication disabled.
Tools Used in Lateral Movement
Lateral movement tooling the CEH v13 exam references, by job:
Mimikatz: the credential-dumping anchor — logonpasswords extracts hashes, plaintext, and tickets from LSASS; sekurlsa::pth performs pass-the-hash; kerberos::ptt performs pass-the-ticket; kerberos::golden forges golden tickets. Detected by virtually all EDR solutions
Impacket: the Python protocol suite behind most study-material PtH references — psexec.py executes remotely over SMB named pipes, wmiexec.py moves via WMI, smbexec.py works through service creation, atexec.py abuses Task Scheduler, and secretsdump.py pulls credentials remotely without touching the target disk
Metasploit: post-exploitation modules for the movement phase — local_exploit_suggester finds local privilege escalation paths, migrate shifts the session into a stable process, and route/portfwd build the tunnels that reach otherwise unreachable subnets
Cobalt Strike: beacon-based C2 with built-in lateral movement modules, Malleable C2 profiles for evasion, an integrated SOCKS proxy for pivoting, and process-injection credential dumping
Rubeus: the Kerberos-specific toolset — asreproast for AS-REP roasting, golden and silver ticket forging, PTT execution, and S4U2Self/S4U2Proxy impersonation attacks
Ligolo-ng: modern tunneling framework for low-noise pivoting — multi-hop chains over HTTP/HTTPS proxy modes or DNS tunneling to reach segmented internal networks
Worked Example: One Shell, Then the Whole Domain, Hop by Hop
The attacker lands on a workstation with code execution. Mimikatz against LSASS dumps the user's NTLM hashes — no plaintext crosses the wire again. Authentication itself becomes the movement method: sekurlsa::pth (or Impacket's psexec.py) uses the NT hash directly to start a process on the next host; kerberos::ptt replays a captured TGT to open RDP or WinRM sessions across the tier. Each new host is both destination and launch point — SSH tunnels, SOCKS proxies, or Ligolo-ng chains turn the fleet into a relay reaching the segmented subnet where the file servers and domain controller sit.
The twist: every hop is also a detection opportunity, which is why the exam pairs the attack with its brakes. EDR flags Mimikatz's LSASS access almost universally; least-privilege and tiered administration (JEA) mean a workstation shell carries no domain-admin hash at all; segmentation stops the relay from reaching the core; monitoring for anomalous cross-host logons — one account authenticating to forty machines in an hour — turns slow lateral movement into an alert. If a golden ticket is found in play, krbtgt rotation is the incident's signature cleanup step.
How to Study Lateral Movement for the CEH v13 Exam
To effectively study Module 18 for the Certified Ethical Hacker exam:
Create a comparison table: Attack Type (PtH vs PTT vs Golden Ticket) | What's Stolen (NTLM hash / TGT / krbtgt hash) | Protocol Required (NTLM / Kerberos / Kerberos) | Scope (single system / domain-wide / domain-wide perpetual) | Tool Used (Mimikatz pth / Rubeus ptt / Mimikatz golden) | Detection Method (SMB auth anomaly / ticket reuse / impossible ticket lifetime). Stems ask you to identify the attack from its mechanism
Hands-on exercise: set up a two-VM Active Directory lab (DC + workstation, VirtualBox or GNS3). On the workstation, run Mimikatz logonpasswords as admin to dump NTLM hashes, then use psexec.py from a Kali VM to connect to the DC with the harvested hash — document each step and the exact commands. For PTT: capture a TGT with Rubeus dump /credentialtype:tgt and inject it with Rubeus ptt
Memorize the defense-in-depth mitigations: (1) LSA Protection (LocalSecurityAuthority\RestrictRemoteSAM registry key) — blocks remote access to lsass.exe; (2) Credential Guard (VBS-protected) — isolates secrets in a VSM enclave; (3) Tiered Administration Model (T0=Domain Controllers, T1=member servers, T2=workstations) — prevents admin credentials on all tiers; (4) network segmentation restricting workstation-to-workstation SMB (445); (5) EDR with LSASS memory access alerts and behavioral detection of unusual authentication patterns
Review related modules: Module 5 (System Hacking) for the initial compromise techniques that provide the foothold, and Module 19 (Post-Exploitation & IR) for what happens once lateral movement reaches its objective — exfiltration, C2 establishment, detection and containment
Frequently Asked Questions About Lateral Movement
What is a golden ticket attack and how does it differ from Pass-the-Ticket?
A golden ticket forges a Kerberos TGT from scratch using the krbtgt account's NTLM hash; Pass-the-Ticket replays a legitimately issued TGT stolen from memory. Golden Ticket: dump the krbtgt NT hash (typically via DCSync or LSASS access on a Domain Controller), then forge a TGT for any user with Mimikatz (kerberos::golden /user:Administrator /rc4:krbtgt_hash). The forged ticket is valid until the krbtgt password changes — or forever if never changed — granting persistent, domain-wide access that survives logoff, password changes, and service restarts. Exam points: (1) it requires the krbtgt hash, so you already have Domain Admin-level access; (2) detection is hard — the ticket looks cryptographically valid and the KDC cannot distinguish forged from legitimate; (3) mitigation: rotate krbtgt twice, monitor for TGTs with impossible encryption types or lifetimes, enable Kerberos pre-authentication on all accounts. Key difference from PTT: PTT is ephemeral (expires per normal policy); a golden ticket persists until krbtgt rotation.
How does LSA Protection prevent lateral movement attacks?
LSA Protection (LSASS protection) restricts which processes can access the memory of the LSASS (Local Security Authority Subsystem Service) process, via the registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa\RestrictRemoteSAM: 0 (default — any authenticated user), 1 (only LocalSystem and services), 2 (only LocalSystem). At level 1+, it blocks remote access to LSASS memory from other machines — remote process injection into lsass.exe, ReadProcessMemory calls from remote contexts, network-based credential dumping. It's a defense-in-depth measure alongside Credential Guard and EDR, but it does NOT stop a local process already running on the same machine with SYSTEM privileges — for that, Credential Guard (VBS-based isolation) is required. Together they form a layered defense against the most common lateral movement prerequisite: credential dumping. Practical implication: in a well-protected environment the attacker cannot easily read NTLM hashes from memory and must resort to DCSync (requiring existing domain admin) or offline attacks.
Related CEH v13 Modules
Module 5: System Hacking — provides the initial-compromise foothold (shell, web shell) that lateral movement extends through the network