Metasploit's payload factory: build a reverse shell for (almost) any platform in one line. Building payloads teaches you what shells actually are.
Follow the steps — click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
LHOST = attacker IP (you), LPORT = your listener's port.
No listener = shell connects to nobody. Handler first!
-l payloads browses hundreds.
Bind vs reverse: reverse dials home to you — firewall-friendly.
Encoding dodges naive signatures — modern AV eats it anyway; great EDR lesson in the lab.
| -p | payload path |
| LHOST / LPORT | call-back IP / port |
| -f | format exe/elf/raw/php… |
| -o | output file |
| -e / -i | encoder / iterations |
| -l payloads|formats | list all |
multi/handler from Metasploit catches every payload type — muscle memory it.
Try staged (meterpreter/reverse_tcp) vs stageless (meterpreter_reverse_tcp) to feel the difference.
Payloads are the answer to 'how do I turn RCE into a usable shell?'
Drop payloads only into your lab VMs — treat as live ammo.
Use msfvenom only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox — plenty of legal targets, zero risk.