This module covers what happens after initial compromise — both from the attacker's perspective (persistence, privilege escalation, log clearing, data exfiltration) and the defender's perspective (incident response lifecycle, forensic investigation, recovery procedures). Understanding both sides is critical for ethical hackers.
The CEHStudy app carries 13 flashcards for Module 19 across 3 sections — one heads-up: the app's Module 19 deck currently covers the paired Cloud Computing domain, so read it as a companion to this page and drill post-exploitation and incident response itself with the Module 19 practice questions.
Digital forensics fundamentals and chain of custody
System recovery and hardening after compromise
Important Terms & Concepts
Persistence: Maintaining access after reboot or credential changes. Methods: registry Run keys, Windows Services, scheduled tasks, WMI event subscriptions, bootkits/rootkits.
Privilege Escalation: Moving from standard user to administrator/root. Vertical escalation (higher privileges) vs horizontal escalation (different user). Tools: Mimikatz, WinPEAS, LinPEAS.
Log Clearing: Deleting or modifying event logs, firewall logs, and application logs to cover tracks. Windows: `wevtutil`, `Clear-EventLog`. Linux: `auditctl -C`, log rotation.
Data Exfiltration: Transferring stolen data out of the network. Methods: DNS tunneling, HTTP/S POST, FTP, cloud storage upload, email, ICMP tunneling, covert channels.
Chain of Custody: Documented record of evidence handling from collection to presentation. Critical for legal admissibility. Includes who collected, when, where, and how evidence was stored/transferred.
How to Study This Module
Memorize the Incident Response lifecycle phases and key activities in each
Know common persistence mechanisms on Windows and Linux
Learn anti-forensics methods and how to detect them
Frequently Asked Questions
What is the first step in incident response? Preparation — having tools, policies, and trained personnel ready before an incident occurs. Once an incident happens, Detection & Analysis is the first active phase.
How do ethical hackers use this knowledge? To test persistence mechanisms, verify privilege escalation paths, check if logs are properly configured, and assess incident response readiness through red team exercises.
What is Post-Exploitation and Incident Response in Ethical Hacking?
Post-Exploitation & Incident Response (Module 19) is a dual-perspective domain on the Certified Ethical Hacker v13 (CEH v13) exam. The post-exploitation side covers what an attacker does after access: establishing persistence for long-term access, escalating privileges to administrative control, covering tracks through anti-forensics, and exfiltrating stolen data. The incident response side covers how defenders detect, contain, and recover using structured frameworks (NIST SP 800-61, SANS PICERL) — knowing how attackers operate is what makes the defenses work. On the CEH v13 exam, questions related to Module 19 account for approximately 8% of total questions.
Key Concepts in Post-Exploitation & IR
Persistence Mechanisms — Maintaining Access: Persistence makes attacker access survive reboots, credential resets, even reimages. Techniques the exam tests: (1) Registry Run keys — HKLM\Software\Microsoft\Windows\CurrentVersion\Run (executes at user logon); (2) Windows Services — a new service pointing to a malicious binary (sc.exe create / sc.exe start); (3) Scheduled Tasks — entries that run at specific times or trigger conditions; (4) WMI Event Subscriptions — triggers in the WMI repository that execute code on events like process start or user logon; (5) Bootkits/Rootkits — firmware-level persistence surviving OS reinstallation (UEFI bootkits like LoJax); (6) Linux — .bashrc/.profile modifications, cron jobs, systemd units, PAM backdoors. WMI subscriptions are among the stealthiest: minimal filesystem artifacts, triggered by legitimate system events. Detection: review scheduled tasks, services with unusual paths or startup types, WMI event filters, compare running processes against known-good baselines.
Privilege Escalation — Local Exploitation Path: Privilege escalation moves from initial access (typically standard user) to administrative/root control. Exam coverage: (1) kernel exploits — CVE-based (CVE-2021-34527 PrintSpoofer on Windows; dirty pipe/dirty cred on Linux); (2) misconfiguration abuse — services with write permissions allowing binary replacement, unquoted service paths, token manipulation; (3) credential harvesting for local use — stored credentials in registry, password files, high-privilege service accounts; (4) token/impersonation attacks — duplicating a higher-privileged process's token (Mimikatz privilege::debug + token::steal); (5) SUID/SGID binary exploitation on Linux. Tools: WinPEAS (Windows Privilege Escalation Awesome Script — automated enumeration of escalation paths), LinPEAS (Linux equivalent), Metasploit's local_exploit_suggester. Key point: WinPEAS/LinPEAS are enumeration tools, not exploitation tools — you still apply the exploit after identification.
