Metasploit Project Profile Banner
Metasploit Project Profile
Metasploit Project

@metasploit

Followers
251,519
Following
189
Media
120
Statuses
2,504

Official account of the Metasploit Project, part of the @rapid7 family. Mastodon: @metasploit @infosec .exchange Slack:

Distributed
Joined January 2009
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@metasploit
Metasploit Project
2 months
Metasploit Framework 6.4 is out now! 🆕🎉 Features include: 🔹More Kerberos goodness, like support for diamond and sapphire tickets and extract tickets from compromised windows hosts to leverage unconstrained delegation 🔹DNS configuration 1/4
2
87
241
@metasploit
Metasploit Project
5 years
Metasploit Framework 5.0 released
27
1K
2K
@metasploit
Metasploit Project
5 years
Today we released a community-developed exploit module PR for #BlueKeep (CVE-2019-0708). We expect to continue refining the exploit over time in collaboration with contributors. Some important notes on exploitation and detection from @busterbcook :
20
889
1K
@metasploit
Metasploit Project
1 year
Metasploit Framework 6.3 is out now🎉 New features include native Kerberos authentication support, streamlined Active Directory attack workflows (AD CS, AD DS), and new modules that request, forge, and convert tickets between formats.
17
263
810
@metasploit
Metasploit Project
4 years
Today we're excited to announce active development of Metasploit Framework 6. Initial MSF 6 features include end-to-end encryption of Meterpreter communications, SMBv3 client support, and a new polymorphic payload generation routine.
10
266
646
@metasploit
Metasploit Project
6 years
Two targets. Three days. 1,000 teams. Announcing the 2018 Metasploit community CTF: Registration opens Nov. 12, play starts Nov. 30. Get it.
3
249
388
@metasploit
Metasploit Project
4 years
Registration for the 2020 Metasploit community CTF is now open. 1,000 teams, four days to find flags, unlimited shells. Play starts January 30. NOTE: Teams only need to register ONE account. Get it: #metasploitctf
17
236
375
@metasploit
Metasploit Project
7 years
We have a new YouTube channel! We'll be publishing ~biweekly demos of new stuff in Metasploit Framework here
6
212
358
@metasploit
Metasploit Project
7 years
Metasploit module for Samba CVE-2017-7494 just landed. Any writable share (auth or not) is RCE. Thanks @hdmoore and everyone who helped test
4
372
359
@metasploit
Metasploit Project
4 years
Tip: Stop setting RHOSTS for each of your modules and instead set it globally with 'setg RHOSTS x.x.x.x'. Use the 'tips' command in #Metasploit for more suggestions.
Tweet media one
4
99
352
@metasploit
Metasploit Project
6 years
Encapsulating antivirus evasion techniques in Metasploit Framework: New research from @_sinn3r , a new module type in MSF 5, and a framework for developers to build their own evasion modules.
4
179
309
@metasploit
Metasploit Project
5 years
Cheers to @HackingDave and the whole @DerbyCon community for hosting (and heckling) the Metasploit Town Hall for the past five years. Thanks for all the shells!
5
70
310
@metasploit
Metasploit Project
5 years
New Metasploit research from @_surefire_ and @jhartftw : A practical exploitation guide for Java serialization vulnerabilities. MSF now includes native support for building Java deserialization payloads with @frohoff 's ysoserial.
2
156
285
@metasploit
Metasploit Project
6 years
Registration for the 2018 Metasploit community CTF is now open: . Help us keep the game accessible to as many folks as possible by only registering ONE account per team (share creds, friends). Full rules and prizes here:
6
191
276
@metasploit
Metasploit Project
5 years
Metasploit shellcode grows up: Introducing encrypted and authenticated C shells in MSF 5 New payloads c/o @SpaceySpacek
3
133
264
@metasploit
Metasploit Project
5 years
We released Metasploit Framework 5.0 last month. Support for Python and Go, database and automation APIs, evasion modules, and new usability improvements—see what's new:
4
123
255
@metasploit
Metasploit Project
4 years
Last year, @wvuuuuuuuuuuuuu researched and published a command-and-control module for SMB DOUBLEPULSAR. Since then, we've researched and reverse-engineered the RDP version of the implant. Today we're publishing that research and a module for it. Details:
1
118
244
@metasploit
Metasploit Project
1 year
Psssst! @RealTryHackMe 's Advent of Cyber Challenge begins today! Metasploit has teamed up with the THM elves for some holiday fun on Friday, December 9th! Let the cyber challenges & cheer begin!
