Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Metasploit</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Metasploit"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Metasploit rootpage-Metasploit skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Metasploit</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */


.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}


/* end https://en.wikipedia.org/ */
</style><table class="infobox vevent"><tbody><tr><th colspan="2" class="infobox-above summary">Metasploit</th></tr><tr><td colspan="2" class="infobox-image logo"></td></tr><tr><td colspan="2" class="infobox-image logo"><span typeof="mw:File"></span><div class="infobox-caption">Metasploit Community showing three hosts, two of which were compromised by an exploit</div></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Original author(s)</a></th><td class="infobox-data"><a href="H._D._Moore" title="H. D. Moore">H. D. Moore</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data">Rapid7, Inc.</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Initial release</th><td class="infobox-data">2003<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2003</span>)</span><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></td></tr><tr style="display: none;"><td colspan="2" class="infobox-full-data"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_release_life_cycle" title="Software release life cycle">Stable release</a></th><td class="infobox-data"><div style="margin:0px;">6.4.59<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
/ April&nbsp;24,&nbsp;2025<span style="display: none;">&nbsp;(<span class="bday dtstart published updated itvstart">2025-04-24</span>)</span></div></td></tr><tr style="display:none"><td colspan="2">
</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Repository_(version_control)" title="Repository (version control)">Repository</a></th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://github.com/rapid7">github<wbr>.com<wbr>/rapid7</a></span></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Written in</th><td class="infobox-data"><a href="Ruby_(programming_language)" title="Ruby (programming language)">Ruby</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Operating_system" title="Operating system">Operating system</a></th><td class="infobox-data"><a href="Cross-platform" class="mw-redirect" title="Cross-platform">Cross-platform</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data"><a href="Computer_security" title="Computer security">Security</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_license" title="Software license">License</a></th><td class="infobox-data">Framework: <a href="BSD_License" class="mw-redirect" title="BSD License">BSD</a>,<sup id="cite_ref-bsdlicense_3-0" class="reference"><a href="#cite_note-bsdlicense-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Community/Express/Pro: Proprietary</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://www.metasploit.com/">www<wbr>.metasploit<wbr>.com</a></span></td></tr></tbody></table>
<p>The <b>Metasploit Project</b> is a <a href="Computer_security" title="Computer security">computer security</a> project that provides information about <a href="Vulnerability_(computer_science)" class="mw-redirect" title="Vulnerability (computer science)">security vulnerabilities</a> and aids in <a href="Penetration_testing" class="mw-redirect" title="Penetration testing">penetration testing</a> and <a href="Intrusion-detection_system" class="mw-redirect" title="Intrusion-detection system">IDS signature</a> development. It is owned by <b>Rapid7</b>, a <a href="Boston" title="Boston">Boston</a>, Massachusetts-based security company.
</p><p>Its best-known sub-project is the <a href="Open-source_software" title="Open-source software">open-source</a><sup id="cite_ref-bsdlicense_3-1" class="reference"><a href="#cite_note-bsdlicense-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> <b>Metasploit Framework</b>, a tool for developing and executing <a href="Exploit_(computer_security)" title="Exploit (computer security)">exploit</a> code against a remote target machine. Other important sub-projects include the Opcode Database, <a href="Shellcode" title="Shellcode">shellcode</a> archive and related research.
</p><p>The Metasploit Project includes <a href="Anti-computer_forensics" class="mw-redirect" title="Anti-computer forensics">anti-forensic</a> and evasion tools, some of which are built into the Metasploit Framework. In various operating systems it comes pre installed.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>Metasploit was created by <a href="H._D._Moore" title="H. D. Moore">H. D. Moore</a> in 2003 as a portable network tool using <a href="Perl" title="Perl">Perl</a>. By 2007, the Metasploit Framework had been completely rewritten in <a href="Ruby_(programming_language)" title="Ruby (programming language)">Ruby</a>. On October 21, 2009, the Metasploit Project announced<sup id="cite_ref-:0_4-0" class="reference"><a href="#cite_note-:0-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> that it had been acquired by Rapid7, a security company that provides unified vulnerability management solutions.
