Leanpub Header

Skip to main content

Practical Metasploit

Mastering the Metasploit Framework from First Exploit to Advanced Post-Exploitation

Practical Metasploit

Go beyond clicking through msfconsole. A progressive, hands-on course that takes you from your first canned exploit to writing custom Ruby modules, pivoting through compromised networks, and extending the Metasploit Framework itself.

Minimum price

$19.00

$29.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

Buying multiple copies for your team? See below for a discount!

PDF
EPUB
WEB
APP
Discussion Forum
About

About

About the Book

Metasploit is the tool every penetration tester reaches for, and the one most people only half understand. They click through msfconsole, fire a canned exploit, and stop there. This book takes you the rest of the way.

Over nineteen lab-driven chapters you build a purpose-made attack lab, then work through the framework the way a serious operator does: service discovery with db_nmap and auxiliary scanners, payload theory and msfvenom generation, exploitation and session handling, and full Meterpreter mastery — process migration, privilege escalation, pivoting, and tunneling through compromised hosts. From there you move into post-exploitation: credential harvesting, persistence, and lateral movement across SMB, WinRM, and SSH.

The second half is where most books stop and this one keeps going. You write your own auxiliary, scanner, and post modules in Ruby, build a working exploit against a patched CVE, call the Windows API through Railgun, and automate engagements with resource scripts. A closing section covers what encoders and evasion can and can't do, and how to keep your modules alive against the framework's release and deprecation cadence.

Every chapter escalates. You start by running exploits and finish by writing them. If you know your way around a terminal and want to treat Metasploit as something you extend rather than something you click, this is the book.

Team Discounts

Team Discounts

Get a team discount on this book!

  • Up to 3 members

    Minimum price
    $47.00
    Suggested price
    $72.00
  • Up to 5 members

    Minimum price
    $76.00
    Suggested price
    $116
  • Up to 10 members

    Minimum price
    $133
    Suggested price
    $203
  • Up to 15 members

    Minimum price
    $190
    Suggested price
    $290
  • Up to 25 members

    Minimum price
    $285
    Suggested price
    $435

Author

About the Author

Ground Truth Books

Ground Truth Books publishes practical technical books on computer science, IT tools, data science, machine learning, software engineering and AI.

The name comes from machine learning, where "ground truth" means the real, verified answers you check a model against. That's how these books are made. They're researched and drafted with AI assistance, and then checked against reality. Examples are run against real captures and data in a lab, and those runs are cited like any other source, so you can see which output came straight from the tool. Every claim is cited to its source, with official documentation, specifications and source code preferred over blog posts.

Each book is built around doing the work. Chapters end with exercises, and an appendix gives worked answers you can reproduce on your own machine, using the same freely available data and captures.

Books are updated when the tools change. If you find an error, please report it: a corrected edition is free for every reader, which is one of the best things about Leanpub.

Contents

Table of Contents

Foundations

What Is Metasploit

  1. Why Metasploit for penetration testers
  2. How Metasploit works
  3. The seven components
  4. Glossary

Modules and Framework Architecture

  1. Understanding the Metasploit module directory structure
  2. Auxiliary modules
  3. Payloads
  4. Filesystem and libraries
  5. Encoders
  6. NOPs
  7. ATT&CK metadata

Building Your Attack Lab

  1. Installing the Metasploit Framework
  2. Installing on Kali Linux
  3. Launch msfconsole in Kali
  4. DNS configuration
  5. Keeping the lab current

The msfconsole Workflow

  1. Metasploit commands
  2. Getting help for msfconsole commands
  3. Searching for exploits with keywords
  4. Datastore
  5. Finding modules
  6. Understanding module options
  7. Use, back, and exit commands

The Metasploit Database

  1. Initialize the Metasploit PostgreSQL database
  2. Database support
  3. Database workspaces
  4. Example workflow
  5. Keep your Metasploit data safe
  6. Using msfdb
  7. Exploitation

Service Discovery and Scanning

  1. Port scanning
  2. Scanner HTTP auxiliary modules
  3. Auxiliary module examples
  4. Vulnerability scanning with Metasploit
  5. A TCP port scanner
  6. The Metasploitable scanning lab

Staged versus Stageless Payloads

  1. How payloads work
  2. What are staged payloads?
  3. What are stageless payloads?
  4. Staged versus stageless handlers
  5. Connecting stageless payloads to staged handlers
  6. Stageless mode
  7. Working with payloads

Generating Payloads with msfvenom

  1. Introducing msfvenom
  2. How to use msfvenom
  3. Output formats
  4. Handlers
  5. Advanced msfvenom payload generation
  6. A worked example

Exploitation and Session Management

  1. Working with exploits
  2. Working with sessions
  3. Checking target availability
  4. Manage Meterpreter and shell sessions
  5. Setting up a payload
  6. Basic workflow
  7. Meterpreter and Post-Exploitation

Meterpreter Fundamentals

  1. What is Metasploit Meterpreter?
  2. How Meterpreter works
  3. Meterpreter flavors
  4. Core commands
  5. File system commands
  6. Help
  7. Meterpreter transport control
  8. The lab

Migration and Privilege Escalation

  1. Meterpreter getsystem
  2. Migrate
  3. priv_migrate
  4. System commands
  5. Other commands
  6. The escalation lab

Pivoting and Routing

  1. How pivoting works
  2. Route-based pivoting
  3. Port forwarding

Credentials, Persistence, and Lateral Movement

  1. About post-exploitation
  2. hashdump
  3. Post-exploitation modules by category
  4. Lateral movement and persistence
  5. Extending the Framework

Resource Scripts and Automation

  1. Resource scripts
  2. Six ways to automate Metasploit
  3. Automating the Metasploit console
  4. Basic workflow

Writing Custom Auxiliary Modules

  1. Writing an auxiliary module
  2. How to add a third-party module
  3. Running private modules
  4. Navigating the codebase
  5. Using Rex::Proto::Http::Client
  6. The Exploit::Remote::Tcp mixin
  7. Module documentation

Writing Your First Exploit

  1. Building your first Metasploit exploit
  2. Setting up a Metasploit development environment
  3. Writing module documentation

Railgun and the Windows API

  1. Using Railgun for Windows post-exploitation
  2. Defining a DLL and its functions
  3. MSF Meterpreter and Railgun
  4. Evasion and Modern Context

Encoders and Evasion Limits

  1. Encoders
  2. AV bypass with Metasploit templates
  3. A defender’s checklist
  4. Detecting Metasploit attacks
  5. Hardening and defensive takeaways

Keeping Modules Current

  1. Metasploit 6 in development
  2. Metasploit Framework 6.0 release notes
  3. Metasploit Framework 6.4
  4. The 6.5 MCP server
  5. When the APT repo falls behind
  6. Reading the release notes
  7. Future trends and emerging considerations

Appendix A: Command and module cheat sheet

  1. Console startup
  2. Navigation and workflow
  3. Module layout
  4. Payloads and msfvenom
  5. Database commands
  6. Sessions, jobs, handlers
  7. Meterpreter commands
  8. Pivoting
  9. Post module pick list
  10. Ranks and check codes
  11. Resource scripts

Appendix B: Framework release history

  1. Major releases
  2. Version numbering and release cadence
  3. Module inventory over time
  4. Compatibility breaks
  5. Editions and licensing

Appendix C: Auxiliary and post module index

  1. Auxiliary modules
  2. Post modules

Glossary

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub