awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
rapid7 avatar

rapid7/metasploit-framework

0
View on GitHub↗
38,415 Stars·14,877 Forks·Ruby·24 Aufrufewww.metasploit.com↗

Metasploit Framework

The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures.

The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to manage high-performance, concurrent network connections and features a transport-agnostic communication layer that abstracts protocols to maintain persistent command and control. Users can extend the core functionality through a plugin system and define complex exploit logic using a domain-specific language.

The framework provides robust capabilities for remote payload management, including the configuration of network settings like sleep intervals and timeout thresholds. It maintains state persistence across long-running sessions by storing discovered host information and vulnerability data in a relational database. The software is designed for cross-platform deployment, with installation support available for Linux, macOS, and Windows environments.

Features

  • Penetration Testing Platforms - Serves as a comprehensive environment for security professionals to develop, test, and execute exploits.
  • Exploit Frameworks - Provides a collection of interchangeable components to define complex attack logic.
  • Exploitation Frameworks - Provides a modular platform for developing and executing custom security payloads and exploit logic.
  • Exploit Execution Engines - Targets known vulnerabilities to gain unauthorized access or execute arbitrary commands on a remote machine.
  • Memory Injection Techniques - Executes code directly within process memory space to avoid writing artifacts to the disk.
  • Post-Exploitation Frameworks - Manages persistent access and gathers data on compromised systems to understand the scope of a security incident.
  • Post-Exploitation Toolkits - Facilitates long-term session persistence, privilege escalation, and sensitive data collection following successful system access.
  • Remote Command Execution Tools - Manages persistent sessions and delivers custom payloads to compromised systems.
  • Transport Abstractions - Decouples command and control logic from underlying network protocols to maintain persistent remote connections.
  • Payload Development Tools - Crafts custom code designed to bypass security controls during authorized security assessment activities.
  • Vulnerability Assessment Tools - Tests networked systems to confirm if known security flaws are exploitable.
  • Wordlists - Framework containing various wordlists for exploitation.
  • Exploit Development - Comprehensive penetration testing framework for vulnerability research and exploitation.
  • Network Protocol Fuzzers - Security framework with auxiliary modules for protocol fuzzing.
  • Security Frameworks - Industry-standard framework for penetration testing and exploit development.
  • C2 Frameworks - Comprehensive framework for exploit development and system compromise.
  • Command And Control Frameworks - Comprehensive security project for vulnerability research and penetration testing.
  • Exploitation Frameworks - Comprehensive foundation for developing and executing security exploits.
  • Exploitation Tools - Comprehensive framework for exploit development and execution.
  • Penetration Testing Frameworks - Industry standard platform for developing and executing exploit code.
  • Penetration Testing Toolkits - The industry-standard framework for penetration testing.
  • Post Exploitation Frameworks - Industry-standard framework for exploitation and post-exploitation.
  • Privilege Escalation Tools - Framework for developing and executing exploit code.
  • Security Analysis Frameworks - Industry-standard framework for penetration testing and exploit development.
  • Sicherheit und Datenschutz - Framework for penetration testing and security research.
  • Security Frameworks - Industry-standard framework for penetration testing and exploit development.
  • Security Testing Tools - Industry standard penetration testing framework for exploit development and execution.
  • Vulnerability Scanners - Industry-standard framework for exploit development and testing.
  • Vulnerability Scanning - Framework for developing and executing exploit code.
  • Web Security - Comprehensive penetration testing and exploitation framework.
  • Evasive Payload Generators - Generates malicious code designed to bypass antivirus software and endpoint protection systems.
  • Testing Frameworks - Standardizes the process of identifying and documenting security weaknesses through repeatable and automated assessment procedures.
  • Security Research Environments - Provides a standardized workspace for identifying and validating vulnerabilities through repeatable procedures.
  • Plugin Architectures - Extends core functionality through dynamically loaded components that integrate into the main environment.
  • Network Scanning Tools - Gathers intelligence on target systems and infrastructure to identify potential entry points.
  • Concurrency Models - Provides a non-blocking execution model for managing high-concurrency network operations.

Star-Verlauf

Star-Verlauf für rapid7/metasploit-frameworkStar-Verlauf für rapid7/metasploit-framework

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Häufig gestellte Fragen

Was macht rapid7/metasploit-framework?

The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures.

Was sind die Hauptfunktionen von rapid7/metasploit-framework?

Die Hauptfunktionen von rapid7/metasploit-framework sind: Penetration Testing Platforms, Exploit Frameworks, Exploitation Frameworks, Exploit Execution Engines, Memory Injection Techniques, Post-Exploitation Frameworks, Post-Exploitation Toolkits, Remote Command Execution Tools.

Welche Open-Source-Alternativen gibt es zu rapid7/metasploit-framework?

Open-Source-Alternativen zu rapid7/metasploit-framework sind unter anderem: 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… byt3bl33d3r/crackmapexec — CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security… bc-security/empire — Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and… empireproject/empire — Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It… havocframework/havoc — Havoc is a post-exploitation framework used for red team operations. It provides a centralized command and control…

Open-Source-Alternativen zu Metasploit Framework

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Metasploit Framework.
  • 1n3/sn1perAvatar von 1N3

    1N3/Sn1per

    10,049Auf GitHub ansehen↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    Auf GitHub ansehen↗10,049
  • samratashok/nishangAvatar von samratashok

    samratashok/nishang

    9,951Auf GitHub ansehen↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    Auf GitHub ansehen↗9,951
  • byt3bl33d3r/crackmapexecAvatar von byt3bl33d3r

    byt3bl33d3r/CrackMapExec

    9,144Auf GitHub ansehen↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    Auf GitHub ansehen↗9,144
  • bc-security/empireAvatar von BC-SECURITY

    BC-SECURITY/Empire

    5,045Auf GitHub ansehen↗

    Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each

    PowerShellc2empirehacktoberfest
    Auf GitHub ansehen↗5,045
  • Alle 30 Alternativen zu Metasploit Framework anzeigen→