ALL PASS, NO FAIL!

CEH v13 Module 19: Post-Exploitation & Incident Response

This module covers what happens after initial compromise — both from the attacker's perspective (persistence, privilege escalation, log clearing, data exfiltration) and the defender's perspective (incident response lifecycle, forensic investigation, recovery procedures). Understanding both sides is critical for ethical hackers.

The CEHStudy app carries 13 flashcards for Module 19 across 3 sections — one heads-up: the app's Module 19 deck currently covers the paired Cloud Computing domain, so read it as a companion to this page and drill post-exploitation and incident response itself with the Module 19 practice questions.

Key Topics Covered

Important Terms & Concepts

Persistence: Maintaining access after reboot or credential changes. Methods: registry Run keys, Windows Services, scheduled tasks, WMI event subscriptions, bootkits/rootkits.
Privilege Escalation: Moving from standard user to administrator/root. Vertical escalation (higher privileges) vs horizontal escalation (different user). Tools: Mimikatz, WinPEAS, LinPEAS.
Log Clearing: Deleting or modifying event logs, firewall logs, and application logs to cover tracks. Windows: `wevtutil`, `Clear-EventLog`. Linux: `auditctl -C`, log rotation.
Data Exfiltration: Transferring stolen data out of the network. Methods: DNS tunneling, HTTP/S POST, FTP, cloud storage upload, email, ICMP tunneling, covert channels.
Incident Response Lifecycle (NIST): 1) Preparation → 2) Detection & Analysis → 3) Containment & Eradication → 4) Recovery → 5) Post-Incident Activity.
Chain of Custody: Documented record of evidence handling from collection to presentation. Critical for legal admissibility. Includes who collected, when, where, and how evidence was stored/transferred.

How to Study This Module

Frequently Asked Questions

What is the first step in incident response?
Preparation — having tools, policies, and trained personnel ready before an incident occurs. Once an incident happens, Detection & Analysis is the first active phase.

How do ethical hackers use this knowledge?
To test persistence mechanisms, verify privilege escalation paths, check if logs are properly configured, and assess incident response readiness through red team exercises.

Related Modules

What is Post-Exploitation and Incident Response in Ethical Hacking?

Post-Exploitation & Incident Response (Module 19) is a dual-perspective domain on the Certified Ethical Hacker v13 (CEH v13) exam. The post-exploitation side covers what an attacker does after access: establishing persistence for long-term access, escalating privileges to administrative control, covering tracks through anti-forensics, and exfiltrating stolen data. The incident response side covers how defenders detect, contain, and recover using structured frameworks (NIST SP 800-61, SANS PICERL) — knowing how attackers operate is what makes the defenses work. On the CEH v13 exam, questions related to Module 19 account for approximately 8% of total questions.

Key Concepts in Post-Exploitation & IR

Common Exam Mistakes in Module 19

Mixing the NIST and SANS incident response models: the exam tests both, and their phase counts differ. NIST SP 800-61 runs Preparation → Detection & Analysis → a combined Containment / Eradication / Recovery stage → Post-Incident Activity, with lessons learned feeding back into readiness. SANS PICERL splits the middle: six distinct steps — Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. Stems name the framework first; pairing the wrong phase list to a right-sounding model is the classic miss.
Hunting persistence by checking Run keys and services only: WMI event subscriptions (filter + consumer + binding) execute code on a system event with no dropped file, survive reboots automatically, and never appear in Task Manager or Services.msc. The defensible hunt queries the root/subscription namespace or uses Autoruns' WMI tab against a known-good baseline — otherwise the implant simply is not seen.
Believing cleared logs destroy the evidence: the attacker's anti-forensics kit — wevtutil/Clear-EventLog, secure deletion with cipher.exe, timestamp manipulation — only reaches what stays local. The counter in exam answers is centralized, append-only log shipping: events leave the host before tampering, and SIEM correlation (one admin account touching forty workstations in an hour) reconstructs what the local logs no longer show.

Tools Used in Post-Exploitation & IR

Post-exploitation and incident response tooling the CEH v13 exam references, by job:

Worked Example: Compromise to Containment, One Incident at a Time

Attacker side, in order: code execution becomes persistence — a WMI event subscription created from the command line leaves no file behind; WinPEAS enumerates the host and finds an unquoted service path for local privilege escalation to SYSTEM; stolen data is staged and exfiltrated over DNS tunneling so outbound traffic looks like ordinary lookups; the exit kit runs last — Clear-EventLog wipes the local record, cipher.exe overwrites deleted files. Defender side, same timeline: the SIEM correlates thousands of events and fires on the pattern no single host reveals — an admin account authenticating to forty workstations in an hour.

