Skip to content
ScopefileGet the app

Module 6Domain 3 of 9System Hacking Phases and Attack Techniques

System hacking: from access to covering tracks

System hacking is CEH Module 6: the stretch of an intrusion between the first foothold on a host and the attempt to erase the evidence, covering password attacks, exploited flaws, privilege escalation, persistence, hidden data and log tampering. This file takes each one from the defender's side: what it depends on, what it leaves behind on the host, and what closes it.

Exam
312-50
Domain
3 of 9
Domain weight
15%
This file
~5%
Targets
17

What each stage depends on

Online password attack
Guessing against a live login service. It relies on logins with no throttling, no lockout and no second factor.
Offline password attack
Recovering passwords from stolen hash material on the attacker's own hardware, out of the defender's sight. It relies on short passwords and fast, unsalted hashing.
Vulnerability exploitation
Abusing a software flaw, such as memory corruption or a logic error, to run code the owner never approved. It relies on missing patches and on programs built without modern memory protections.
Vertical privilege escalation
Moving from a lower privilege level to a higher one, such as from a standard user to an administrator. It relies on over-broad permissions and unpatched local flaws.
Horizontal privilege escalation
Taking over another account at the same privilege level to reach that user's data. It relies on weak separation between accounts.
Maintaining access
Making a foothold survive a reboot, a password reset or a patch. It relies on configuration changes that nobody baselines or reviews.
Steganography
Hiding the existence of data inside an innocent carrier such as an image or audio file. It relies on inspection that never checks statistical oddities; steganalysis is the defender's discipline of detecting it.
Covering tracks
Deleting or altering logs, timestamps and other artifacts so the intrusion cannot be reconstructed. It relies on logs that live only on the host they describe.

Traces on the host, stage by stage

Each stage leaves a different trace. Place an observation in a stage before deciding what to do about it:

  • Many accounts failing a login once or twice from one source: an online attack spread thin to dodge lockout. One account hammered until it locks is plain brute force.
  • A clean login with no failures, from a new location at an odd hour: credentials obtained elsewhere, by an offline crack or a reused password.
  • A service that crashes, then a process nobody expected: exploitation of that service.
  • A standard account suddenly in an administrative group, or a user application spawning an elevated process: escalation.
  • Startup configuration that drifts from the baseline after an incident: persistence.
  • A cleared security log, a gap in record sequence, timestamps that contradict the volume's own records: covering tracks.
  • Media files with sizes out of proportion to their content, leaving through unusual channels: steganography.

Four close pairs, separated

  • Steganography vs encryption: steganography hides that a message exists; encryption hides what it says. They stack, so treat them as separate controls. The encryption side lives in the cryptography module.
  • Online vs offline cracking: an offline attack never touches the login service, so lockout does nothing against it. Salting, slow hashing and length raise its cost; the mechanics are on symmetric, asymmetric and hashing compared.
  • Vertical vs horizontal escalation: did the privilege level go up, or did the attacker only move into a peer's account?
  • Maintaining access vs covering tracks: persistence keeps the door open; covering tracks hides that it was ever opened.

Credentials and cleanup on an authorized test

The written agreement decides whether credential recovery is in scope and how recovered passwords are stored, reported and destroyed. Anything a tester adds to a host is documented and removed at cleanup, and client logs stay intact. Module 1 covers authorization in full.

Neighbors that feed this module

The flaws exploited here are the ones found in vulnerability analysis, and the five phases of ethical hacking shows where this module sits in the sequence. Keyloggers, spyware and rootkits appear in the v13 outline for this module, but their behavior is taught in Module 7 on malware threats: learn the names here and the mechanics there. The highest-yield single topic attached to this module is password attack types, every category with the defense that stops it.

Eight threats against their controls and traces

Threats in Module 6, the control that answers each, and the signal a defender watches
ThreatControl that closes itTrace to watch
Online password guessingMulti-factor authentication, throttling or lockout, screening against breached-password listsBursts of failed logins across accounts or from one source
Offline cracking of stolen hashesLong passphrases, salted and deliberately slow hashing, tight protection of credential storesReads of credential stores or their backups by unexpected processes
Exploited software flawPatch management, compiler and OS memory protections, disabling unneeded servicesService crashes followed by unexpected child processes
Privilege escalationLeast privilege, no standing admin rights, prompt patching of local flawsNew privileged group memberships, elevated processes from user apps
Unauthorized applications such as keyloggers and spywareApplication allowlisting and endpoint monitoringUnknown binaries starting from user-writable folders
PersistenceA configuration baseline with change monitoringDrift from the baseline on startup items
SteganographyData loss prevention plus steganalysis on outbound mediaCarrier files with odd sizes or statistics
Log clearing and timestamp tamperingForwarding logs to a central write-protected store, file integrity monitoringLog-cleared events, sequence gaps, contradictory timestamps

Detection and mitigation notes for each class: ATT&CK T1110 Brute Force, T1068 Exploitation for Privilege Escalation, T1027.003 Steganography, T1070 Indicator Removal.

Stage, trace, control

Some targets are pure vocabulary and some describe what a defender found on a host. For the second kind, decide the stage first; that alone rules out options from elsewhere in the intrusion.

