Every term the CEH v13 (312-50) exam can throw at you, in reading order A–Z. Definition first; the grey note under each one says what the exam actually asks about it.
Kerberoasting, AS-REP Roasting, Pass-the-Hash, DCSync, Golden/Silver Ticket, BloodHound enumeration, Shadow Credentials, ACL abuse, GPP (Group Policy Preferences) exploitation.
Skeleton Key (Mimikatz), Overpass the Hash, Malicious Replication, WMI Event Subscription persistence (PowerLurk), AdminSDHolder abuse. Methods to maintain access in AD environments.
Directly interacting with the target system to gather information. Examples: network scanning, ping sweeps, DNS zone transfers, enumeration. More likely to be detected by security systems and IDS.
Takes over active session by breaking connection or actively participating as MITM. Must guess sequence number before target responds.
Automated web application vulnerability scanner with deep Vulnerability Detection technology. Detects SQL injection, XSS, CSRF, and other OWASP Top 10 vulnerabilities.
An Advanced Persistent Threat (APT) is a prolonged, targeted cyberattack in which an adversary gains unauthorized access to a network and remains undetected for an extended period. The primary goal is data theft, espionage, or sabotage rather than immediate disruption. APTs are typically state-sponsored or well-funded criminal organizations with advanced capabilities, dedicated resources, and long-term operational planning.
On the CEH v13 exam: APTs are referenced throughout CEH v13, particularly in Modules 07 (Malware), 05 (Vulnerability Analysis), and the overall exam context. The exam tests knowledge of APT characteristics (targeted, persistent, advanced, organized), real-world examples (Stuxnet as first major discovered APT, targeting Iranian nuclear facilities via industrial control systems), the Lockheed Martin Cyber Kill Chain phases, MITRE ATT&CK framework awareness, and detection strategies (UEBA, threat intelligence, network traffic analysis for low-and-slow exfiltration).
Antimalware Scan Interface bypass to prevent PowerShell scripts from being scanned by antivirus. Common technique: patching amsi.dll AmsiScanBuffer function in memory.
APK reverse engineering, insecure data storage (SQLite, shared preferences), insufficient transport layer encryption, weak server-side API controls, code obfuscation bypass (ProGuard), malicious third-party app stores.
Securing application programming interfaces: authentication/authorization, rate limiting, input validation, encryption in transit, monitoring for abuse, OWASP API Security Top 10.
ARP Spoofing (also called ARP Cache Poisoning) is a Layer 2 attack where an attacker sends forged Address Resolution Protocol (ARP) messages onto a local network to associate their MAC address with the IP address of another device (typically the default gateway). This causes all traffic destined for that IP to be routed through the attacker, enabling man-in-the-middle interception.
On the CEH v13 exam: ARP spoofing is covered in CEH v13 Module 08 (Sniffing and Traffic Analysis) as a primary sniffing technique. The exam tests understanding of ARP protocol mechanics (ARP request/reply format, cache table structure, gratuitous ARP), how to detect ARP poisoning (monitoring for duplicate IP-to-MAC mappings, comparing ARP tables across hosts), defensive countermeasures (Dynamic ARP Inspection on managed switches, static ARP entries on critical systems, port security), and the limitations of ARP spoofing (only works on same Layer 2 broadcast domain/VLAN). Questions may present ARP cache outputs for anomaly identification.
Cracking Kerberos TGT ticket targeting users who do NOT have Kerberos pre-authentication required. Extract AS-REP ticket → crack offline for user password.
Mathematically related public/private key pair. Public key encrypts, private key decrypts (and vice versa for signatures). Algorithms: RSA, ECC, Diffie-Hellman. Slower than symmetric but solves key distribution.
Hierarchical model of possible attacks against a system. Root = attacker goal. Branches = methods. Leaves = specific techniques. Used for threat modeling and risk assessment.
Authenticated scanning uses valid credentials to log into targets for deeper assessment including configuration review and patch level. Unauthenticated scanning only observes from outside the network, missing many configuration issues.
Offering something enticing to the victim to lure them into a trap. Examples: leaving infected USB drives in parking lots, offering free downloads, promising exclusive content in exchange for credentials.
Advanced network attack and monitoring framework for Linux. Capabilities: ARP spoofing, DNS spoofing, HTTP proxying, Bluetooth attacks, WiFi deauth detection. Modern replacement for Ettercap in many scenarios.
A malicious hacker who exploits system vulnerabilities for personal gain, financial profit, or unauthorized access. Operates without permission and violates computer fraud laws.
Distributed ledger technology security: 51% attack, double-spending, smart contract vulnerabilities, private key management, consensus mechanism attacks (PoW, PoS).
Powerful Active Directory enumeration tool using Neo4j graph database. Maps relationships between users, computers, groups, and GPOs to find attack paths for privilege escalation.
Defensive security professionals responsible for detecting, responding to, and recovering from cyberattacks. Activities: monitoring SIEM, incident response, threat hunting, patch management.
Password cracking method systematically trying every possible character combination until the correct one is found. Effective against short/simple passwords but slow on strong ones.
A Buffer Overflow is a memory corruption vulnerability that occurs when a program writes more data to a buffer than it can hold, overwriting adjacent memory. This allows an attacker to modify program execution flow, inject and run arbitrary code, or cause a denial of service by corrupting critical data structures.
On the CEH v13 exam: Buffer overflows are central to CEH v13 Module 06 (System Hacking). The exam tests understanding of memory layout (stack frames, heap structure), exploitation methodology (finding EIP offset, NOP sleds, ROP chains), and modern mitigations including Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP/NX bits), stack canaries, and Control Flow Integrity (CFI). Questions often present assembly or C code snippets for vulnerability identification.
Incentive program where organizations reward ethical hackers for discovering and reporting vulnerabilities. Platforms: HackerOne, Bugcrowd, Intigriti. Ranges from $50 to $1M+ for critical findings.
Integrated platform for web application security testing. Features: proxy, scanner, intruder, repeater, repeater, sequencer, decoder, comparer. Community (free) and Professional editions.
A documented process to ensure that essential business functions can continue during and after a disaster. Includes incident response procedures, backup systems, recovery sites, communication plans, and regular testing schedules.
Impersonating executive to request wire transfers or sensitive information from employees, particularly finance departments. Also called Business Email Compromise (BEC).
Mobile security technique locking an app to specific certificate or public key, preventing MITM attacks even if device's trusted CA store is compromised. Bypass techniques exist but provide strong defense.
Documented chronological record of evidence handling from collection through court presentation. Ensures evidence integrity and admissibility in legal proceedings.
The foundational information security model consisting of three pillars: Confidentiality (data not disclosed), Integrity (data not tampered with), Availability (data accessible when needed). All other security controls map back to one or more of these principles.
Tricks user into clicking hidden/misleading elements using invisible iframe overlaying legitimate content. Prevention: X-Frame-Options DENY/SAMEORIGIN, CSP frame-ancestors directive.
Resending a legitimate email with a malicious link or attachment replacing the original. Uses the credibility of the previous communication to trick the recipient.
Unauthorized use of cloud resources for cryptocurrency mining. Detected via unusual CPU/billing patterns. Prevention: Resource monitoring alerts, IAM least privilege, container security scanning.
Public Cloud (shared infrastructure), Private Cloud (dedicated), Hybrid Cloud (combination), Multi-Cloud (multiple providers), Community Cloud (shared by organizations with common requirements).
Challenges: multi-tenancy, data location jurisdiction, volatile evidence, reliance on provider APIs, lack of physical access. Techniques: snapshot analysis, log collection, API audit trails.
Public S3 buckets, insecure APIs, weak IAM policies, cross-account permission issues, data exposure from encryption misconfiguration, insufficient audit logging. Most common cloud security issue.
IaaS (Infrastructure as a Service — EC2, VMs), PaaS (Platform as a Service — Heroku, App Engine), SaaS (Software as a Service — Office 365, Salesforce), FaaS (Function as a Service — Lambda).
Provider secures: Infrastructure, physical security, hypervisor. Customer secures: Data, access management, OS configuration, applications. Different for each service model — IaaS customer manages more, SaaS provider manages more.
Commercial adversary simulation platform used by red teams. Features: Beacon (payload), Malleable C2 (traffic obfuscation), resource editor, payload generation, lateral movement tools.
Command Injection (also called OS Command Injection or Shell Injection) is a vulnerability that allows an attacker to execute arbitrary operating system commands on the underlying server by injecting malicious input into application parameters that are passed to system call functions (system(), exec(), popen() in C; Runtime.exec() in Java; os.system() in Python).
On the CEH v13 exam: Command injection is covered in CEH v13 Module 14 (Hacking Web Applications) alongside SQL injection and XSS as a key injection vulnerability. The exam tests knowledge of shell metacharacters and their functions (;, |, &&, ||, $(), backticks), how to identify vulnerable endpoints (parameters passed to system calls), blind/OOB injection techniques, prevention strategies (input validation with allowlists, avoiding shell interpretation via parameter arrays, output encoding, containerization/sandboxing), and differences from SQL injection (OS-level vs database-level). Questions may present code snippets for vulnerability identification.
Security for Docker/Kubernetes environments: image scanning, runtime protection, network policies, secrets management, least privilege, vulnerability assessment of base images.
Compression Ratio Leak Made Easy. Client-side attack exploiting TLS/HTTP compression ratio to infer cookies by analyzing compressed packet sizes. Applies to SSL/TLS, SPDY, HTTPS. Prevention: Disable TLS compression.
Cross-Site Scripting (XSS) is a web security vulnerability that allows an attacker to inject malicious JavaScript or HTML into web pages viewed by other users. The injected script executes in the victim's browser with the victim's permissions, enabling session theft, data exfiltration, and account compromise.
On the CEH v13 exam: XSS is covered in CEH v13 Module 14 (Hacking Web Applications) and the OWASP Top 10. Exam questions test your ability to identify XSS vectors in code samples, distinguish between reflected/stored/DOM-based variants, understand browser security context (same-origin policy bypass via session cookies), and apply prevention measures like Content Security Policy (CSP) headers and output encoding.
One-way functions producing fixed-size digest: MD5 (128-bit, broken), SHA-1 (160-bit, deprecated), SHA-256 (256-bit, secure), SHA-512 (512-bit, secure), BLAKE3 (modern), bcrypt/scrypt/Argon2 (password hashing).
Hijacks victim system resources to mine cryptocurrency without consent. Uses Proof-of-Work algorithms. Also called 'Cryptojacking.' Can be inline (web-based) or installed (malware). Signs: high CPU/GPU usage, increased power consumption.
Cross-Site Request Forgery (CSRF) is an attack that forces an authenticated user's browser to send unintended requests to a trusted application. The attacker crafts a malicious request (form submission, link click, image load) that is automatically sent with the victim's valid session cookies, causing actions to be performed as if the victim initiated them.
On the CEH v13 exam: CSRF is covered in CEH v13 Module 14 (Hacking Web Applications). The exam tests understanding of the CSRF mechanism (browser automatically includes cookies with same-origin requests), distinction between CSRF and XSS (XSS executes attacker code; CSRF uses victim's own browser to send requests), prevention strategies (anti-CSRF tokens with unique per-session values, SameSite cookie attribute Lax/Strict, verifying Origin/Referer headers, requiring re-authentication for sensitive actions), and how to identify vulnerable endpoints. Questions may present HTML/code samples for vulnerability identification.
A dictionary of publicly disclosed information security vulnerabilities. Each entry has a unique identifier (e.g., CVE-2024-1234) and description. Maintained by MITRE Corporation.
Common Vulnerability Scoring System rates vulnerabilities from 0.0 to 10.0: 0.0 None, 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical. Base metrics: Attack Vector, Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability.
A Lockheed Martin framework identifying seven phases of a cyber attack: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control (C2), Actions and Objectives. Used to classify and prevent attacks at each stage.
Evidence-based knowledge about threats that helps organizations make better security decisions. Types: Strategic (for executives), Tactical (for security teams), Operational (for incident response), Technical (for systems/SIEM). Lifecycle: Direction → Collection → Processing → Analysis → Dissemination → Feedback.
Investigating hidden services on Tor/I2P networks where stolen data, exploits, and malware are traded. Tools: Tor Browser, Ahmia (search engine), dark web monitoring services.
Attacker obtains privileged account with domain replication rights, creates virtual DC similar to original AD, extracts NTLM hashes enabling Golden Ticket attacks. Tool: Mimikatz — lsadump::dcsync.
Rate limiting, traffic filtering with ACLs, blackhole routing (RFC 3896), CDN (Cloudflare, Akamai), Anycast distribution, IPS, redundant infrastructure across datacenters, ISP-level scrubbing centers, DDoS protection services (AWS Shield).
Nmap -D flag sends packets from multiple fake source IPs simultaneously. Example: nmap -D decoy1,decoy2,yourIP target. IDS sees traffic from all decoys, making it hard to identify real scanner.
A Denial of Service (DoS) Attack is a malicious attempt to make a system, network, or service unavailable to legitimate users by overwhelming it with traffic, exploiting resource exhaustion vulnerabilities, or corrupting configuration. A Distributed DoS (DDoS) uses multiple compromised systems (botnet) to amplify the attack volume beyond what a single source can generate.
On the CEH v13 exam: DoS/DDoS is CEH v13 Module 10. The exam tests understanding of all three attack categories (volume, protocol, application), specific named attacks (SYN flood mechanics with half-open connections, amplification factors for DNS/NTP/memcached), and mitigation strategies including rate limiting, connection pooling, DDoS scrubbing services (Cloudflare, Akamai), SYN cookies, and BGP flow specifications. Questions may present packet captures or attack logs for classification.
Integrating security into DevOps pipeline. Shift-left security: SAST/DAST scanning in CI/CD, infrastructure as code security, automated compliance checks, container image signing.
Creating a massive number of DHCP requests to exhaust the available IP pool. Combined with a rogue DHCP server, allows Man-in-the-Middle attacks on switched networks.
A model for describing cyber intrusions with four core components: Adversary (WHO), Capability (WHAT), Infrastructure (WHERE), Victim (WHO TARGETED). Used to analyze and compare intrusion events.
