🎯 Metasploit Framework
The Metasploit Framework is the world's most widely used penetration testing platform. This interactive demo illustrates the typical attack chain used in authorized security assessments.
This demonstration is for educational purposes in an authorized academic setting. Unauthorized access to computer systems is illegal under the Computer Fraud and Abuse Act (CFAA) and similar laws worldwide. Always obtain written permission before conducting security assessments.
(Kali Linux)
Perimeter
(Windows/Linux)
, ,
/ \
((__---,,,---__))
(_) O O (_)_________
\ _ / |\
o_o \ M S F | \
\ _____ | *
||| WW|||
||| |||
=[ metasploit v6.4.0-dev ]
+ -- --=[ 2400 exploits - 1200 auxiliary - 400 post ]
+ -- --=[ 1100 payloads - 50 encoders - 10 nops ]
+ -- --=[ 9 evasion ]
msf6 > _
Pre-built attack modules targeting specific vulnerabilities in operating systems, applications, and services.
Code that runs on the target system after successful exploitation - shells, meterpreter, command execution.
Scanning, fuzzing, and information gathering modules that support the exploitation process.
Modules for privilege escalation, credential harvesting, pivoting, and maintaining access.
🔍 NMAP Scanning
Network Mapper (NMAP) is the industry standard for network discovery and security auditing. It identifies live hosts, open ports, running services, and potential vulnerabilities.
Discovered Services
| Port | Service | Version | State | Risk |
|---|---|---|---|---|
| 22/tcp | SSH | OpenSSH 7.9 | Open | Low |
| 80/tcp | HTTP | Apache 2.4.38 | Open | Medium |
| 445/tcp | SMB | Windows SMB | Open | High |
| 3389/tcp | RDP | MS Terminal Services | Open | High |
Probes open ports to determine service/version info. Critical for finding vulnerable versions.
Runs default NSE scripts for additional enumeration and vulnerability detection.
Fingerprints the target OS using TCP/IP stack analysis. Helps select appropriate exploits.
💉 Exploit Delivery
Once vulnerabilities are identified, Metasploit delivers exploit code to compromise the target system. This demo shows the EternalBlue (MS17-010) SMB exploit.
LHOST: 192.168.1.50
MS17-010
RHOST: 192.168.1.100
Remote host(s) - the target IP address or range to attack.
Local host - the attacker's IP for reverse connections back.
Local port - the port on attacker machine listening for shells.
💻 In-Memory Command Shell
Meterpreter is an advanced, dynamically extensible payload that operates entirely in memory, leaving minimal forensic footprint. It provides extensive post-exploitation capabilities.
Meterpreter runs entirely in RAM without writing to disk, evading traditional antivirus detection and file-based forensics.
Can migrate to other processes for persistence and to avoid detection when the initial process terminates.
All traffic between attacker and target is encrypted using TLS, making network detection difficult.
Supports loading additional modules on-demand for new capabilities without touching the disk.
🚪 Backdoor Setup
Persistence mechanisms ensure continued access even after system reboots. This demonstrates various techniques attackers use to maintain their foothold.
Common Persistence Techniques
| Technique | Location | Trigger | Detection |
|---|---|---|---|
| Registry Run Keys | HKLM/HKCU\...\Run | User Logon | Autoruns, Registry Monitoring |
| Scheduled Tasks | Task Scheduler | Time-based / Event | Task Scheduler Logs |
| Windows Services | Services.msc | System Boot | Service Creation Events |
| DLL Hijacking | Application Directories | App Execution | Process Monitoring |
| WMI Subscriptions | WMI Repository | Event-based | WMI Activity Logging |
Security teams use tools like Sysinternals Autoruns, EDR solutions, and SIEM correlation to detect unauthorized persistence mechanisms. Regular baseline comparisons and anomaly detection are key defensive strategies.
🔐 Password Dumps
Credential harvesting extracts password hashes and tokens from memory and system files. These can be used for lateral movement or offline cracking.
Security Account Manager stores local user password hashes. Requires SYSTEM privileges to dump.
Local Security Authority Subsystem Service stores credentials of logged-in users in memory.
TGT and service tickets can be extracted for pass-the-ticket attacks in Active Directory.
Domain cached credentials (DCC2) stored locally for offline domain authentication.
⚡ Password Cracking
Offline password cracking uses various techniques to recover plaintext passwords from captured hashes. Modern GPUs can test billions of combinations per second.
3 of 4 hashes cracked (75%)
Attack Modes Comparison
| Mode | Hashcat Flag | Speed | Coverage | Best For |
|---|---|---|---|---|
| Dictionary | -a 0 | Very Fast | Limited | Common passwords |
| Brute Force | -a 3 | Slow | Complete | Short passwords |
| Rule-Based | -a 0 -r | Fast | Good | Password variations |
| Combinator | -a 1 | Medium | Medium | Word combinations |
| Hybrid | -a 6/7 | Medium | Good | Dict + mask patterns |
Classic password cracker supporting many hash types. Good for initial quick cracks with auto-detection.
World's fastest password cracker. GPU-accelerated, supports 300+ hash types and advanced rules.
👑 Privilege Escalation
Privilege escalation exploits misconfigurations or vulnerabilities to elevate from a standard user to administrator or SYSTEM level access.
Common Privilege Escalation Vectors
Exploits auto-elevation features in Windows to run code with elevated privileges without triggering UAC prompts.
Steals or duplicates access tokens from other processes to assume their privileges (SeImpersonatePrivilege).
Unquoted service paths, weak permissions, or writable service binaries allow code execution as SYSTEM.
Vulnerabilities in the Windows kernel or drivers provide direct path to SYSTEM privileges.
Organizations should: Apply security patches promptly, enforce least privilege, use Credential Guard, enable LAPS for local admin passwords, audit service configurations, and deploy EDR solutions with privilege escalation detection.