Answered 0/17Hits 0

T-01

During a routine log triage, an EDR system flags an administrator account executing PsExec across multiple internal network segments. What must be confirmed first before declaring this event a definitive system compromise?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe number of hosts touched describes scope, but large or small, it does not tell you whether the activity was authorized.
  2. BPsExec is legitimately signed by Microsoft Sysinternals, so its signature says nothing about whether this use is malicious.
  3. CCorrect: administrators use PsExec routinely, so checking change tickets and scheduled maintenance first separates normal IT work from lateral movement.
  4. DEncoded PowerShell is a useful indicator but is secondary; it does not establish whether the activity was sanctioned.
T-02

An engagement provides an offline dump of thousands of NTLM hashes. You need to crack these as efficiently as possible within a limited timeframe. Which approach is the most optimal?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACPU brute force over a full character set is far slower than GPU attacks and impractical within a limited timeframe.
  2. BUsing a botnet is illegal and outside any authorized engagement, and building rainbow tables is slower than cracking directly.
  3. CCorrect: GPU-accelerated Hashcat with masks and rules targets likely password patterns and processes NTLM hashes at very high speed.
  4. DAn online attack against the domain controller is slow, triggers lockouts and logging, and makes no use of the offline hashes.
T-03

Which of the following is TRUE about rootkits?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMany rootkits persist across reboots by hooking boot processes, drivers or firmware.
  2. BCorrect: rootkits intercept system calls or kernel structures to hide files, processes and connections from the operating system and security tools.
  3. CRootkits are designed to evade detection, and no antivirus product reliably finds and removes all of them.
  4. DRootkits exist for Windows, macOS, Linux and firmware, not only Linux.
T-04

On a Windows computer, where would you find the file that stores user account details including password hashes?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThis path does not exist; Windows does not store password hashes in a plain folder under Program Files.
  2. BCorrect: the SAM database at System32\config stores local account data and password hashes, locked while Windows runs.
  3. CNo accounts file exists in this location; local credentials are held in the SAM hive.
  4. DThere is no security\pwd file in Windows; this path is invented.
T-05

An organization experiences repeated successful credential stuffing attacks leading to account takeovers and lateral movement within the internal network. Management asks you to design a comprehensive control framework. Which combination of controls BEST addresses credential abuse, post-compromise movement, detection, and governance?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APassword complexity, expiry and lockout do little against credential stuffing with valid leaked passwords, and do not address movement, detection or governance.
  2. BCorrect: MFA blunts stolen credentials, segmentation limits lateral movement, EDR analytics detects post-compromise behavior, and access reviews provide governance.
  3. CSIEM, perimeter IDS and quarterly scans add detection but lack a preventive control for stolen credentials and do little to limit internal movement.
  4. DWAF rate limits and CAPTCHA slow automated logins, but lack strong authentication and governance, leaving stolen credentials usable.
T-06

Which privilege escalation technique involves exploiting improperly configured services that run with higher privileges than necessary?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: service exploitation abuses misconfigured services running as SYSTEM or root, such as weak permissions or unquoted paths, to gain higher privileges.
  2. BCross-site scripting injects script into web pages viewed by other users, not a local privilege escalation technique.
  3. CPass-the-hash reuses captured NTLM hashes to authenticate, which is lateral movement rather than abuse of service configuration.
  4. DDLL injection loads code into another process; it can be abused for escalation but is not specifically about over-privileged service configuration.
T-07

Which of the following is NOT typically used as a method for maintaining access after successful system compromise?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: port scanning is a reconnaissance activity that finds open services and does not keep an attacker's foothold on a compromised system.
  2. BWeb shells give an attacker repeat access through a web server, a common persistence method that defenders hunt for.
  3. CRootkits hide malicious components and keep access over time, making them a classic persistence mechanism.
  4. DBackdoor accounts let an attacker log in again later, which is why account audits are a key defensive check.
T-08

What technique involves manipulating a system's memory to run arbitrary code when a program writes data beyond the boundaries of allocated memory?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a buffer overflow writes past a buffer's bounds, corrupting adjacent memory and potentially redirecting execution; bounds checks, DEP and ASLR mitigate it.
  2. BSQL injection manipulates database queries through unsanitized input, not memory boundaries.
  3. CA race condition exploits timing between operations, not writing beyond allocated memory.
  4. DCross-site scripting injects script into web pages for other users' browsers, not memory corruption on the system.
T-09

A threat actor wants to maintain long-term, stealthy access to a compromised Windows system. They require a persistence mechanism that operates without creating traditional scheduled tasks or autorun registry keys. Which technique best meets these requirements?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA browser extension can steal data, but it lives in the browser profile and is not system-level persistence that avoids typical autorun checks.
  2. BCorrect: WMI event subscriptions run code when defined system events occur, living in the WMI repository rather than tasks or Run keys, so defenders must enumerate them specifically.
  3. CThe Startup folder is one of the most common and frequently monitored autorun locations, which the requirement rules out.
  4. DWinlogon keys are well-known autorun registry locations, so this does not meet the no-autorun-keys requirement.
T-10