Password cracking method using a pre-compiled word list to guess passwords. Significantly faster than brute-force for dictionary-based passwords. Tools: Hydra, Hashcat, John the Ripper.
Method of securely exchanging cryptographic keys over public channel. Allows two parties to jointly agree upon shared secret key without prior shared secrets. Based on discrete logarithm problem.
Mathematical scheme verifying authenticity and integrity of digital messages. Uses asymmetric cryptography — sender encrypts hash with private key, receiver decrypts with public key.
Hiding data within images, audio, or video files. Tools: OpenStego, StegoOnline, DeepSound. Used by attackers to hide C2 communications and exfiltrated data.
Directory Traversal (Path Traversal) is a vulnerability that allows an attacker to access files and directories outside the intended web root directory by manipulating file path parameters with sequences like ../ (Unix) or ..\ (Windows). When exploited for reading sensitive files, it is also called Local File Inclusion (LFI). Remote variants where the server fetches external resources are called Remote File Inclusion (RFI).
On the CEH v13 exam: Directory traversal is covered in CEH v13 Module 14 (Hacking Web Applications). The exam tests understanding of path resolution mechanisms on Linux vs Windows, how web servers handle relative vs absolute paths, null byte handling differences across OS versions, WAF bypass techniques (encoding, case manipulation, null bytes), prevention strategies (canonicalizing paths, using allowlists for accessible files, running as unprivileged user, disabling RFI in PHP configuration), and identifying vulnerable parameters in application code. Questions may present file path strings for traversal attempt identification.
Analysis of disk images to recover deleted files, examine file system metadata, identify timestamps (MACBT), and detect tampering. Tools: Autopsy, FTK, EnCase.
Inserting malicious DLL into another process's address space to execute code within its context. Used for privilege escalation, persistence, and evasion.
Placing malicious DLL in application library path on Windows, or dynamic library on macOS. Tool: Spartacus (Windows), Dylib Hijack Scanner (macOS). Exploits application loading order.
Technologies and policies to detect and prevent unauthorized data exfiltration. Monitors email, web uploads, USB transfers, network traffic for sensitive data patterns.
Type of volumetric amplification attack. Attacker sends DNS queries with spoofed source IP (victim) to open DNS resolvers. DNS response is much larger than query (28x+ amplification). Mitigation: BCP38/BCP84, disable open resolvers.
Types of DNS records: A (IPv4 address), AAAA (IPv6 address), MX (mail exchange), NS (name server), CNAME (alias), SOA (start of authority), SRV (service record), PTR (reverse lookup), RP (responsible person), HINFO (host info), TXT (text data for DKIM/SPF).
Encode data in DNS queries to bypass firewalls. Domain: encoded-data.evil.com. DNS server acts as relay for exfiltrated/stolen data. Tools: iodine, dnscat2, dns2tcp.
A DNS protocol mechanism (type 256) that copies an entire zone file from primary to secondary servers. If misconfigured, attackers can harvest all subdomains and internal hostnames using dig axfr or nslookup.
Registering domain similar to legitimate one: missing letter (microsof.com), double letter (companny.com), extra TLD (company.com.co). Used in phishing emails and fake login pages.
Searching through discarded materials (paper documents, storage media) to find sensitive information such as credentials, network diagrams, or business plans. A common OSINT technique.
Listening to unauthorized conversations to gather sensitive information. Can be performed in person near office spaces or via network sniffing of unencrypted communications.
Security solution monitoring and responding to threats on endpoints (computers, servers, mobile). Provides continuous visibility, behavioral analysis, threat hunting, and automated response capabilities.
Uses database error messages to extract schema information. When injection causes SQL syntax errors, the error message reveals table names, column names, or data types.
The authorized practice of circumventing computer systems to identify potential security breaches. Ethical hackers use the same tools and techniques as malicious hackers but with permission and for defensive purposes.
Disabling auditing, clearing logs (Metasploit meterpreter), manipulating logs, covering tracks on network/OS, deleting files, hiding artifacts, disabling Windows functionality. Using cipher.exe to securely delete files.
Stateless (filters packets based on rules), Stateful (tracks connection state), Application-layer/Next-Gen (inspects content), WAF (web-specific), NGFW (integrates IPS, application control, threat intelligence).
Tool to find metadata and hidden information in scanned documents. Extracts author names, company info, timestamps, hidden comments, tracked changes, network paths, usernames from Office documents and PDFs.
Property where compromise of long-term keys does not compromise past session keys. Implemented via ECDHE (Elliptic Curve Diffie-Hellman Key Exchange). Ensures past communications remain secure.
FREAK (Factoring RSA Export Keys): Forces downgrade to weak export-grade crypto. Forbidden Attack: MITM exploiting reuse of cryptographic nonce during TLS handshake. AES-GCM cipher exploitation.
Forge Ticket Granting Ticket (TGT) by compromising KRBTGT account password hash. Grants access to ANY service in the domain indefinitely. Tool: Mimikatz.
Special operators used to find sensitive information exposed on the web. Key operators: cache:, link:, related:, info, site:, allintitle:, intitle:, allinurl:, inurl:, location:. Database at Google Hacking Database (GHDB).
A threat actor who conducts cyberattacks for political, social, or ideological causes, targeting organizations to draw attention to their agenda through defacement, data leaks, or denial of service.
Floods free space of process memory by writing multiple copies of malicious code. Used with buffer overflow exploits to increase chance of code execution.
Combines cryptographic hash function with secret key to provide both integrity and authentication. Used in IPsec, TLS, and API authentication.
Production Honeypot (used by organizations for defense), Research Honeypot (used for security research), Threat Intelligence Honeypot (collects attacker TTPs). Low interaction vs High interaction.
Application-layer DDoS attack sending大量 HTTP GET requests to overwhelm web server resources. Targets specific URLs that require database queries or expensive processing.
Exploiting differences in how front-end and back-end servers interpret HTTP request boundaries to send malicious requests that bypass security controls or gain unauthorized access.
Framework for managing digital identities and their access to resources. Includes authentication, authorization, provisioning, deprovisioning, and access review processes.
Network layer protocol used for diagnostics and error reporting. Types: Type 0 (Echo Reply), Type 3 (Destination Unreachable), Type 8 (Echo Request/ping), Type 11 (Time Exceeded/traceroute). Used in ping sweeps and host discovery.
Fragmentation, Junk Data Injection, Timing Manipulation, Decoy Scanning (Nmap -D), OS Fingerprint Evasion, Packet Reordering, TCP Wrapping.
NIDS (Network-based): Monitors network traffic. HIDS (Host-based): Monitors system activity. Signature-based: Matches known patterns. Anomaly-based: Detects deviations from baseline behavior.
Collection of Python classes for working with network protocols. Tools: secretsdump.py (LSASS/SAM/NTDS), psexec.py, wmiexec.py, atexec.py, smbexec.py — essential for AD penetration testing.
Pretending to be a legitimate or authorized person, often wearing uniforms, using fake IDs, or spoofing phone numbers and email addresses to gain access to restricted areas or information.
A structured approach to handling and managing security breaches. Phases: Preparation, Recording and Assignment, Triage, Notification, Containment, Evidence Gathering, Eradication, Recovery, Post-Incident Activity.
A framework for ensuring information security. Process: Plan → Design → Find Problems → Get Resources → Plan Fixes → Apply Controls → Verify → Train People. Covers all aspects of information handling and protection.
The five core pillars: Confidentiality, Integrity, Availability, Authenticity (ensuring files, communications, and identities are genuine), and Non-repudiation (guaranteeing a sender cannot deny sending a message).
Exploiting unsafe deserialization of user-supplied data to execute arbitrary code, cause DoS, or bypass authentication. Common in Java, PHP, Python, Ruby applications.
A security risk originating from within the organization by trusted users with legitimate access who carry out attacks from inside the network perimeter. Can be malicious or accidental.
Jailbreaking removes Apple restrictions exposing system files. Insecure data storage (Keychain misuse), backup encryption disabled, SSL pinning bypass, ClassKit/Handoff vulnerabilities, iMessage exploit vectors.
Extract firmware from flash chip for offline analysis. Tools: binwalk, firmware-mod-kit, QEMU. Look for hardcoded credentials, backdoors, update mechanisms, serial console access.
MQTT (pub/sub telemetry), CoAP (constrained HTTP-like), Zigbee (low-power mesh), Z-Wave (home automation), BLE (short-range), LoRaWAN (long-range low-power).
Physical access (UART/USB serial console), firmware extraction (binwalk), hardware analysis (logic analyzer), network protocol testing, API security assessment, mobile app reverse engineering.
The process of mapping IP addresses to physical locations including country, region, city, latitude/longitude. Tools like IP2Location provide geographic data associated with an IP address.
Exploit blind spots, use encryption to hide payload, slow down attacks to stay below thresholds, fragment traffic across multiple sessions, target application-layer vulnerabilities not covered by IPS signatures.
Request service ticket for any service account (SPN), extract encrypted TGS offline and crack for password. Works against any domain-joined user. Tool: Rubeus, Impacket.
Secret key cryptography authentication protocol. Components: KDC, AS (Authentication Server), TGS (Ticket Granting Server). Process: Login → Request ticket → Receive TGT → Request service access → Receive Service Ticket → Access service.
A Keylogger (keystroke logger) is a surveillance technology that records every keystroke made on a computer or device, along with additional data such as clicked URLs, captured screens, and sent email content. Keyloggers can be hardware-based (physical device between keyboard and motherboard) or software-based (malware or monitoring application), and are used for both legitimate enterprise monitoring and malicious credential theft.
On the CEH v13 exam: Keyloggers are referenced throughout CEH v13, particularly in Module 07 (Malware) and Module 09 (Social Engineering context). The exam tests understanding of keylogger implementation mechanisms (API hooking vs driver-level vs hardware), how they differ from screen capture and clipboard monitoring, detection methods (endpoint monitoring for anomalous process injection, hardware inspection for physical devices, network traffic analysis for C2 beaconing of logged data), prevention (USB port control, endpoint detection and response, user education on hardware inspection), and legal/ethical considerations for deployment in enterprise environments.
Lightweight Directory Access Protocol — extract user lists, group memberships, organizational structure. Ports: 389 (unencrypted), 636 (LDAPS). Tools: ldapsearch, Quest ActiveRoles Server.
Rules of engagement, written authorization requirements, scope boundaries, reporting obligations, data privacy laws (GDPR, CCPA), Computer Fraud and Abuse Act (CFAA), professional codes of conduct.
Collecting volatile evidence from running systems: memory dumps, network connections, running processes, open files, logged-in users. Performed before powering down to preserve time-sensitive data.
Using built-in OS tools (PowerShell, WMI, PsExec, rundll32) for attack operations instead of custom malware. Evades signature-based detection by using legitimate binaries.
Windows name resolution methods for hosts on same link. Attacker spoofs responses to intercept authentication. Tool: Responder detects and performs poisoning. Detection tools: Vindicate, got-responded.
Malicious code triggered by specific conditions (date, event, password). Lies dormant until trigger condition is met. Often used by disgruntled employees with insider access.
LOIC (Low Orbit Ion Cannon): Basic traffic flood tool for DoS testing. HOIC (High Orbit Ion Cannon): Enhanced LOIC with presets and multiple attack profiles. Both used for educational/lab purposes.
Flood switch CAM table with thousands of fake MAC addresses. When table overflows, switch enters 'fail-open' mode and behaves like a hub, broadcasting all traffic. Enables sniffing on previously switched networks.
Visual link analysis tool for open-source intelligence and forensics. Visualizes relationships between people, domains, IPs, URLs, social media accounts, companies, DNS records, and infrastructure.
Malware (malicious software) is any software intentionally designed to cause harm to a computer, server, or network. It encompasses a broad range of threat types including viruses, worms, trojans, ransomware, rootkits, spyware, adware, and logic bombs. Modern malware frequently combines multiple capabilities (polymorphic engines, anti-analysis, fileless techniques) to evade detection and maintain persistence.
On the CEH v13 exam: Malware is CEH v13 Module 07 and one of the highest-weighted modules. The exam tests knowledge of all malware types with emphasis on distinguishing characteristics, the malware lifecycle (delivery → execution → persistence → C2 → exfiltration), detection methods (signature-based, behavioral/heuristic, sandboxing, memory analysis), removal procedures, modern evasion techniques (fileless malware using PowerShell/Live, process hollowing, DLL sideloading, AMSI bypass), APT-specific malware families, and ransomware incident response. Questions may present malware descriptions or screenshots for classification.
Static Analysis (examining code without running it — disassembly, strings extraction, header analysis) and Dynamic Analysis (running malware in controlled environment/sandbox — network traffic observation, file modification tracking, registry changes monitoring).
Static: IDA Pro, Ghidra, PEiD, strings, exiftool. Dynamic: Cuckoo Sandbox, ANY.RUN, Joe Sandbox. Debuggers: OllyDbg, x64dbg, GDB. Network: Wireshark, TCPView. System: Process Monitor, Process Explorer, API Monitor. Memory: Volatility.
Trojan infects computer, installs malicious code that loads after browser restart. Handler registered for every webpage visit. Extension matches URL with known targeted sites, extracts DOM field values, and modifies them before sending to server.
A Man-in-the-Middle (MitM) Attack is a technique where an attacker secretly intercepts and potentially alters communication between two parties who believe they are directly communicating with each other. The attacker positions themselves between the communicating endpoints to eavesdrop, modify, or inject data without detection.
On the CEH v13 exam: MitM attacks are covered in CEH v13 Modules 08 (Sniffing and Traffic Analysis) and 11 (Session Hijacking). The exam tests knowledge of Layer 2-7 interception techniques, how to detect MitM (certificate pinning, HSTS, network monitoring), the mechanics of ARP cache poisoning, DNS hijacking variants, and TLS-specific attacks (BEAST, POODLE as enablers). Questions often present network topology diagrams for attack feasibility assessment.
Internet-scale port scanner capable of scanning all 65535 ports in under a minute. Sends SYN packets at extremely high rates. Can scan the entire internet in under 6 hours.