</p><p>Like comparable commercial products such as Immunity's Canvas or <a href="Core_Security_Technologies" title="Core Security Technologies">Core Security Technologies</a>' Core Impact, Metasploit can be used to test the vulnerability of computer systems or to break into remote systems. Like many <a href="Information_security" title="Information security">information security</a> tools, Metasploit can be used for both legitimate and unauthorized activities. Since the acquisition of the Metasploit Framework, Rapid7 has added an <a href="Open_core" class="mw-redirect" title="Open core">open core</a> proprietary edition called Metasploit Pro.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>Metasploit's emerging position as the <a href="De_facto" title="De facto">de facto</a> exploit development framework<sup id="cite_ref-:1_6-0" class="reference"><a href="#cite_note-:1-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> led to the release of software vulnerability advisories often accompanied<sup id="cite_ref-:2_7-0" class="reference"><a href="#cite_note-:2-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> by a third party Metasploit exploit module that highlights the exploitability, risk and remediation of that particular bug.<sup id="cite_ref-VMwareNAT_8-0" class="reference"><a href="#cite_note-VMwareNAT-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-MOKB-11-11-2006_9-0" class="reference"><a href="#cite_note-MOKB-11-11-2006-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> Metasploit 3.0 began to include <a href="Fuzzing" title="Fuzzing">fuzzing</a> tools, used to discover software vulnerabilities, rather than just exploits for known bugs. This avenue can be seen with the integration of the <a href="Lorcon" title="Lorcon">lorcon</a> wireless (802.11) toolset into Metasploit 3.0 in November 2006.
</p>
<div class="mw-heading mw-heading2"><h2 id="Framework">Framework</h2></div>
<p>The basic steps for exploiting a system using the Framework include.
</p>
<ol><li>Optionally checking whether the intended target system is vulnerable to an exploit.</li>
<li>Choosing and configuring an <i>exploit</i> (code that enters a target system by taking advantage of one of its <a href="Software_bug" title="Software bug">bugs</a>; about 900 different exploits for <a href="Microsoft_Windows" title="Microsoft Windows">Windows</a>, <a href="Unix" title="Unix">Unix</a>/<a href="Linux" title="Linux">Linux</a> and <a href="MacOS" title="MacOS">macOS</a> systems are included).</li>
<li>Choosing and configuring a <i><a href="Payload_(software)" class="mw-redirect" title="Payload (software)">payload</a></i> (code that will be executed on the target system upon successful entry; for instance, a remote shell or a <a href="Virtual_Network_Computing" class="mw-redirect" title="Virtual Network Computing">VNC server</a>). Metasploit often recommends a payload that should work.</li>
<li>Choosing the encoding technique so that hexadecimal opcodes known as "bad characters" are removed from the payload, these characters will cause the exploit to fail.</li>
<li>Executing the exploit.</li></ol>
<p>This modular approach – allowing the combination of any exploit with any payload – is the major advantage of the Framework. It facilitates the tasks of attackers, exploit writers and payload writers.
</p><p>Metasploit runs on Unix (including Linux and macOS) and on Windows. The Metasploit Framework can be extended to use add-ons in multiple languages.
