Metasploit post-exploitation modules explained, by category with examples

This blog offers a comprehensive guide to Metasploit's post exploitation modules, providing a detailed table of the top 100 modules used by ethical hackers and penetration testers. It explains how each module is categorized—system information, credential dumping, persistence, browser data, file access, and more—along with practical examples for real-world usage. This post is perfect for cybersecurity students, red teamers, and OSCP aspirants looking to strengthen their post exploitation techniques and understand the full potential of Metasploit after gaining access to a system.

May 26, 2025 - 11:28
Updated: 8 days ago
110.6k
Metasploit post-exploitation modules explained, by category with examples

Quick answer: Metasploit's post-exploitation modules run after you already have a session, usually Meterpreter, on a target. They group into information gathering, privilege escalation, credential access, persistence, lateral movement and cleanup. Use only sessions on systems you are authorised to test, document every action, and remove any persistence you add before the engagement ends.

Key takeaways

  • Post-exploitation covers what happens after you already hold a session.
  • Modules group into gathering, privilege escalation, credentials, persistence, pivoting and cleanup.
  • Meterpreter's built-in commands cover much of this without separate modules.
  • Document and remove anything you add, including persistence.
  • Only run these against systems you are authorised to test.

What is post-exploitation?

Once an exploit succeeds and you hold a session, the real value of a penetration test starts: showing what an attacker could actually do with that access. Metasploit organises this work through Meterpreter commands and post modules, usually run with run post/... or use post/... against an existing session.

Why does this article not list 100 modules?

Metasploit ships many post modules, and the exact count changes with every update. A long numbered list goes stale immediately and encourages copying commands without understanding them. Instead, this guide groups what matters by purpose, which stays useful regardless of version. Check msfconsole itself with search type:post for the current, exact list on your install.

What are the main categories?

CategoryPurposeExample
Information gatheringLearn about the compromised hostpost/windows/gather/enum_logged_on_users
Credential accessFind stored credentialspost/windows/gather/credentials/credential_collector
Privilege escalationMove from a limited to a higher-privilege accountpost/multi/recon/local_exploit_suggester
PersistenceKeep access across reboots, for the engagement onlyexploit/windows/local/persistence style modules
PivotingReach other hosts from the compromised onepost/multi/manage/autoroute
CleanupRemove changes you madeManual removal plus Meterpreter logging

What does a lab walkthrough look like?

Using a Metasploitable VM you own:

msf6 > use exploit/multi/handler
msf6 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_tcp
msf6 exploit(multi/handler) > exploit
meterpreter > sysinfo
meterpreter > getuid
meterpreter > run post/multi/recon/local_exploit_suggester
meterpreter > hashdump
  • sysinfo and getuid tell you what you have landed on and as whom.
  • local_exploit_suggester checks the host against known local privilege escalation modules, and you review its suggestions rather than run them blindly.
  • hashdump (on a Windows target you are authorised to test) extracts local password hashes for an authorised credential review.

Record every command and its output as you go, with timestamps, for the report. The MITRE ATT&CK matrix is a useful reference for naming these post-exploitation techniques consistently.

What is pivoting?

Pivoting uses a compromised host as a stepping stone to reach other hosts the tester could not reach directly. autoroute adds a route through the session so later modules can target that internal network. This should only happen within the agreed scope.

What about persistence and cleanup?

Persistence modules install a way back in, useful for showing a client how long undetected access could last. Document exactly what was installed, and remove it, including any scheduled task, service or registry key, before the test ends. A good report lists every artefact and confirms it was cleaned up.

What should a tester keep in mind?

  • Everything here needs written authorisation and an agreed scope.
  • Logging on the target may generate real alerts. Coordinate with the client's defenders, depending on the engagement type.
  • Meterpreter's built-in commands, like getsystem, screenshot and keyscan_start, often matter as much as separate post modules.

Where can you learn this properly?

Our VAPT course and OSCP course cover Metasploit and post-exploitation in a structured, lab-based way. Related reading: top 10 Metasploit features and the Metasploit framework overview.

Next steps

To practise this safely, see our VAPT course. For the broader framework, read the Metasploit framework overview.

Frequently Asked Questions

They are modules and commands used after a session is already established on a target, to gather information, escalate privileges, collect credentials, maintain access and pivot to other hosts, all within an authorised scope.

Metasploit's exact module count changes with every update, so a fixed long list goes stale quickly. Grouping modules by purpose stays accurate, and msfconsole's own search command shows the current list on your install.

On a Windows target you are authorised to test, hashdump extracts local account password hashes from a session with sufficient privileges, so testers can review password strength as part of the engagement.

Pivoting uses a compromised host to reach other systems on its network that the tester could not access directly, typically using a module such as autoroute to add a route through the session.

Yes. Use them only on systems and sessions you are explicitly authorised to test, under a written scope. Unauthorised use is illegal under India's IT Act.

Yes. Any persistence mechanism installed to demonstrate ongoing access should be documented in detail and removed before the engagement ends, and the report should confirm the cleanup.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.