Spectre: Found in AMD, Apple, ARM, Intel. Tricks speculative execution to read restricted data. Meltdown: All ARM and Intel CPUs. Tricks processors into accessing out-of-bounds memory.
Most powerful DNS-like amplification attack. Open Memcached servers can achieve up to 51,000x amplification factor when queried with ANY command and spoofed source IP.
Analysis of volatile RAM content to find malware artifacts, encryption keys, network connections, and running processes not visible through normal means. Tool: Volatility framework.
Rewrites its entire code structure each time it infects a system, performing the same function with completely different code. More advanced than polymorphic — changes both signature AND behavior patterns.
Module types: Exploit (configure active exploit), Payload (establishes communication — singles, stagers, stages), Auxiliary (one-time actions like scanning), NOPs (generate no-op instructions), Encoder (hide payloads), Evasion (modify behavior to avoid detection), Post-exploitation (interact after compromise).
IoT botnet that infected millions of devices (cameras, routers) scanning for default credentials on Telnet/SSH. Used for massive DDoS attacks (Dyn DNS attack: 1Tbps+). Source code leaked in 2016.
A knowledge base of adversary tactics and techniques based on real-world observations. Structure: Tactics (WHY hacker acts), Techniques (HOW they achieve goals), Subtechniques, Procedures. Contains 14+ tactics across Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact.
System for managing mobile devices in enterprise: Remote wipe, enforce encryption and password policies, app whitelisting/blacklisting, VPN configuration, certificate management, jailbreak/root detection.
Recovery of digital evidence from mobile devices. Covers physical extraction (bit-for-bit), logical extraction (file system), and file-based methods. Tools: Cellebrite, Oxygen Forensics.
Trojans (appear legitimate), Spyware (track location, contacts), Ransomware (lock device), Adware (inject ads), Rootkits (gain root access), Banking Trojans (intercept transactions).
Requiring two or more independent credentials for authentication: something you know (password), something you have (token/phone), something you are (biometric). Significantly reduces credential theft impact.
Privilege escalation technique using Windows named pipes for process impersonation. Metasploit module available for exploitation.
Industry-standard vulnerability scanner with extensive plugin library. Identifies vulnerabilities, misconfigurations, compliance violations. Commercial product with free personal edition.
Enumerate computer names, user names, domains via NetBIOS Session Service (port 139) and Name Service (ports 137/138). Tools: nbtscan, enum4linux, rpcclient.
Network statistics tool. Commands: netstat -an (all connections and listening ports), netstat -b (executable tied to each port), netstat -n (numeric only, no DNS resolution). Shows TCP connection states: ESTABLISHED, SYN_SENT, FIN_WAIT, CLOSE_WAIT, TIME_WAIT, LISTEN.
Network Enumeration is the process of extracting detailed information about a network's resources, including usernames, machine names, network shares, group memberships, service versions, and configuration details. It follows initial scanning and provides the attacker with specific targets for exploitation — essentially converting "open ports" into "known vulnerabilities with specific exploit targets."
On the CEH v13 exam: Enumeration is CEH v13 Module 04. The exam tests knowledge of each protocol's enumeration methods, specific commands and tools, how to interpret enumeration output for attack planning, and defensive countermeasures (restricting SMB anonymous access, hardening LDAP with TLS and bind requirements, changing SNMP community strings or migrating to SNMPv3, disabling NetBIOS where not needed). Questions often present enumeration output for analysis — identifying exploitable findings from the data.
Capture and analysis of network traffic for investigation. Uses packet captures (PCAP), NetFlow data, and firewall logs to reconstruct attack timeline and identify indicators of compromise.
Dividing network into smaller subnets to limit lateral movement during a breach. Reduces attack surface and contains compromise within specific zones.
Network Information Service enumeration for Unix systems. Retrieves passwd/group database entries via UDP 751.
A guide to information technology security testing published by NIST that provides guidelines for conducting security testing including planning, testing, and documentation phases.
-O flag enables OS detection by analyzing TCP/IP stack fingerprints. Analyzes TCP Initial TTL values, window size, IP ID sequence generation, TCP options ordering. Compares responses against nmap-os-db database.
Multiple scanning techniques in Nmap: SYN Scan (-sS), Connect Scan (-sT), UDP Scan (-sU), XMAS Scan (-sX), NULL Scan (-sN), FIN Scan (-sF), ACK Scan (-sA), Idle Scan (-sI). Each type has different stealth and detection characteristics.
-sI option uses an idle 'zombie' host to scan the target, making the scan appear to come from the zombie. Requires an idle zombie with predictable IP ID sequence and no communication during scan.
Hidden data streams within files on NTFS filesystem. Attackers hide malicious content in alternate streams. Tools: StreamArmor, GMER, ADS Scanner.
NT LAN Manager — default Windows authentication scheme using challenge-response. Process: Client requests access → Server sends challenge → Client computes response → Server verifies (AD or SAM). NTLMv2 is reasonably secure but weaker than Kerberos.
Web vulnerability where application redirects users to a URL derived from user input without proper validation, enabling phishing attacks that appear to originate from trusted domain.
Open-source alternative to Nessus. Full-featured vulnerability scanner with regular feed updates. Part of Greenbone network.
Collection of open-source intelligence tools organized by category. Covers reconnaissance, domain research, IP address research, social media investigation, and more.
Open Source Security Testing Methodology Manual. A free and open framework for security testing that provides standardized metrics and measurements for penetration testing.
Safety-first approach to industrial control systems. Network segmentation (Purdue Model), passive monitoring, disable unnecessary services, physical security, incident response plans for OT environments.
Uses different channel to exfiltrate data — DNS lookups or HTTP requests from the database server. Requires specific DB configuration but works when in-band methods fail.
Split malicious payload into smaller fragments. Each fragment individually appears harmless. IDS may not reassemble before inspection. Target system reassembles and executes the payload. Nmap: -f flag.
Injecting compromised hash into local session to authenticate to network resources without cracking password to plaintext. Uses logged-in user hash to log into domain controller.
Gathering information about a target without directly interacting with their systems. Examples: searching search engines, checking social media, WHOIS lookups, public records, company websites. Leaves no trace on target infrastructure.
Only observe and record traffic, capture IDs/passwords without disturbing the session. Uses packet sniffers to intercept unencrypted session tokens.
Methods to extract credentials: dumping from memory, stealing SAM database, stealing AD file ntds.dit, extracting SYSKEY boot key, intercepting credentials on network. Tools: pwdump7, Mimikatz, DSinternals.
Targets multiple accounts simultaneously with the same common password to avoid account lockout that single-password brute force would trigger. Example: Try 'Password123' against all user accounts.
Structured methodology for authorized simulated cyberattacks. Phases: Preparation (define scope, rules of engagement), Assessment (actual penetration testing including reconnaissance, scanning, exploitation), Conclusion (report preparation, findings documentation, recommendations).
Documenting findings with executive summary, technical details, risk ratings, evidence (screenshots), and remediation recommendations. Key to demonstrating value to stakeholders.
Redirecting traffic to fake websites via DNS poisoning or manipulating hosts file. Users visit legitimate sites but are directed to fraudulent lookalike sites.
