Phase 04 · Proving the Risk

Exploitation

A vulnerability report says a door might be unlocked. Exploitation walks through it. This phase is about gaining that first foothold — turning a scored finding into actual access — using the Metasploit Framework, targeted attacks on unpatched services, credential attacks, and the human layer.

00

About this phase

The Metasploit Framework is the center of gravity here: a structured way to search for an exploit matching a finding, configure it, select a payload, and fire. But exploitation is broader than one tool — it includes attacking out-of-date services, cracking captured password hashes, abusing weak credentials, and using social engineering to get a user to open the door for you. The disciplined tester confirms access carefully and avoids collateral damage.

Authorized targets only. Exploitation is the phase where the legal boundary is least forgiving. Everything here assumes a signed scope and systems you are permitted to attack.
Lessons
7 live
Phase
04 of 08
Status
Complete
01

Lessons in this phase