00
About this phase
The Metasploit Framework is the center of gravity here: a structured way to search for an exploit matching a finding, configure it, select a payload, and fire. But exploitation is broader than one tool — it includes attacking out-of-date services, cracking captured password hashes, abusing weak credentials, and using social engineering to get a user to open the door for you. The disciplined tester confirms access carefully and avoids collateral damage.
Authorized targets only. Exploitation is the phase where the legal boundary is least forgiving. Everything here assumes a signed scope and systems you are permitted to attack.
Lessons
7 live
Phase
04 of 08
Status
Complete
01
Lessons in this phase
04.01Live →
04.02Live →
04.03Live →
04.04Live →
04.05Lab →
04.06Live →
04.07Live →
The Metasploit Framework
Architecture and workflow: modules, search, options, sessions — the mental model behind msfconsole.
Finding & Running Exploits
Matching a finding to a module or an exploit-db PoC, setting options, and confirming a successful exploit.
Attacking Unpatched Services
The bread-and-butter of real engagements: known CVEs against services that were never updated.
Payloads & Encoders
Staged vs stageless, bind vs reverse shells, and why payload choice matters.
Password & Credential Attacks
Hydra, John, and Hashcat against captured hashes and login services. Cross-links to the Password Attack Racer lab.
The Social Engineering Toolkit (SET)
Phishing and pretext-driven access as an exploitation path. Cross-links to the Social Engineering module.
Command & Control Frameworks
Beyond Metasploit: the modern C2 landscape (Cobalt Strike, Sliver, Havoc, Brute Ratel, Mythic), redirectors, and how attackers abuse Cloudflare Tunnel for resilient C2.