</p><p>To choose an exploit and payload, some information about the target system is needed, such as operating system version and installed network services. This information can be gleaned with <a href="Port_scanning" class="mw-redirect" title="Port scanning">port scanning</a> and <a href="TCP/IP_stack_fingerprinting" title="TCP/IP stack fingerprinting">TCP/IP stack fingerprinting</a> tools such as <a href="Nmap" title="Nmap">Nmap</a>. <a href="Vulnerability_scanner" title="Vulnerability scanner">Vulnerability scanners</a> such as <a href="Nessus_(software)" title="Nessus (software)">Nessus</a>, and <a href="OpenVAS" title="OpenVAS">OpenVAS</a> can detect target system vulnerabilities. Metasploit can import vulnerability scanner data and compare the identified vulnerabilities to existing exploit modules for accurate exploitation.<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Interfaces">Interfaces</h2></div>
<p>There are several interfaces for Metasploit available. The most popular are maintained by Rapid7 and Strategic Cyber LLC.<sup id="cite_ref-Metasploit_editions_11-0" class="reference"><a href="#cite_note-Metasploit_editions-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Metasploit_Framework_(Open_Source_Edition)">Metasploit Framework (Open Source Edition)</h3></div>
<p>The Metasploit Framework is the freely available, open-source edition of the Metasploit Project.
</p><p>It provides tools for vulnerability assessment and exploit development including:
</p>
<ul><li>A command-line interface for controlling exploit modules.</li>
<li>Database for managing scan data and exploit results.</li>
<li>Import of network scan results from external scanning utilities such as Nmap.</li>
<li>Scanning support using the integrated `db_nmap` feature for automated execution and data integration.</li>
<li>Over 1,500 built-in exploits, with the ability of adding custom exploit modules or automated resource scripts.</li></ul>
<p>The Metasploit Framework is implemented in Ruby and uses a modular software architecture.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Pro">Pro</h3></div>
<p>In October 2010, Rapid7 added Metasploit Pro, an open-core commercial Metasploit edition for penetration testers. Metasploit Pro adds onto Metasploit Express with features such as Quick Start Wizards/MetaModules, building and managing <a href="Social_engineering_(security)" title="Social engineering (security)">social engineering</a> campaigns, web application testing, an advanced Pro Console, dynamic payloads for anti-virus evasion, integration with Nexpose for ad-hoc vulnerability scans, and VPN pivoting.
</p>
<div class="mw-heading mw-heading3"><h3 id="Discontinued_editions">Discontinued editions</h3></div>
<div class="mw-heading mw-heading4"><h4 id="Community">Community</h4></div>
<p>The edition was released in October 2011, and included a free, web-based user interface for Metasploit. Metasploit Community Edition was based on the commercial functionality of the paid-for editions with a reduced set of features, including network discovery, module browsing and manual exploitation. Metasploit Community was included in the main installer.
</p><p>On July 18, 2019, Rapid7 announced the end-of-sale of Metasploit Community Edition.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> Existing users were able to continue using it until their license expired.
</p>
<div class="mw-heading mw-heading4"><h4 id="Express">Express</h4></div>
<p>The edition was released in April 2010, and was an open-core commercial edition for security teams who need to verify vulnerabilities. It offers a graphical user interface, It integrated nmap for discovery, and added smart brute-forcing as well as automated evidence collection.
</p><p>On June 4, 2019, Rapid7 discontinued Metasploit Express Edition.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Armitage">Armitage</h3></div>
<p><a href="Armitage_(computing)" title="Armitage (computing)">Armitage</a> is a graphical cyber attack management tool for the Metasploit Project that visualizes targets and recommends exploits. It is a <a href="Free_and_open_source" class="mw-redirect" title="Free and open source">free and open source</a> <a href="Network_security" title="Network security">network security</a> tool notable for its contributions to <a href="Red_team" title="Red team">red team</a> collaboration allowing for shared sessions, data, and communication through a single Metasploit instance.<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p><p>The latest release of Armitage was in 2015.