A Phishing Attack is a social engineering technique where an attacker disguises themselves as a trusted entity (via email, SMS, phone, or other communication channels) to trick victims into revealing sensitive information such as credentials, financial data, or personally identifiable information (PII). It is the most common initial vector for cyberattacks.
On the CEH v13 exam: Phishing is covered extensively in CEH v13 Module 09 (Social Engineering). The exam tests knowledge of all phishing variants, the difference between phishing and pretexting, email header analysis for spoofing detection, user education strategies, technical countermeasures (SPF, DKIM, DMARC), and how to design and evaluate a corporate phishing simulation program. Expect multiple questions covering both offensive and defensive perspectives.
Sends malformed or oversized ICMP packets (>65,535 bytes). Target system crashes trying to reassemble fragmented packets. Mostly patched in modern systems but still relevant for legacy/IoT.
Method to find active machines on a network by sending ICMP Echo Requests. Tools: Angry IP Scanner, Superscan, Nmap (-sn), Advanced IP Scanner, PingPlotter.
Targets WPA2-Personal networks. Captures PMKID from first handshake message. Faster than full handshake capture. Tool: aircrack-ng with hashcat. Requires station connected to AP or known SSID.
Changes its code signature each time it replicates while keeping the original algorithm intact. Uses mutation engines to evade signature-based AV detection. Different from Metamorphic which rewrites entire code structure.
Well Known Ports: 0-1023 (reserved), Registered Ports: 1024-49151 (assigned), Dynamic/Private Ports: 49152-65535 (temporary). Common ports: 21/FTP, 22/SSH, 23/Telnet, 25/SMTP, 53/DNS, 80/HTTP, 443/HTTPS, 445/SMB, 3389/RDP.
Port Scanning is a network reconnaissance technique used to identify open ports, running services, and their versions on a target system by sending crafted packets to specific port numbers and analyzing responses. It is one of the first steps in any penetration test or cyberattack, providing the attacker with an attack surface map.
On the CEH v13 exam: Port scanning is the foundation of CEH v13 Module 03 (Scanning Networks). The exam tests understanding of TCP/IP packet flag behavior for each scan type, when to use stealth scans vs connect scans, Nmap command syntax and options (-sS, -sT, -sU, -sF, -sN, -sX, -A, -p, --top-ports), detection via IDS signatures (Suricata/Snort rules for SYN floods on non-standard ports), and evasion techniques (fragmentation, decoys, timing adjustments, OS fingerprinting). Questions may present packet captures for scan type identification.
Living-off-the-land technique using PowerShell for fileless malware, credential theft, lateral movement. Techniques: -encodedcommand, IEX (Invoke-Expression), IWR (Invoke-WebRequest), AMSI bypass.
Sequential tokens (easily predictable), timestamp-based tokens, small token space (brute force possible), weak RNG algorithms, lack of rate limiting allows rapid guessing.
Social engineering methodology: Positioning (establish credibility and role), Rapport (build trust and connection), Extraction (gather information gradually), Prestige (make target feel honored to help).
Creating a fabricated scenario (pretext) to engage the victim and extract information. The attacker researches the target beforehand to create a believable story, often impersonating IT support, bank representative, or law enforcement.
Privilege Escalation is the process of exploiting software vulnerabilities, misconfigurations, or logic flaws to gain higher-level permissions on a system. Vertical escalation (vertical) moves from low-privilege user to root/administrator. Horizontal escalation moves between users at the same privilege level.
On the CEH v13 exam: Privilege escalation is a core topic in CEH v13 Module 06. The exam tests knowledge of both Linux and Windows escalation paths, specific misconfigurations to check (world-writable files, SUID binaries, scheduled tasks), kernel exploit mechanics, Active Directory-based escalation (Kerberoasting, Pass-the-Hash escalation), and post-exploitation enumeration techniques. Questions frequently present system configurations for vulnerability identification.
Technique where a running process is suspended, its memory is unmapped, and replaced with malicious code. The original process resumes execution but runs attacker-controlled payload.
Principles exploited in social engineering: Authority (people obey figures of authority), Scarcity (limited availability creates urgency), Urgency (time pressure prevents rational thinking), Familiarity/Liking, Consistency, Reciprocity.
Penetration Testing Execution Standard. Provides a comprehensive taxonomy including pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
System for managing digital certificates and public-key encryption. Components: Certificate Authority (CA), Registration Authority (RA), Digital Certificates, CRL, Certificate Revocation.
Collaborative approach combining red team (attack) and blue team (defense) in real-time to improve detection capabilities and security posture through continuous feedback.
QR codes used as attack vector in phishing. Directs victim to malicious URLs without showing URL until after scan. Bypasses email security filters that cannot scan QR codes.
Cloud-based vulnerability management solution. Provides continuous monitoring, compliance scanning, and asset discovery without requiring on-premise hardware.
Quantum computers could break RSA and ECC encryption. Shor's algorithm factors large numbers efficiently. NIST standardizing post-quantum cryptography (lattice-based, hash-based, code-based). Timeline: 10-30 years.
A social engineering technique where the attacker promises a benefit in exchange for information ("I'll fix your computer if you share your admin password"). Derived from Latin meaning "something for something."
A Rainbow Table Attack is a password cracking technique that uses precomputed tables of hash values to reverse common passwords significantly faster than brute-force or dictionary attacks. Each table maps a chain of plaintext → hash → transformation → plaintext → hash sequences, allowing rapid lookup of a target hash by finding its matching position in the chain and working backwards.
On the CEH v13 exam: Rainbow tables are covered in CEH v13 Module 06 (System Hacking) in the context of password attacks and credential recovery. The exam tests understanding of how hash chains work, why salting defeats rainbow tables (each salt requires separate table), the difference between LM and NTLM hashing (LM splits password into two 7-char halves, making it weaker), modern password storage best practices (bcrypt/scrypt/Argon2 with high cost factors), and how to identify which hashing algorithm was used from stored hash format. Questions may present hash values for algorithm identification.
Crypto-ransomware (encrypts files), Locker-ransomware (locks device/screen), Double Extortion (steals data THEN encrypts, threatens to leak). Examples: WannaCry, Ryuk, LockBit, BlackCat/ALPHV.
Enterprise vulnerability management platform providing comprehensive scanning, risk-based prioritization, and remediation guidance.
Web-based reconnaissance framework (open-source, modular) for gathering information from public sources. Features modules for WHOIS, DNS, Google hacking, Shodan integration, and more.
All-in-one reconnaissance tool providing DNS lookup, whois information, port scanning, and more. Usage: recondog footprint, recondog scanner.
Pen test: Find and report vulnerabilities within scope. Red team: Simulate real adversary TTPs to test detection and response. Broader, more stealthy, objectives-based rather than vulnerability-focused.
Organizations managing IP address allocation by region: ARIN (Americas), AFRINIC (Africa), APNIC (Asia-Pacific), RIPE NCC (Europe/Middle East/Central Asia), LACNIC (Latin America/Caribbean).
Methods for executing code remotely: Web-browser exploitation (spear phishing), Office-application exploitation, WMI (Windows Management Instrumentation), WinRM (Windows Remote Management). Tools: Dameware, Ninja, Pupy, PsExec.
