The legendary exploitation framework: pick exploit โ set target โ choose payload โ shell. It's the fastest path to understanding how attacks chain together.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
First time takes ~30s while the DB spins up.
Match service version from your Nmap scan to a module.
RHOSTS = victim. LHOST = you (needed by most payloads).
You have a shell. id proves who you are (root on Metasploitable2).
Upgrade to meterpreter payloads for post-ex superpowers.
| search x | find modules |
| use path | select module |
| info | details & options |
| set RHOSTS/LHOST | target / you |
| show options | what it needs |
| run | fire! |
| sessions -l/-i | list / interact |
| msfvenom | payload factory |
Rank matters: 'excellent' modules basically never crash targets.
check (before run) tests if the target looks vulnerable โ always worth it.
Not just exploits: auxiliary/ scanners substitute for half your toolkit.
Free official course: Metasploit Unleashed โ a rite of passage.
Use Metasploit Framework only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.