</p>
<div class="mw-heading mw-heading3"><h3 id="Cobalt_Strike">Cobalt Strike</h3></div>
<p>Cobalt Strike is a collection of threat emulation tools provided by HelpSystems to work with the Metasploit Framework.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> Cobalt Strike includes all features of <a href="Armitage_(computing)" title="Armitage (computing)">Armitage</a> and adds post-exploitation tools, in addition to report generation features.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Exploits">Exploits</h2></div>
<p>Metasploit currently has over 2074 exploits, organized under the following platforms: <a href="AIX" class="mw-redirect" title="AIX">AIX</a>, <a href="Android_(operating_system)" title="Android (operating system)">Android</a>, <a href="BSD" class="mw-redirect" title="BSD">BSD</a>, <a href="BSDi" class="mw-redirect" title="BSDi">BSDi</a>, <a href="Cisco" title="Cisco">Cisco</a>, <a href="Firefox" title="Firefox">Firefox</a>, <a href="FreeBSD" title="FreeBSD">FreeBSD</a>, <a href="HP-UX" title="HP-UX">HP-UX</a>, <a href="Irix" class="mw-redirect" title="Irix">Irix</a>, <a href="Java_(programming_language)" title="Java (programming language)">Java</a>, <a href="JavaScript" title="JavaScript">JavaScript</a>, <a href="Linux" title="Linux">Linux</a>, <a href="Mainframe" class="mw-redirect" title="Mainframe">mainframe</a>, multi (applicable to multiple platforms), <a href="NetBSD" title="NetBSD">NetBSD</a>, <a href="NetWare" title="NetWare">NetWare</a>, <a href="Nodejs" class="mw-redirect" title="Nodejs">NodeJS</a>, <a href="OpenBSD" title="OpenBSD">OpenBSD</a>, <a href="MacOS" title="MacOS">macOS</a>, <a href="PHP" title="PHP">PHP</a>, <a href="Python_(programming_language)" title="Python (programming language)">Python</a>, <a href="R_(programming_language)" title="R (programming language)">R</a>, <a href="Ruby_(programming_language)" title="Ruby (programming language)">Ruby</a>, <a href="Solaris_(operating_system)" class="mw-redirect" title="Solaris (operating system)">Solaris</a>, <a href="Unix" title="Unix">Unix</a>, and <a href="Windows" class="mw-redirect" title="Windows">Windows</a>.
</p><p>Note that <a href="IOS" title="IOS">Apple iOS</a> is based on FreeBSD, and some FreeBSD exploits may work, while most won't.
</p>
<div class="mw-heading mw-heading2"><h2 id="Payloads">Payloads</h2></div>
<p>Metasploit currently has over 592 payloads. Some of them are:
</p>
<ul><li>Command shell enables users to run collection scripts or run arbitrary commands against the host.</li>
<li>Meterpreter (the Metasploit Interpreter) enables users to control the screen of a device using VNC and to browse, upload and download files.</li>
<li>Dynamic payloads enable users to evade anti-virus defense by generating unique payloads.</li>
<li>Static payloads enable static IP address/port forwarding for communication between the host and the client system.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Auxiliary_modules">Auxiliary modules</h2></div>
<p>The Metasploit Framework includes hundreds of auxiliary modules that can perform scanning, fuzzing, sniffing, and much more. There are three types of auxiliary modules namely scanners, admin and server modules.
</p>
<div class="mw-heading mw-heading2"><h2 id="Contributors">Contributors</h2></div>
<p>Metasploit Framework operates as an open-source project and accepts contributions from the community through GitHub.com pull requests.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> Submissions are reviewed by a team consisting of both Rapid7 employees and senior external contributors. The majority of contributions add new modules, such as exploits or scanners.<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p>List of original developers:
</p>
<ul><li><a href="H._D._Moore" title="H. D. Moore">H. D. Moore</a> (founder and chief architect)</li>
<li>Matt Miller (core developer from 2004–2008)</li>
<li>Dean McNamee (Spoonm) (core developer from 2003–2008)</li></ul>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1266661725">
/* start https://en.wikipedia.org/ */


.mw-parser-output .portalbox{padding:0;margin:0.5em 0;display:table;box-sizing:border-box;max-width:175px;list-style:none}.mw-parser-output .portalborder{border:1px solid var(--border-color-base,#a2a9b1);padding:0.1em;background:var(--background-color-neutral-subtle,#f8f9fa)}.mw-parser-output .portalbox-entry{display:table-row;font-size:85%;line-height:110%;height:1.9em;font-style:italic;font-weight:bold}.mw-parser-output .portalbox-image{display:table-cell;padding:0.2em;vertical-align:middle;text-align:center}.mw-parser-output .portalbox-link{display:table-cell;padding:0.2em 0.2em 0.2em 0.3em;vertical-align:middle}@media(min-width:720px){.mw-parser-output .portalleft{margin:0.5em 1em 0.5em 0}.mw-parser-output .portalright{clear:right;float:right;margin:0.5em 0 0.5em 1em}}


/* end https://en.wikipedia.org/ */
</style>
<ul><li><a href="W3af" title="W3af">w3af</a></li>
<li><a href="OWASP" title="OWASP">OWASP</a> Open Web Application Security Project</li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.oreilly.com/library/view/metasploit/9781593272883/pr04s03.html">"A Brief History of Metasploit"</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20230803154255/https://www.oreilly.com/library/view/metasploit/9781593272883/pr04s03.html">Archived</a> from the original on 2023-08-03<span class="reference-accessdate">. Retrieved <span class="nowrap">2024-05-23</span></span>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/rapid7/metasploit-framework/tags">"Tags · rapid7/Metasploit-framework"</a>. <i><a href="GitHub" title="GitHub">GitHub</a></i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20221219104034/https://github.com/rapid7/metasploit-framework/tags">Archived</a> from the original on 2022-12-19<span class="reference-accessdate">. Retrieved <span class="nowrap">2024-05-23</span></span>.</cite></span>
</li>
<li id="cite_note-bsdlicense-3"><span class="mw-cite-backlink">^ <a href="#cite_ref-bsdlicense_3-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-bsdlicense_3-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/rapid7/metasploit-framework/blob/master/LICENSE">"3-clause BSD license"</a>. <i><a href="GitHub" title="GitHub">GitHub</a></i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20210130132454/https://github.com/rapid7/metasploit-framework/blob/master/LICENSE">Archived</a> from the original on 2021-01-30<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-06-24</span></span>.</cite></span>
</li>
<li id="cite_note-:0-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-:0_4-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.rapid7.com/metasploit-announcement.jsp">"Rapid7 Press Release"</a>. <i>Rapid7</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110715154413/http://www.rapid7.com/metasploit-announcement.jsp">Archived</a> from the original on 15 July 2011<span class="reference-accessdate">. Retrieved <span class="nowrap">18 February</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.rapid7.com/products/metasploit/download/editions/">"Metasploit Editions: Network Pen Testing Tool"</a>. <i>Rapid7</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20230720185815/https://www.rapid7.com/products/metasploit/download/editions/">Archived</a> from the original on 2023-07-20<span class="reference-accessdate">. Retrieved <span class="nowrap">2023-08-03</span></span>.</cite></span>
</li>