LLMNR/NBT-NS/mDNS poisoner and credential harvester. Captures Windows name resolution requests and returns malicious responses, harvesting NTLM hashes from the network.
Process of privately notifying vendor of vulnerability before public disclosure, allowing time for patch development. Timeline: 90 days initial, 180 days max before public release.
Reusing code snippets already existing in the binary, usually in libc or kernel32.dll. Chains small code 'gadgets' ending in RET instruction to build arbitrary execution. Defeats DEP/NX protections.
The process of identifying, estimating, and prioritizing threats to information assets. Formula: Risk = Threats × Vulnerabilities × Impact. Key metrics include ARO (Annual Rate of Occurrence), SLE (Single Loss Expectancy), and ALE (Annualized Loss Expectancy = SLE × ARO).
Four approaches: Mitigation (reduce risk), Transfer (insurance/outsourcing), Accept (tolerate residual risk), Avoid (eliminate activity causing risk).
Unauthorized AP connected to secure network. Can be installed by employees without IT knowledge providing backdoor for attackers. Detection: Wireless intrusion detection systems (WIDS). Prevention: Network access control policies.
Detection methods: Integrity-based detection (Tripwire, AIDE baseline), analyzing memory dumps, comparing process lists (rootkit vs OS view). Anti-Rootkit tools: GMER (SirMed), Stinger, TDSSKiller, Avast One.
Sending TCP RST packets to established connections to forcibly terminate them. Can disrupt legitimate communications and cause application-level denial of service.
Written agreement defining scope, timing, techniques allowed, target systems, communication procedures, and emergency contacts for a penetration test. Protects both tester and client.
Legacy systems not designed for connectivity, proprietary protocols with weak authentication, long lifecycle without updates, physical safety implications. Common targets: power grids, water treatment, manufacturing.
Modbus (no authentication), DNP3 (utilities), BACnet (building automation), PROFINET (industrial Ethernet), OPC UA (more secure), S7comm (Siemens PLC).
An inexperienced attacker who uses pre-made exploit tools, scripts, or automated attack tools without understanding the underlying concepts, often causing more disruption than damage.
Standards and frameworks for organizational security: ISO 27001, NIST CSF, PCI DSS, HIPAA, SOC 2, GDPR, COBIT. Provide structured approach to managing security risks.
Attacker logs into shared session, victim clicks link, victim authenticates attacker's session, attacker gains victim's data. Prevention: Bind session to user/IP/device.
Attacker sets session ID in advance (via link, cookie). Victim logs in using attacker-known session ID. Prevention: Regenerate session ID after login.
Search engine for internet-connected devices. Indexes banners from all connected devices including webcams, routers, servers, IoT devices. Used for discovering exposed services and vulnerabilities.
A physical social engineering technique observing a target's screen, keyboard, or password entry by standing nearby. Can be performed in person or via surveillance cameras.
Centralized platform for collecting, analyzing, and correlating security logs and events from multiple sources. Enables real-time threat detection, compliance reporting, and incident response.
Steal user credentials and create fake Service Ticket (TGS, not TGT). Grants access to a specific service, not entire domain. Tool: Mimikatz.
Application Layer (Layer 7) attack opening multiple connections to web server and keeping them open. Sends partial HTTP requests with slow intervals. Uses very little bandwidth, hard to detect.
Fake text messages with malicious links. Mobile-optimized phishing using SMS as the delivery vector. Often includes urgency to prompt immediate action.
Using SMTP VRFY, EXPN, or RCPT TO commands to verify email addresses and enumerate users. Tools: smtp-user-enum, Nmap scripts (smtp-enum), Swaks.
Sends ICMP echo requests (pings) to broadcast addresses with spoofed source IP of victim. All hosts on network reply to victim simultaneously, overwhelming it with traffic.
Using community strings to extract system info, interface stats, routing tables, connected devices. Common defaults: 'public' (read-only), 'private' (read-write). Tools: snmpwalk, snmpget, Net-SNMP.
Social Engineering is the art of manipulating people into performing actions or disclosing confidential information through psychological manipulation rather than technical exploitation. It exploits human traits such as trust, curiosity, fear, urgency, and willingness to help. Social engineering is considered the weakest link in organizational security because it bypasses all technical controls by targeting the human element directly.
On the CEH v13 exam: Social Engineering is CEH v13 Module 09 and one of the highest-weighted modules. The exam tests all major SE techniques with emphasis on distinguishing between them, understanding the psychology behind each (Cialdini's principles: reciprocity, commitment, social proof, authority, liking, scarcity, unity), designing penetration test social engineering assessments, legal/ethical boundaries, and organizational countermeasures (training programs, verification procedures, security awareness). Expect 10+ questions across the exam touching SE concepts.
Gathering information from social media platforms for OSINT. LinkedIn reveals organizational structure and employee roles. Facebook/Twitter reveal personal details used in spear phishing.
Targeted phishing attack directed at specific individual or organization. Uses personalized information gathered through reconnaissance to make the attack more convincing and effective.
SQL Injection (SQLi) is a code injection technique that exploits vulnerabilities in an application's database interface by inserting or "injecting" malicious SQL statements into input fields. When successfully exploited, it can manipulate the database to disclose, alter, or delete data, and in some cases execute administrative commands on the database server.
On the CEH v13 exam: SQL Injection is explicitly covered as CEH v13 Module 15 and appears throughout the exam. Questions test knowledge of attack vectors, detection via input validation analysis, prevention strategies (parameterized queries, stored procedures, WAF rules), and the specific behaviors of different SQLi types. Expect at least 5-7 questions directly addressing SQLi concepts.
Automated SQL injection tool. Commands: sqlmap -u "url?id=1" --dbs (list databases), -D dbname --tables (list tables), -T tbl --dump (dump data), --os-shell (OS shell), --passwords (extract passwords).
Downgrades HTTPS connections to HTTP before TLS negotiation begins, enabling plaintext interception. Tool by Moxie Marlinspike. Exploits the transition period before application redirects to secure version.
Attacker induces the server to make HTTP requests to an arbitrary domain of their choosing. Can be used to access internal resources, cloud metadata services, or scan internal networks.
A government-backed adversary conducting sophisticated cyber operations for intelligence gathering, strategic disruption, or economic espionage. Resources and sophistication far exceed criminal groups.
Hiding secret data within non-secret files (images, audio, video). Unlike cryptography which hides content, steganography hides the existence of the message itself.
A threat categorization model: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege. Used during threat modeling to systematically identify potential threats.
Discovered in 2010, targeted Iranian nuclear facilities. Specifically attacked Siemens SCADA systems to disrupt centrifuge operations. Used multiple zero-day exploits. First cyberweapon targeting physical infrastructure.
Fast subdomain discovery tool using passive online sources. Finds subdomains belonging to target domains for attack surface mapping and reconnaissance.
Same key for encryption and decryption. Algorithms: AES (128/192/256-bit), DES (broken), 3DES, RC4 (broken), Blowfish, Twofish, ChaCha20. Faster than asymmetric but key distribution is challenging.
Exploits TCP three-way handshake by sending many SYN requests but never completing with SYN-ACK. Target's connection table fills up with half-open connections, preventing legitimate connections. Mitigation: SYN cookies.
