Frameworks
Metasploit Framework
Modular exploitation framework with payloads, auxiliaries, and post modules.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Only against systems you own or have written permission to test.
When
You have a confirmed vulnerability and authorized scope to validate exploitability.
How
msfconsole → search modules → set RHOSTS/LHOST → check → exploit. Prefer check before exploit.
Why
Industry standard for exploit development workflows and consistent post-exploitation modules.
Commands & usage
msfconsole
search type:exploit name:apache
use exploit/multi/handler
set payload windows/x64/meterpreter/reverse_tcp
run
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
ATT&CK
Tags
Related in Frameworks
Kali Linux
Debian-based distro preloaded with hundreds of offensive security tools.
Parrot OS
Security-focused Debian derivative with Privacy and Security editions.
Cobalt Strike
Commercial adversary simulation platform with Beacon C2.
Sliver
Open-source adversary emulation C2 framework (implants, listeners, pivots).
Mythic C2
Collaborative multi-agent C2 platform with modular agents.
PowerShell Empire / Starkiller
Post-exploitation framework with PowerShell/Python agents and GUI (Starkiller).