0
42
233
@metasploit
Metasploit Project
4 years
We're happy to announce another #Metasploit community CTF coming your way December 4! We developed this year's game to be accessible to beginners who want to connect with the community. Teams of all sizes are encouraged—registration opens 11/30.
5
91
227
@metasploit
Metasploit Project
7 years
The latest POSIX Meterpreter supports webcam snapshots on Linux.
Tweet media one
9
93
216
@metasploit
Metasploit Project
7 years
"Metasploit is built on the premise that security professionals need to have the same tools that attackers do" -
3
107
204
@metasploit
Metasploit Project
5 years
The Metasploit research team noticed an uptick in Java deserialization CVEs and a recent rise in exploit modules for JSO-related vulns. We were intrigued—so we added ysoserial support to MSF and wrote a practical JSO exploitation guide.
1
89
209
@metasploit
Metasploit Project
7 years
Want to learn Metasploit but don't have vulnerable servers to play with? Check out our new open source vuln emulator
3
155
203
@metasploit
Metasploit Project
5 years
Thanks for trusting us, @zerosum0x0 . We're digging into it and will keep the code private to the core MSF team until we think it’s ready for the Framework PR queue.
0
66
198
@metasploit
Metasploit Project
4 years
Howdy, folks. We'll be hosting another community CTF at the end of January. Stay tuned for a registration announcement next week. #metasploitctf
3
78
189
@metasploit
Metasploit Project
1 year
Metasploit 6.3.18 has added support for Active Directory Certificate Services ESC4 exploitation, as well as a new sudoedit extra arguments privilege escalation module
0
40
189
@metasploit
Metasploit Project
4 years
Introducing AttackerKB: A new community resource that highlights diverse perspectives on which vulnerabilities make the most appealing targets for attackers.
4
93
189
@metasploit
Metasploit Project
5 years
Our research team has been analyzing vulns and exploitable conditions for more than a decade and documenting the process of turning PoC and PRs into modules. It's time those notes left @_sinn3r 's computer. Introducing the Metasploit Development Diaries:
1
84
166
@metasploit
Metasploit Project
5 years
Code execution, command injection, and privilege escalation...OH MY!! Our new weekly from @pearce_barry wrap-up has it all! 🦁🐯🐻
3
54
163
@metasploit
Metasploit Project
5 years
Open source command and control of the DOUBLEPULSAR implant: New research from @wvuuuuuuuuuuuuu and @shellfail details a path to RCE on the backdoor widely attributed to the NSA
0
91
156
@metasploit
Metasploit Project
7 years
Save time typing in msfconsole with the alias plugin:
Tweet media one
1
97
147
@metasploit
Metasploit Project
6 years
Headed to #DEFCON26 ? Find us and the rest of the @Rapid7 family in the vendor hall selling limited edition #Metasploit0xf Anniversary Tour shirts to benefit @EFF . Get it.
Tweet media one
10
29
143
@metasploit
Metasploit Project
7 years
now has more info and focus on the open source community. Check it out for all your Metasploit needs.
7
89
140
@metasploit
Metasploit Project
7 years
Eternalblue module landed on Metasploit's master branch thanks to great work by @zerosum0x0 & @JennaMagius ! x64 only for now, more coming
2
111
141
@metasploit
Metasploit Project
5 years
We added initial support for GoLang in Metasploit last month. Pumped? Here's how to write an external GO module.
6
61
136
@metasploit
Metasploit Project
7 years
ICYMI Metasploit's auxiliary/scanner/smb/smb_ms17_010 can detect both #EternalBlue vuln and #DoublePulsar backdoor
0
118
136
@metasploit
Metasploit Project
6 years
Want to rain shells on the Linux version of Metasploitable3...and win prizes? Come play with us. Announcing the Metasploit community CTF!