A physical social engineering attack where an unauthorized person follows an authorized person into a restricted area without independent authentication. Also called piggybacking.
A connection-oriented transport layer protocol providing guaranteed delivery, ordered packets, error checking, and flow control. Uses three-way handshake (SYN, SYN/ACK, ACK) to establish connections.
Connection lifecycle states: ESTABLISHED (active), SYN_SENT (request sent), SYN_RECEIVED (waiting for response), FIN_WAIT_1/2 (waiting for close), CLOSE_WAIT (remote closed), TIME_WAIT (local closed, waiting ACK), LISTEN (accepting connections).
Control bits in TCP header: SYN (connection initiation), ACK (acknowledgment), RST (reset), FIN (finish/close), URG (urgent), PSH (push), NULL (none set), XMAS (FIN+URG+PSH all set). Used for connection management and scan detection.
Process to establish a TCP connection: 1) SYN — Client sends synchronization packet with random sequence number, 2) SYN/ACK — Server acknowledges and sends its own SYN, 3) ACK — Client acknowledges server's SYN, connection established.
Email and subdomain reconnaissance tool. Usage: theHarvester -d domain.com -l 200 -b linkedin. Collects emails, subdomains, hostnames from public sources including search engines, LinkedIn, PGP key servers.
Process of identifying what can go wrong, how systems can be attacked, and how to mitigate risks. Steps: Identify assets, Create attack trees, Identify threats (STRIDE framework), Mitigate threats, Validate assumptions.
Using Windows access tokens to impersonate other users or system accounts. Enables lateral movement without credentials. Tool: Meterpreter (steal/tokn impersonate).
Analyzing network traffic patterns WITHOUT reading content. Can reveal communication patterns, frequency, volume, parties involved. Useful even when traffic is encrypted. Tools: Wireshark statistics, Maltego, NetworkMiner.
Downloader Trojan (downloads additional malware), Dropper Trojan (deploys other malware), Backdoor Trojan (creates unauthorized access channel), DDoS Trojan (joins botnet), Banking Trojan (steals financial credentials), RAT (Remote Access Trojan — full remote control).
Methods to bypass User Account Control: FodHelper Registry, eventvwr Registry, COM handler hijacking, binary planting, registry permission abuse.
A connectionless transport layer protocol with no guaranteed delivery or ordering but faster with lower overhead. Used by TFTP, DNS, DHCP, and real-time applications.
Secure tunneling protocols: IPsec (network layer), SSL/TLS (application layer), OpenVPN (open-source), WireGuard (modern, lightweight), PPTP (deprecated), L2TP/IPsec (combined).
A tool that automatically identifies known vulnerabilities in systems, networks, or applications by comparing configurations and software versions against databases of known vulnerabilities (CVE). Examples: Nessus, OpenVAS, Qualys.
Filters, monitors, and blocks HTTP traffic between web application and internet. Protects against SQL injection, XSS, path traversal, and other OWASP Top 10 attacks.
Searching for wireless networks while moving through an area using laptop/phone with WiFi adapter and GPS. Tools: NetSpot, InSSIDer, Android WiFi Analyzer. Reveals open networks, WEP/WPA networks, hidden SSIDs.
Attack where attackers identify websites regularly visited by their target group and compromise those sites. When targets visit the compromised site, malware is delivered to them.
OWASP ZAP (open-source scanner), Burp Suite (manual testing toolkit), Acunetix (automated scanner), Nikto (server scanner), SQLmap (SQLi tool), Wfuzz (web fuzzer), Skipfish, Arachni.
X-Frame-Options (DENY/SAMEORIGIN), X-Content-Type-Options (nosniff), Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-XSS-Protection, Referrer-Policy. All essential for web security.
Remove default pages, disable directory listing, use strong SSL/TLS, keep software updated, restrict HTTP methods, implement WAF, use security headers (X-Frame-Options, CSP, HSTS), regular vulnerability scanning.
Spear phishing specifically targeting C-level executives and senior management. High-value targets with access to sensitive data and authority to authorize transactions.
An ethical security professional who tests systems and networks with explicit authorization to identify vulnerabilities and help organizations strengthen their defenses.
A protocol used to query databases for information about domain registration. Provides registrant contact details, registration dates, nameservers, and IP address allocations. Thick vs Thin WHOIS models.
Database storing hashed passwords for local user accounts. Location: %SystemRoot%\system32\config\SAM or registry HKEY_LOCAL_MACHINE\SAM. Cannot copy while Windows running. Stores LM or NTLM hashed passwords.
Aircrack-ng suite (monitor mode, capture, crack), Kismet (detector/sniffer), Reaver (WPS attack), Fern WiFi Cracker (GUI tool), Bully (WPS offline/online), Cowpatty (PMKID attacks).
Virus requires host file and human action to spread (opens attachment, runs program). Worm is standalone malware that self-replicates across networks WITHOUT user interaction. Worms spread faster but viruses can be more destructive.
WPA2 Cracking refers to the process of recovering the pre-shared key (PSK) or passphrase of a Wi-Fi network protected by WPA2-PSK encryption. The primary method involves capturing the 4-way handshake during client association, then performing offline dictionary or brute-force attacks against the captured handshake data using tools like Aircrack-ng.
On the CEH v13 exam: WPA2/WPA3 security is CEH v13 Module 16 (Attacking Wireless Networks). The exam tests understanding of the WPA2 4-way handshake process (ANonce, SNonce, PMK, PTK derivation), how deauthentication triggers reconnection and handshake, PMKID capture mechanics, WPS vulnerability specifics, WPA3 SAE improvements and remaining weaknesses, and enterprise wireless security (802.1X, RADIUS). Questions may present handshake captures for analysis or ask about specific attack feasibility given network conditions.
Exploits WPS 8-digit PIN with split authentication vulnerability (4+4 digits). ~11,000 attempts max. Tool: Reaver. Can recover PSK in hours.
Exploits XML parsers that process external entity declarations, enabling file read, SSRF, and data exfiltration through crafted XML input. OWASP Top 10 vulnerability.
Official graphical user interface for Nmap. Provides preset scan configurations, visualization of network topology, and comparison of scan results over time.
Security model assuming no user or system should be trusted by default, even if inside the network perimeter. Requires continuous verification of identity, device health, and access rights for every request.
A Zero-Day Vulnerability (0-day) is a software security flaw that is unknown to the vendor and for which no patch or mitigation exists. The term "zero-day" refers to the fact that the vendor has had zero days to fix the vulnerability since it was discovered by the attacker. Once publicly disclosed or patched, it becomes an N-day vulnerability (where N is the number of days between disclosure and exploitation in the wild).
On the CEH v13 exam: Zero-days are referenced throughout the CEH v13 exam, particularly in the context of APT operations (Module 07), vulnerability management (Module 05), and ethical considerations. The exam tests understanding of the difference between 0-day and N-day, the responsible disclosure process (identifying researcher, notifying vendor, providing reproduction steps, allowing remediation period), why zero-days are critical for APT groups, and defensive strategies when a 0-day is active (virtual patching via WAF/IPS, network segmentation, enhanced monitoring).