Anti-Forensics & Log Clearing: Anti-forensics keeps defenders from understanding what happened. CEH-tested techniques: (1) Windows Event Log clearing — wevtutil cl Security / Clear-EventLog Security (the action itself logs: Event ID 1102 "The audit log was cleared"); (2) Linux log manipulation — deleting /var/log/auth.log, auditctl -C (flush audit buffers), modifying /etc/wtmp and /etc/btmp (login records); (3) timestamp manipulation — touch on Linux, PowerShell on Windows; (4) timestomping — setting file creation/modification times to match legitimate activity; (5) memory clearing — zeroing RAM before shutdown to defeat memory forensics. Log clearing is self-detecting in well-configured environments: if logs are forwarded to a central SIEM first, the deletion attempt is captured. Key detection signal: Event ID 1102 (log cleared) combined with Event ID 4688 (process creation showing wevtutil or cmd.exe). Best defense: ship logs to immutable storage (SIEM, cloud WORM) so they cannot be modified at the source.
Data Exfiltration & Covert Channels: Exfiltration is the final step — stolen data leaves the environment. Methods: (1) DNS tunneling — data encoded into DNS query names (e.g., base32-encoded subdomain labels); bypasses many egress firewalls because port 53 is rarely filtered; tools: dnscat, iodine; (2) HTTP/S POST to an attacker-controlled server — most common in real attacks; (3) covert channels — data hidden in fields not normally inspected (ICMP payload, TCP timestamp field, DNS TXT records); (4) cloud storage — public services (pastebin, cloud storage, image hosting) to dodge pattern-based detection; (5) email exfiltration to an attacker-controlled mailbox, often compressed/encrypted attachments. DNS tunneling is the most commonly tested covert channel — it exploits the assumption that DNS traffic is trusted infrastructure. Detection: unusually high DNS query volume from one host, abnormally long subdomain labels, queries to high-entropy (random-looking) domains. Egress filtering should force internal hosts through a logged internal recursive resolver instead of public DNS.
Common Exam Mistakes in Module 19
Mixing the NIST and SANS incident response models: the exam tests both, and their phase counts differ. NIST SP 800-61 runs Preparation → Detection & Analysis → a combined Containment / Eradication / Recovery stage → Post-Incident Activity, with lessons learned feeding back into readiness. SANS PICERL splits the middle: six distinct steps — Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. Stems name the framework first; pairing the wrong phase list to a right-sounding model is the classic miss.
Hunting persistence by checking Run keys and services only: WMI event subscriptions (filter + consumer + binding) execute code on a system event with no dropped file, survive reboots automatically, and never appear in Task Manager or Services.msc. The defensible hunt queries the root/subscription namespace or uses Autoruns' WMI tab against a known-good baseline — otherwise the implant simply is not seen.
Believing cleared logs destroy the evidence: the attacker's anti-forensics kit — wevtutil/Clear-EventLog, secure deletion with cipher.exe, timestamp manipulation — only reaches what stays local. The counter in exam answers is centralized, append-only log shipping: events leave the host before tampering, and SIEM correlation (one admin account touching forty workstations in an hour) reconstructs what the local logs no longer show.
Tools Used in Post-Exploitation & IR
Post-exploitation and incident response tooling the CEH v13 exam references, by job:
Mimikatz: the post-exploitation Swiss army knife — privilege::debug for token manipulation, token::steal for impersonation, lsadump::sam and lsadump::dcsync for offline credential extraction, sekurlsa for live memory dumping
WinPEAS / LinPEAS: automated local privilege-escalation enumeration — WinPEAS checks kernel-exploit applicability, unquoted service paths, weak file permissions, and stored credentials; LinPEAS checks SUID binaries, sudo misconfigurations, and writable /etc/passwd
Cobalt Strike: post-exploitation framework with built-in persistence modules for services, tasks, and WMI, privilege escalation via direct Windows API calls, and data exfiltration through Malleable C2 profiles
Autoruns (Sysinternals): definitive persistence enumeration tool — every auto-starting program, service, driver, scheduled task, WMI subscription, and browser extension in one view, the WMI tab catching fileless implants
Volatility: memory (RAM) forensics — extracts processes, network connections, and credentials from memory dumps; RAM holds what disk never sees: injected code, decrypted keys, running malware
Autopsy: open-source digital forensics platform for examining disk images — filesystem analysis, keyword search, email recovery, web history extraction, and artifact correlation
Worked Example: Compromise to Containment, One Incident at a Time
Attacker side, in order: code execution becomes persistence — a WMI event subscription created from the command line leaves no file behind; WinPEAS enumerates the host and finds an unquoted service path for local privilege escalation to SYSTEM; stolen data is staged and exfiltrated over DNS tunneling so outbound traffic looks like ordinary lookups; the exit kit runs last — Clear-EventLog wipes the local record, cipher.exe overwrites deleted files. Defender side, same timeline: the SIEM correlates thousands of events and fires on the pattern no single host reveals — an admin account authenticating to forty workstations in an hour.
The twist: what happens next is decided by framework and by physics. Containment follows NIST's third phase — isolate affected systems, block IOCs, reset compromised credentials; then capture evidence while it is still live memory, because Volatility pulls processes, connections, and decrypted keys from RAM before a reboot destroys them. The disk path: write-blocked acquisition plus matching hashes of original and image, every transfer documented in chain of custody — the paperwork that keeps the evidence admissible. Finally, Post-Incident Activity (NIST) or Lessons Learned (SANS) closes the loop back into Preparation — both frameworks begin where they end.
How to Study Post-Exploitation & IR for the CEH v13 Exam
To effectively study Module 19 for the Certified Ethical Hacker exam:
Create a persistence comparison table: Mechanism | Location (registry path/file path) | Trigger (logon/reboot/scheduled/event) | Survives Reboot? | Survives Credential Reset? | Detection Method. Stems ask which persistence mechanism survives specific remediation — e.g., "Which mechanism survives a password reset?" (Answer: services pointing to files, WMI subscriptions, bootkits — NOT registry Run keys if the user profile is reset, NOT scheduled tasks for that specific user)
Hands-on exercise: on a Windows VM, use WinPEAS to enumerate privilege escalation paths and document what it finds (applicable kernel exploits, service misconfigurations, credential storage locations), then use Autoruns to catalog all persistence locations. For IR: write an incident report in NIST structure — describe a simulated breach through each phase (Preparation: what should have been in place; Detection: what alerts fired; Containment: what was isolated; Recovery: what was rebuilt; Post-Incident: what was learned)
Memorize NIST SP 800-61r2 phases and key activities: Preparation (IR plan, tools, training, communication) → Detection & Analysis (identify, triage, collect evidence) → Containment/Eradication/Recovery (short-term isolation, remove root cause, restore from clean media) → Post-Incident (lessons learned report, update IR plan). The SANS model (PICERL) separates Identification from Preparation and adds Lessons Learned as a distinct final phase. Stems ask which phase a given activity belongs to
Review related modules: Module 5 (System Hacking) for the initial access techniques that lead into post-exploitation, and Module 18 (Lateral Movement) for how persistence and privilege escalation enable network-wide movement. The complete lifecycle: Reconnaissance → Initial Access (Module 5) → Privilege Escalation (Module 19) → Lateral Movement (Module 18) → Objectives (Exfiltration/Ransomware, Module 19) → Cover Tracks (Anti-forensics, Module 19)
Frequently Asked Questions About Post-Exploitation & IR
What is a WMI event subscription and why is it significant for persistence detection?
A WMI (Windows Management Instrumentation) event subscription is a persistent trigger that executes code when a specific system event occurs — no file on disk, invisible to standard process monitoring. The attacker uses WMIC or PowerShell to create three components: (1) an Event Filter — what triggers execution (e.g., __TimerFilter for periodic runs, __EventFilter for process start); (2) a Consumer — what executes (CommandLineEventConsumer running a binary, ActiveScriptEventConsumer running code); (3) a Binding — connecting the filter to the consumer. Example: wmic /namespace:\root\subscription create __EventFilter name="f" QueryLanguage="WQL" Query="SELECT * FROM __TimerFilter WITHIN 60". Why it matters: minimal filesystem artifacts (no dropped executable when reusing cmd.exe or powershell.exe), automatic persistence across reboots, and invisibility in Task Manager or Services.msc — you must query the WMI repository (Get-WmiObject -Namespace root/subscription) or use Autoruns' "WMI" tab. Detection: enumerate all event filters, consumers, and bindings in the subscription namespace against a known-good baseline. A defender who only checks services and registry Run keys misses WMI implants entirely.
What is chain of custody and why is it critical in digital forensics?
Chain of custody is the documented, unbroken record of who handled digital evidence from collection to court. It includes: (1) date/time of collection; (2) collector's name and credentials; (3) location where found; (4) description (make, model, serial number, IP address, hash value); (5) each transfer — who received it, when, why, how stored; (6) storage conditions (write-blocker used? bag sealed? hash verified at each transfer?); (7) final disposition. Why critical: (1) legal admissibility — without proper chain of custody, evidence can be excluded from court; (2) integrity verification — hashes (MD5/SHA-256) calculated at collection and verified at each transfer prove the evidence was not modified; (3) accountability — every person who touched it is documented, preventing tampering. Standard process: photograph in situ → connect through a write-blocker → create a forensic image (dd, FTK Imager, X-Ways) → hash original and image → seal the original in an anti-static bag with evidence label → store in a restricted-access evidence locker. The write-blocker is the single most important piece of equipment: it prevents any modification of the original media during imaging, which is what makes the copy admissible.
Related CEH v13 Modules
Module 5: System Hacking — provides the initial access that post-exploitation (persistence, escalation, exfiltration) builds on
Module 18: Lateral Movement — overlap: persistence and privilege escalation here enable PtH/PTT/pivoting to other hosts