Metasploit post-exploitation modules explained, by category with examples
This blog offers a comprehensive guide to Metasploit's post exploitation modules, providing a detailed table of the top 100 modules used by ethical hackers and penetration testers. It explains how each module is categorized—system information, credential dumping, persistence, browser data, file access, and more—along with practical examples for real-world usage. This post is perfect for cybersecurity students, red teamers, and OSCP aspirants looking to strengthen their post exploitation techniques and understand the full potential of Metasploit after gaining access to a system.
Quick answer: Metasploit's post-exploitation modules run after you already have a session, usually Meterpreter, on a target. They group into information gathering, privilege escalation, credential access, persistence, lateral movement and cleanup. Use only sessions on systems you are authorised to test, document every action, and remove any persistence you add before the engagement ends.
Key takeaways
- Post-exploitation covers what happens after you already hold a session.
- Modules group into gathering, privilege escalation, credentials, persistence, pivoting and cleanup.
- Meterpreter's built-in commands cover much of this without separate modules.
- Document and remove anything you add, including persistence.
- Only run these against systems you are authorised to test.
What is post-exploitation?
Once an exploit succeeds and you hold a session, the real value of a penetration test starts: showing what an attacker could actually do with that access. Metasploit organises this work through Meterpreter commands and post modules, usually run with run post/... or use post/... against an existing session.
Why does this article not list 100 modules?
Metasploit ships many post modules, and the exact count changes with every update. A long numbered list goes stale immediately and encourages copying commands without understanding them. Instead, this guide groups what matters by purpose, which stays useful regardless of version. Check msfconsole itself with search type:post for the current, exact list on your install.
What are the main categories?
| Category | Purpose | Example |
|---|---|---|
| Information gathering | Learn about the compromised host | post/windows/gather/enum_logged_on_users |
| Credential access | Find stored credentials | post/windows/gather/credentials/credential_collector |
| Privilege escalation | Move from a limited to a higher-privilege account | post/multi/recon/local_exploit_suggester |
| Persistence | Keep access across reboots, for the engagement only | exploit/windows/local/persistence style modules |
| Pivoting | Reach other hosts from the compromised one | post/multi/manage/autoroute |
| Cleanup | Remove changes you made | Manual removal plus Meterpreter logging |
What does a lab walkthrough look like?
Using a Metasploitable VM you own:
msf6 > use exploit/multi/handler
msf6 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_tcp
msf6 exploit(multi/handler) > exploit
meterpreter > sysinfo
meterpreter > getuid
meterpreter > run post/multi/recon/local_exploit_suggester
meterpreter > hashdump
sysinfoandgetuidtell you what you have landed on and as whom.local_exploit_suggesterchecks the host against known local privilege escalation modules, and you review its suggestions rather than run them blindly.hashdump(on a Windows target you are authorised to test) extracts local password hashes for an authorised credential review.
Record every command and its output as you go, with timestamps, for the report. The MITRE ATT&CK matrix is a useful reference for naming these post-exploitation techniques consistently.
What is pivoting?
Pivoting uses a compromised host as a stepping stone to reach other hosts the tester could not reach directly. autoroute adds a route through the session so later modules can target that internal network. This should only happen within the agreed scope.
What about persistence and cleanup?
Persistence modules install a way back in, useful for showing a client how long undetected access could last. Document exactly what was installed, and remove it, including any scheduled task, service or registry key, before the test ends. A good report lists every artefact and confirms it was cleaned up.
What should a tester keep in mind?
- Everything here needs written authorisation and an agreed scope.
- Logging on the target may generate real alerts. Coordinate with the client's defenders, depending on the engagement type.
- Meterpreter's built-in commands, like
getsystem,screenshotandkeyscan_start, often matter as much as separate post modules.
Where can you learn this properly?
Our VAPT course and OSCP course cover Metasploit and post-exploitation in a structured, lab-based way. Related reading: top 10 Metasploit features and the Metasploit framework overview.
Next steps
To practise this safely, see our VAPT course. For the broader framework, read the Metasploit framework overview.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0