<li id="cite_note-:1-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-:1_6-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://sectools.org/sploits.html">"Vulnerability exploitation tools – SecTools Top Network Security Tools"</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20111017222000/http://sectools.org/sploits.html">Archived</a> from the original on 17 October 2011<span class="reference-accessdate">. Retrieved <span class="nowrap">18 February</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-:2-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-:2_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFMetasploit" class="citation web cs1">Metasploit. <a rel="nofollow" class="external text" href="https://www.exploit-db.com/author/?a=3211">"Metasploit"</a>. <i>www.exploit-db.com</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20170116162949/https://www.exploit-db.com/author/?a=3211">Archived</a> from the original on 2017-01-16<span class="reference-accessdate">. Retrieved <span class="nowrap">2017-01-14</span></span>.</cite></span>
</li>
<li id="cite_note-VMwareNAT-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-VMwareNAT_8-0">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20070107145900/http://archives.neohapsis.com/archives/vulnwatch/2005-q4/0074.html">"ACSSEC-2005-11-25-0x1 VMWare Workstation 5.5.0 &lt;= build-18007 GSX Server Variants And Others"</a>. December 20, 2005. Archived from <a rel="nofollow" class="external text" href="http://archives.neohapsis.com/archives/vulnwatch/2005-q4/0074.html">the original</a> on 2007-01-07.</cite></span>
</li>
<li id="cite_note-MOKB-11-11-2006-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-MOKB-11-11-2006_9-0">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://archive.today/20130103221440/http://projects.info-pull.com/mokb/MOKB-11-11-2006.html">"Month of Kernel Bugs – Broadcom Wireless Driver Probe Response SSID Overflow"</a>. November 11, 2006. Archived from <a rel="nofollow" class="external text" href="http://projects.info-pull.com/mokb/MOKB-11-11-2006.html">the original</a> on January 3, 2013.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.metasploit.com/download">"Penetration Testing Tool, Metasploit, Free Download - Rapid7"</a>. <i>Rapid7</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20171224213533/https://www.metasploit.com/download">Archived</a> from the original on 24 December 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">18 February</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-Metasploit_editions-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-Metasploit_editions_11-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.rapid7.com/products/metasploit/editions-and-features.jsp">"Metasploit editions"</a>. <i>rapid7.com</i>. rapid7. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20150310141636/http://www.rapid7.com/products/metasploit/editions-and-features.jsp">Archived</a> from the original on 10 March 2015<span class="reference-accessdate">. Retrieved <span class="nowrap">16 February</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.rapid7.com/products/metasploit/download/editions/">"Metasploit Product Editions"</a>. <i>Rapid7</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2025-03-19</span></span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blog.rapid7.com/2019/07/18/end-of-sale-announced-for-metasploit-community/">"End of Sale Announced for Metasploit Community"</a>. <i>Rapid7 Blog</i>. 2019-07-18. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200713093712/https://blog.rapid7.com/2019/07/18/end-of-sale-announced-for-metasploit-community/">Archived</a> from the original on 2020-07-13<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-07-13</span></span>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blog.rapid7.com/2018/06/04/announcement-end-of-life-for-metasploit-express-edition/">"Announcement: End of Life for Metasploit Express Edition"</a>. <i>Rapid7 Blog</i>. 2018-06-04. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20200716060542/https://blog.rapid7.com/2018/06/04/announcement-end-of-life-for-metasploit-express-edition/">Archived</a> from the original on 2020-07-16<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-07-13</span></span>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://code.google.com/p/armitage/">"Armitage A GUI for Metasploit"</a>. Strategic Cyber LLC. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160114143101/https://code.google.com/p/armitage/">Archived</a> from the original on 2016-01-14<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-11-18</span></span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cobaltstrike.com/">"Adversary Simulation and Red Team Operations Software - Cobalt Strike"</a>. <i>cobaltstrike.com</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20190128054935/https://www.cobaltstrike.com/">Archived</a> from the original on 2019-01-28<span class="reference-accessdate">. Retrieved <span class="nowrap">2019-01-22</span></span>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="http://www.advancedpentest.com/help-armitage-vs-cobaltstrike">"Armitage vs Cobalt Hooked Strike"</a>. Strategic Cyber LLC. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160319071751/http://www.advancedpentest.com/help-armitage-vs-cobaltstrike">Archived</a> from the original on 2016-03-19<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-11-18</span></span>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/rapid7/metasploit-framework/blob/master/CONTRIBUTING.md">"rapid7/metasploit-framework"</a>. <i>GitHub</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20180726041334/https://github.com/rapid7/metasploit-framework/blob/master/CONTRIBUTING.md">Archived</a> from the original on 2018-07-26<span class="reference-accessdate">. Retrieved <span class="nowrap">2017-01-14</span></span>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="https://github.com/rapid7/metasploit-framework/wiki/Contributing-to-Metasploit">"Contributing to Metasploit"</a>. Rapid7, Inc. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20160924052612/https://github.com/rapid7/metasploit-framework/wiki/Contributing-to-Metasploit">Archived</a> from the original on 2016-09-24<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-06-09</span></span>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="Further_reading">Further reading</h2></div>
<ul><li><i><a rel="nofollow" class="external text" href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1135581,00.html">Powerful payloads: The evolution of exploit frameworks</a></i>, searchsecurity.com, 2005-10-20</li>
<li>Chapter 12: Writing Exploits III from <i>Sockets, Shellcode, Porting &amp; Coding: Reverse Engineering Exploits and Tool Coding for Security Professionals</i> by James C. Foster (<a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>1-59749-005-9</bdi>). Written by Vincent Liu, chapter 12 explains how to use Metasploit to develop a buffer overflow exploit from scratch.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1290876196">
/* start https://en.wikipedia.org/ */


.mw-parser-output .side-box{margin:4px 0;box-sizing:border-box;border:1px solid #aaa;font-size:88%;line-height:1.25em;background-color:var(--background-color-interactive-subtle,#f8f9fa);display:flow-root}.mw-parser-output .infobox .side-box{font-size:100%}.mw-parser-output .side-box-abovebelow,.mw-parser-output .side-box-text{padding:0.25em 0.9em}.mw-parser-output .side-box-image{padding:2px 0 2px 0.9em;text-align:center}.mw-parser-output .side-box-imageright{padding:2px 0.9em 2px 0;text-align:center}@media(min-width:500px){.mw-parser-output .side-box-flex{display:flex;align-items:center}.mw-parser-output .side-box-text{flex:1;min-width:0}}@media(min-width:720px){.mw-parser-output .side-box{width:238px}.mw-parser-output .side-box-right{clear:right;float:right;margin-left:1em}.mw-parser-output .side-box-left{margin-right:1em}}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1237033735">
/* start https://en.wikipedia.org/ */


@media print{body.ns-0 .mw-parser-output .sistersitebox{display:none!important}}@media screen{html.skin-theme-clientpref-night .mw-parser-output .sistersitebox img[src*="Wiktionary-logo-en-v2.svg"]{background-color:white}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .sistersitebox img[src*="Wiktionary-logo-en-v2.svg"]{background-color:white}}


/* end https://en.wikipedia.org/ */
</style><div class="side-box side-box-right sistersitebox"><style data-mw-deduplicate="TemplateStyles:r1126788409">
/* start https://en.wikipedia.org/ */


.mw-parser-output .plainlist ol,.mw-parser-output .plainlist ul{line-height:inherit;list-style:none;margin:0;padding:0}.mw-parser-output .plainlist ol li,.mw-parser-output .plainlist ul li{margin-bottom:0}


/* end https://en.wikipedia.org/ */
</style>
<div class="side-box-flex">
<div class="side-box-image"><span class="noviewer" typeof="mw:File"></span></div>
<div class="side-box-text plainlist">Wikimedia Commons has media related to <a href="https://commons.wikimedia.org/wiki/Category:Metasploit" class="extiw external" title="commons:Category:Metasploit"><span style="font-style:italic; font-weight:bold;">Metasploit</span></a>.</div></div>
</div>
<div class="side-box side-box-right sistersitebox">
<div class="side-box-flex">
<div class="side-box-image"><span class="noviewer" typeof="mw:File"></span></div>
<div class="side-box-text plainlist">Wikibooks has more on the topic of: <i><b><a href="https://en.wikibooks.org/wiki/Special:Search/Metasploit" class="extiw external" title="wikibooks:Special:Search/Metasploit">Metasploit</a></b></i></div></div>
</div>
<ul><li><span class="official-website"><span class="url"><a rel="nofollow" class="external text" href="https://www.metasploit.com">Official website</a></span></span></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-20" href="https://en.wikipedia.org/wiki/?title=Metasploit&amp;oldid=1301605247">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>