In a Linux system, which file typically stores user account information including passwords?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe /etc/hosts file maps hostnames to IP addresses locally and holds no account information.
  2. BCorrect: /etc/shadow holds password hashes and aging data and is readable only by root, separating secrets from /etc/passwd.
  3. CThe /etc/group file lists groups and their members, not passwords.
  4. DThe /etc/passwd file lists accounts, UIDs and shells, but on modern systems the password field is just a placeholder.
T-11

What technique can bypass network segmentation by exploiting trust relationships between network segments?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATunneling wraps one protocol inside another to carry traffic past filters, but it is a transport method rather than the act of using a compromised host's trust.
  2. BPacket filtering is a defensive control that allows or blocks traffic by rules; it enforces segmentation instead of bypassing it.
  3. CCorrect: pivoting uses a compromised host that is trusted by another segment as a stepping stone, reaching systems the attacker could not reach directly.
  4. DPort forwarding redirects a single port through a host; it can support pivoting but is a narrower mechanism than exploiting segment trust.
T-12

Windows event logs show multiple Event ID 4625 failures followed by a single Event ID 4624 success. Both the source and destination IP addresses are internal. Which activity does this indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a run of failed logons followed by a success between two internal hosts suggests an attacker guessing credentials to move laterally inside the network.
  2. BA DDoS floods a target with traffic to exhaust resources and would not appear as a sequence of failed and then successful logons.
  3. CCredential stuffing campaigns originate externally, typically against internet-facing logins, but both addresses here are internal.
  4. DAn external brute force attack would show a public source address, whereas these events come from inside the network.
T-13

What does the following command do on a Linux computer? umask 027

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThese permissions do not follow from umask 027; that mask removes write from the group and everything from others, leaving owner read and write.
  2. BThis would require a mask of 002, which leaves group and others with broad access, the opposite of what 027 does.
  3. CCorrect: umask 027 masks group write and all access for others, so new files default to rw-r----- and new directories to rwxr-x---.
  4. DWorld-readable and writable files correspond to a mask of 000, which provides no restriction at all.
T-14

Which type of attack exploits the race condition between the time a system checks a resource and the time it uses that resource?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APass-the-ticket reuses stolen Kerberos tickets to authenticate, not a timing gap between checking and using a resource.
  2. BCorrect: a TOCTOU race exploits the window between a permission check and the actual use of a resource, often by swapping a file in between.
  3. CKerberoasting requests service tickets to crack service account passwords offline, which has nothing to do with race conditions.
  4. DDLL hijacking places a malicious library where an application will load it, a search-order issue rather than a timing race.
T-15

Which tool is used to hide text within audio files?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASnow hides messages in trailing whitespace of text files, not in audio files.
  2. BCameraShy was a browser-based tool for hiding messages in web images, not audio.
  3. CCorrect: MP3Stego embeds hidden data during MP3 encoding, which is why it is the classic audio steganography example.
  4. DOpenStego hides data primarily in image files and offers watermarking, not MP3 audio hiding.
T-16

Which of these is NOT typically a phase in the system hacking methodology?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEscalating privileges is a core system hacking phase that moves from limited access to administrative or root control.
  2. BCorrect: enumeration is a pre-attack information-gathering step that precedes system hacking rather than a phase within it.
  3. CMaintaining access is a system hacking phase in which attackers keep a foothold through backdoors or other persistence.
  4. DCovering tracks is the closing system hacking phase, where attackers clear logs and hide artifacts, which defenders counter with protected logging.
T-17

What defense mechanism is specifically designed to make buffer overflow attacks more difficult?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: ASLR randomizes memory locations of the stack, heap and libraries, so an attacker cannot reliably predict where to redirect execution after an overflow.
  2. BA firewall filters network traffic by rules and does not change how a vulnerable program handles memory.
  3. CAn IDS may detect some exploitation attempts, but it does not make the memory corruption itself harder to exploit.
  4. DAntivirus detects known malicious files and behaviors, but is not a memory protection designed against overflows.

Short answers on Module 6

Where does the line between Module 6 and Module 7 fall?

Module 6 follows the intrusion on one host, from access to covering tracks. Keyloggers, spyware and rootkits appear in its v13 outline on EC-Council's course page (checked Oct 11, 2026) as things an intruder runs there. Malware families, propagation and analysis belong to Module 7.

Is steganography taught here or with cryptography?

Here. Blueprint v5.0 lists hiding files under Module 6 (checked Oct 11, 2026), and the v13 outline names steganography and steganalysis in this module. Encryption itself belongs to Module 20.

Which password guidance should I study, the old rotation rules or current NIST guidance?

Learn both and read the stem carefully. NIST SP 800-63B-4 (final July 2025, checked Oct 11, 2026) favors length and screening against known-compromised passwords over forced periodic changes. Older prep material still teaches rotation. When an option offers more frequent rotation, ask whether it fixes the weakness the stem names.

How should I handle the tool names in this module?

File each name under a category: password recovery, steganography, monitoring software. One short flashcard session covers it, and it is the first thing to cut in a tight week.

Sources