Foundations
What Is Metasploit
- Why Metasploit for penetration testers
- How Metasploit works
- The seven components
- Glossary
Modules and Framework Architecture
- Understanding the Metasploit module directory structure
- Auxiliary modules
- Payloads
- Filesystem and libraries
- Encoders
- NOPs
- ATT&CK metadata
Building Your Attack Lab
- Installing the Metasploit Framework
- Installing on Kali Linux
- Launch msfconsole in Kali
- DNS configuration
- Keeping the lab current
The msfconsole Workflow
- Metasploit commands
- Getting help for msfconsole commands
- Searching for exploits with keywords
- Datastore
- Finding modules
- Understanding module options
- Use, back, and exit commands
The Metasploit Database
- Initialize the Metasploit PostgreSQL database
- Database support
- Database workspaces
- Example workflow
- Keep your Metasploit data safe
- Using msfdb
- Exploitation
Service Discovery and Scanning
- Port scanning
- Scanner HTTP auxiliary modules
- Auxiliary module examples
- Vulnerability scanning with Metasploit
- A TCP port scanner
- The Metasploitable scanning lab
Staged versus Stageless Payloads
- How payloads work
- What are staged payloads?
- What are stageless payloads?
- Staged versus stageless handlers
- Connecting stageless payloads to staged handlers
- Stageless mode
- Working with payloads
Generating Payloads with msfvenom
- Introducing msfvenom
- How to use msfvenom
- Output formats
- Handlers
- Advanced msfvenom payload generation
- A worked example
Exploitation and Session Management
- Working with exploits
- Working with sessions
- Checking target availability
- Manage Meterpreter and shell sessions
- Setting up a payload
- Basic workflow
- Meterpreter and Post-Exploitation
Meterpreter Fundamentals
- What is Metasploit Meterpreter?
- How Meterpreter works
- Meterpreter flavors
- Core commands
- File system commands
- Help
- Meterpreter transport control
- The lab
Migration and Privilege Escalation
- Meterpreter getsystem
- Migrate
- priv_migrate
- System commands
- Other commands
- The escalation lab
Pivoting and Routing
- How pivoting works
- Route-based pivoting
- Port forwarding
Credentials, Persistence, and Lateral Movement
- About post-exploitation
- hashdump
- Post-exploitation modules by category
- Lateral movement and persistence
- Extending the Framework
Resource Scripts and Automation
- Resource scripts
- Six ways to automate Metasploit
- Automating the Metasploit console
- Basic workflow
Writing Custom Auxiliary Modules
- Writing an auxiliary module
- How to add a third-party module
- Running private modules
- Navigating the codebase
- Using Rex::Proto::Http::Client
- The Exploit::Remote::Tcp mixin
- Module documentation
Writing Your First Exploit
- Building your first Metasploit exploit
- Setting up a Metasploit development environment
- Writing module documentation
Railgun and the Windows API
- Using Railgun for Windows post-exploitation
- Defining a DLL and its functions
- MSF Meterpreter and Railgun
- Evasion and Modern Context
Encoders and Evasion Limits
- Encoders
- AV bypass with Metasploit templates
- A defender’s checklist
- Detecting Metasploit attacks
- Hardening and defensive takeaways
Keeping Modules Current
- Metasploit 6 in development
- Metasploit Framework 6.0 release notes
- Metasploit Framework 6.4
- The 6.5 MCP server
- When the APT repo falls behind
- Reading the release notes
- Future trends and emerging considerations
Appendix A: Command and module cheat sheet
- Console startup
- Navigation and workflow
- Module layout
- Payloads and msfvenom
- Database commands
- Sessions, jobs, handlers
- Meterpreter commands
- Pivoting
- Post module pick list
- Ranks and check codes
- Resource scripts
Appendix B: Framework release history
- Major releases
- Version numbering and release cadence
- Module inventory over time
- Compatibility breaks
- Editions and licensing
Appendix C: Auxiliary and post module index
- Auxiliary modules
- Post modules