The twist: what happens next is decided by framework and by physics. Containment follows NIST's third phase — isolate affected systems, block IOCs, reset compromised credentials; then capture evidence while it is still live memory, because Volatility pulls processes, connections, and decrypted keys from RAM before a reboot destroys them. The disk path: write-blocked acquisition plus matching hashes of original and image, every transfer documented in chain of custody — the paperwork that keeps the evidence admissible. Finally, Post-Incident Activity (NIST) or Lessons Learned (SANS) closes the loop back into Preparation — both frameworks begin where they end.

How to Study Post-Exploitation & IR for the CEH v13 Exam

To effectively study Module 19 for the Certified Ethical Hacker exam:

  1. Create a persistence comparison table: Mechanism | Location (registry path/file path) | Trigger (logon/reboot/scheduled/event) | Survives Reboot? | Survives Credential Reset? | Detection Method. Stems ask which persistence mechanism survives specific remediation — e.g., "Which mechanism survives a password reset?" (Answer: services pointing to files, WMI subscriptions, bootkits — NOT registry Run keys if the user profile is reset, NOT scheduled tasks for that specific user)
  2. Hands-on exercise: on a Windows VM, use WinPEAS to enumerate privilege escalation paths and document what it finds (applicable kernel exploits, service misconfigurations, credential storage locations), then use Autoruns to catalog all persistence locations. For IR: write an incident report in NIST structure — describe a simulated breach through each phase (Preparation: what should have been in place; Detection: what alerts fired; Containment: what was isolated; Recovery: what was rebuilt; Post-Incident: what was learned)
  3. Memorize NIST SP 800-61r2 phases and key activities: Preparation (IR plan, tools, training, communication) → Detection & Analysis (identify, triage, collect evidence) → Containment/Eradication/Recovery (short-term isolation, remove root cause, restore from clean media) → Post-Incident (lessons learned report, update IR plan). The SANS model (PICERL) separates Identification from Preparation and adds Lessons Learned as a distinct final phase. Stems ask which phase a given activity belongs to
  4. Review related modules: Module 5 (System Hacking) for the initial access techniques that lead into post-exploitation, and Module 18 (Lateral Movement) for how persistence and privilege escalation enable network-wide movement. The complete lifecycle: Reconnaissance → Initial Access (Module 5) → Privilege Escalation (Module 19) → Lateral Movement (Module 18) → Objectives (Exfiltration/Ransomware, Module 19) → Cover Tracks (Anti-forensics, Module 19)

Frequently Asked Questions About Post-Exploitation & IR

What is a WMI event subscription and why is it significant for persistence detection?

A WMI (Windows Management Instrumentation) event subscription is a persistent trigger that executes code when a specific system event occurs — no file on disk, invisible to standard process monitoring. The attacker uses WMIC or PowerShell to create three components: (1) an Event Filter — what triggers execution (e.g., __TimerFilter for periodic runs, __EventFilter for process start); (2) a Consumer — what executes (CommandLineEventConsumer running a binary, ActiveScriptEventConsumer running code); (3) a Binding — connecting the filter to the consumer. Example: wmic /namespace:\root\subscription create __EventFilter name="f" QueryLanguage="WQL" Query="SELECT * FROM __TimerFilter WITHIN 60". Why it matters: minimal filesystem artifacts (no dropped executable when reusing cmd.exe or powershell.exe), automatic persistence across reboots, and invisibility in Task Manager or Services.msc — you must query the WMI repository (Get-WmiObject -Namespace root/subscription) or use Autoruns' "WMI" tab. Detection: enumerate all event filters, consumers, and bindings in the subscription namespace against a known-good baseline. A defender who only checks services and registry Run keys misses WMI implants entirely.

What is chain of custody and why is it critical in digital forensics?

Chain of custody is the documented, unbroken record of who handled digital evidence from collection to court. It includes: (1) date/time of collection; (2) collector's name and credentials; (3) location where found; (4) description (make, model, serial number, IP address, hash value); (5) each transfer — who received it, when, why, how stored; (6) storage conditions (write-blocker used? bag sealed? hash verified at each transfer?); (7) final disposition. Why critical: (1) legal admissibility — without proper chain of custody, evidence can be excluded from court; (2) integrity verification — hashes (MD5/SHA-256) calculated at collection and verified at each transfer prove the evidence was not modified; (3) accountability — every person who touched it is documented, preventing tampering. Standard process: photograph in situ → connect through a write-blocker → create a forensic image (dd, FTK Imager, X-Ways) → hash original and image → seal the original in an anti-static bag with evidence label → store in a restricted-access evidence locker. The write-blocker is the single most important piece of equipment: it prevents any modification of the original media during imaging, which is what makes the copy admissible.

Related CEH v13 Modules

Related Glossary Terms