0
83
133
@metasploit
Metasploit Project
3 years
Weekly wrap-up via @n00tmeg : Metasploit now captures NTLM hashes from any recent Windows release using SMBv2 and SMBv3, even with encrypted SMB traffic. Plus, @chompie1337 's eBPF exploit lands, along with modules for Git LFS and Geutebruck IP cameras 👯
2
44
132
@metasploit
Metasploit Project
5 years
#Metasploit wrap-up via @tychos_moose : Seven new modules, including two Windows 10 UAC bypasses and an evasion module. We also fixed that pesky digital signing issue.
0
44
124
@metasploit
Metasploit Project
6 years
13 new modules this week with plenty of RCE! Plus, C randomization for all your evasion needs. See what landed in the Metasploit weekly wrap-up:
0
63
126
@metasploit
Metasploit Project
6 years
Game on, CTF players! An important PSA: Reverting boxes takes a long time, so it's wise to not revert unless you have to. Good luck.
2
42
129
@metasploit
Metasploit Project
5 years
Ubiquiti devices are being exploited to conduct DoS attacks using a service on 10001/UDP (h/t @troutman ). Exposure deep dive from @jhartftw —to the tune of 498K+ unique IPV4s—plus a new Metasploit module for discovery.
2
100
123
@metasploit
Metasploit Project
4 years
Announcing beta sign-up for AttackerKB: a new resource to highlight hacker community knowledge on which vulns matter most—and why.
2
61
122
@metasploit
Metasploit Project
6 years
It's our birthday, and we want all the shells: New wrap-up featuring SOCKS5 improvements, a fresh Impacket-based module, MultiDrop mania, and the ability to put Meterpreter on 64-bit iOS devices (<= 9.3.4) thanks to Trident and contributor @timwr .
5
55
119
@metasploit
Metasploit Project
2 years
Announcing Metasploit 6.2! Highlights include a new global network capture plugin, SMB 1/2/3 server support, user-contributable docs, support for debugging Meterpreter sessions, local exploit suggester improvements, and more! 🔥🔥🔥🔥🔥🔥.🔥🔥
34
45
116
@metasploit
Metasploit Project
5 years
Fresh from @_sinn3r : A primer and technical tutorial on heap overflow exploitation on Windows 10
1
65
116
@metasploit
Metasploit Project
2 years
This week's wrap-up is 🔥🔥 with a Spring4Shell RCE, a Cisco RCE, an F5 Big-IP RCE auth bypass, a Powershell Command Adapter & more 😤😤
1
27
116
@metasploit
Metasploit Project
5 years
Heap overflow exploitation on Windows 10: primer and examples from @_sinn3r
0
51
117
@metasploit
Metasploit Project
5 years
We've seen a few more PRs exploiting (de)serialization vulnerabilities over the past few weeks. Check out @_surefire_ 's research-slash-guide on Java serialization exploits here:
1
46
110
@metasploit
Metasploit Project
6 years
Think you have what it takes to hack a target in under 5 minutes? Test your Metasploit skills and sling shells at the @Rapid7 booth at #BSidesLV . Game on.
4
43
108
@metasploit
Metasploit Project
5 years
Game on, friends. Good luck.
2
40
106
@metasploit
Metasploit Project
3 years
Announcing the 2021 Metasploit community CTF: Registration opens Nov. 22, game play begins Dec. 3. Teams welcome and encouraged as always— thanks to @RealTryHackMe and @ctfdio for supporting this year's game.
0
45
103
@metasploit
Metasploit Project
2 years
Pre-registration for the 2021 Metasploit community CTF is now open. Competition details here: . Join the Metasploit Slack team to find teammates or talk to the community. Thanks to @realtryhackme and @ctfdio for supporting this year's game!
1
39
100
@metasploit
Metasploit Project
6 years
@hacks4pancakes Why do you only have one? What do you wear the other six days of the week?
10
2
100
@metasploit
Metasploit Project
6 years
How to write Python modules for #Metasploit :
0
70
98
@metasploit
Metasploit Project
6 years
We owe you a debt, @hdmoore . From the whole Metasploit family, godspeed and thanks for all the shells.
2
22
96
@metasploit
Metasploit Project
4 years
That's a wrap on the 2020 Metasploit community CTF. Congrats to winners pepega, excusemewtf, and exit, and cheers to everyone on a well-played game! Big thanks to @ctfdio and @hackthebox_eu for powering the game and supplying sweet prizes.
3
19
97
@metasploit
Metasploit Project
5 years
Happy Thursday.
Tweet media one
2
10
92
@metasploit
Metasploit Project
6 years
ICYMI: We introduced evasion modules to Metasploit Framework this week. Generate evasive payloads without installing external tools, benefit from @_sinn3r 's AV evasion research, and write your own evasion modules.
0
45
90
@metasploit
Metasploit Project
7 years
190 unique authors contributed code to Metasploit in 2016. Thank you all
0
38
90
@metasploit
Metasploit Project
6 years
Weekly wrap-up: Rising tide lifts all privs, Oracle-foretold RCE, and two new MS17-010 exploit modules that work against any version of Windows thanks to contributor @zerosum0x0
6
43
88
@metasploit
Metasploit Project
5 years
The Metasploit Development Diaries: From 0day to foreverday, here's how our research team analyzes vulnerabilities for potential inclusion in Framework. Technical analysis by @_sinn3r .
0
48
88
@metasploit
Metasploit Project
6 years
New privilege escalation and command injection exploits, plus a SOCKS5 demo and a Mettle extension that plays sounds on a victim host. This week's Metasploit wrap-up c/o @3ss_G33 :
0
61
82
@metasploit
Metasploit Project
7 years
Find yourself typing the same stuff in msfconsole repeatedly? Put cmds in a file under ~/.msf4/scripts/resource/. Run with resource command
2
51
84
@metasploit
Metasploit Project
5 years
Dear diary: I wish I may, I wish I might Find a sweet 0day tonight. But if that 0day don't play nice Foreverday will sure suffice. <3 Metasploit
1
28
87
@metasploit
Metasploit Project
4 years
No fools here, only ponies. Hang in there, fam.
Tweet media one
5
15
85
@metasploit
Metasploit Project
6 years
CTF registration opens tomorrow at noon EST. Teams are allowed; only one registration is needed per team.
0
41
81
@metasploit
Metasploit Project
5 years
Weekly wrap-up via @wvuuuuuuuuuuuuu : Improved BlueKeep exploit reliability c/o @zerosum0x0 , two new Pulse Secure VPN modules, and a password cracking overhaul that adds support for hashcat.
2
43
83
@metasploit
Metasploit Project
5 years
Happy 2019: Metasploit dev @wvuuuuuuuuuuuuu has a deep dive on developing exploits for three vulns leveraged by the Morris Worm—which, as players may remember, was the inspiration for his Cuckoo's Egg-themed CTF challenge this past year.
0
37
86
@metasploit
Metasploit Project
8 years
"The Cisco ASA 5505 as a Stepping Stone Into Embedded Reverse Engineering" by the awesome @iamwilliamwebb
0
59
80
@metasploit
Metasploit Project
6 years
Last week's wrap-up via @HacksForProfit : Three new exploits for JIRA, Git, and Cisco Prime Infrastructure, plus an O365 user enumeration module—in Python, no less. May your Thanksgiving be full of shells.
0
40
77
@metasploit
Metasploit Project
2 years
A new twist to the #MetasploitCTF this year: The higher the port number, the harder the challenge. Want easier challenges? Start looking at services on lower-numbered ports. Game play starts Friday!
5
27
84
@metasploit
Metasploit Project
6 years
Weekly wrap-up: An exploit module for @taviso 's Ghostscript -dsafer bypass and more payload documentation, plus updates on external module support and Metasploit's remote data service.
0
37
82
@metasploit
Metasploit Project
4 years
2019 #Metasploit Framework wrap-up: Two new payload types, six pieces of research, a password-cracking overhaul, #BlueKeep mania. Plus, our list of MVP module contributions, from VPN and deserialization exploits to some neat persistence content. Cheers!
0
33
79
@metasploit
Metasploit Project
5 years
Ignore the internet today and look at ponies in Metasploit instead.
2
16
80
@metasploit
Metasploit Project
5 years
@busterbcook Huge thanks to PoC developers @zerosum0x0 and @ryhanson , and to @TomSellers , @TheColonial , @zeroSteiner , @rickoates , @wvuuuuuuuuuuuuu , @_sinn3r , and @tychos_moose , all of whose work was key in both exploit development + enhancements that will serve MSF users well beyond BlueKeep.
2
17
82
@metasploit
Metasploit Project
6 years
Look ma, no msfconsole: an update on Metasploit's work to support external modules—featuring Python, Impacket, Teradata, and more.
0
35
80
@metasploit
Metasploit Project
6 years
ICYMI: There's now a quick-start set-up option for Metasploitable3 that gets you up and running in minutes, thanks to pre-built Vagrant boxes for VMware and Virtualbox.
1
42
79
@metasploit
Metasploit Project
5 years
Want to help us build Metasploit 6? We're hiring a new team of software engineers in Rapid7's #Belfast , UK office to help shape the future of Framework. Local to Belfast and passionate about open-source? Apply here:
2
34
74
@metasploit
Metasploit Project
5 years
Want to contribute to Metasploit but don't know where to start? Our issue queue is full of bugs to squash and features to work on:
2
33
71
@metasploit
Metasploit Project
6 years
Metasploit weekly wrap-up: Two new Linux exploit modules, an ssh_enumusers update that lets attackers guess user accounts on more versions of OpenSSH, and some neat improvements. Plus, thanks to all our awesome GSoC students!
2
41
72
@metasploit
Metasploit Project
8 months
We've posted the demo that @zerosteiner gave at Black Hat Arsenal 2023 about some of the new AD stuff from 6.3! It includes: LDAP Enumeration Kerberos Authentication Kerberos Ticket Forging Kerberos Debugging ADCS
0
32
77
@metasploit
Metasploit Project
3 years
Weekly wrap-up via @errancarey : Metasploit users can now make HTTPS requests over pivoted sessions, thanks to new support for negotiating SSL connections over multiple connection types, including Meterpreter and SSH. Plus, *28* new post modules! 😱
3
29
74
@metasploit
Metasploit Project
7 years
Find flags, win stuff. #Metasploit #CTF for Metasploitable.
1
60
74
@metasploit
Metasploit Project
5 years
Fresh module based on research from @wvuuuuuuuuuuuuu gets RCE and executes a #Metasploit payload against the Equation Group's DOUBLEPULSAR implant for SMB.
1
34
73
@metasploit
Metasploit Project
3 years
We do enjoy stickers.
@IanColdwater
Ian Coldwater 📦💥
3 years
My son just informed me that if @metasploit was a person it would be old enough to vote
17
12
250
0
7
73
@metasploit
Metasploit Project
6 years
Last week's Metasploit wrap-up: Linux privilege escalation, a sweet Mimikatz Kiwi plugin update, some bad French, and your last chance to give us input on what you want to do with Metasploit data
1
34
71
@metasploit
Metasploit Project
3 years
Weekly wrap-up via Alan Foster: Four new modules, including LPEs for Microsoft Azure OMI CVE-2021-38648 and Win32k CVE-2021-40449, plus named pipe pivoting fixes and enhancements.
1
26
71
@metasploit
Metasploit Project
3 years
For the past 18 months, Metasploit's core engineering team in Belfast has been working on improving the overall user experience in Framework. We've completely overhauled option support to allow for easier URI targeting and streamlined workflows.
2
23
68
@metasploit
Metasploit Project
9 years
Today's the day - RIP MsfPayload & MsfEncode, long live MsfVenom: http://t.co/xjDZBbQ2lu
3
181
70