Hands-on cybersecurity laboratory demonstrating msfvenom payloads, Metasploit Multi/Handler, Reverse TCP, Bind TCP, Meterpreter sessions, and post-exploitation in an authorized virtual lab environment.
This project demonstrates different shell and payload concepts using the Metasploit Framework in a controlled and authorized cybersecurity laboratory environment.
The practical focuses on understanding how an attacker and target can establish sessions using different communication models and how Meterpreter can be used for controlled post-exploitation enumeration.
The following topics are covered:
- msfvenom Payload
- Metasploit Multi/Handler
- Reverse TCP
- Bind TCP
- Meterpreter
- Post-Exploitation
| Component | Details |
|---|---|
| Attacker Machine | Kali Linux |
| Target Machine | Authorized Laboratory VM |
| Framework | Metasploit Framework |
| Payload Generator | msfvenom |
| Session Handler | Multi/Handler |
| Assessment Type | Authorized Laboratory Assessment |
| Virtualization | VMware |
All activities documented in this repository are performed only against systems owned by or explicitly authorized for security testing.
The practical is conducted inside an isolated laboratory environment for educational and cybersecurity training purposes.
No unauthorized systems are targeted.
The practical is divided into six major sections:
msfvenom Payload
↓
Multi/Handler
↓
Reverse TCP
↓
Bind TCP
↓
Meterpreter
↓
Post-Exploitation
Understand how msfvenom is used to generate Metasploit-compatible payloads for an authorized laboratory environment.
msfvenom
A payload defines the functionality delivered after successful execution on the authorized target.
Important payload concepts include:
- Payload type
- Architecture
- Platform
- Connection method
- Listener configuration
- Local host
- Local port
For the laboratory environment, a Linux Meterpreter reverse TCP payload can be generated using an appropriate Metasploit payload.
The payload configuration must correspond to the target operating system and architecture.
Understanding payload generation helps security professionals understand how exploitation frameworks establish communication channels after code execution.
Understand how Metasploit's exploit/multi/handler module receives connections from a compatible payload in an authorized laboratory environment.
exploit/multi/handler
PAYLOAD
LHOST
LPORT
The handler configuration must match the payload configuration.
Payload
↓
Target Execution
↓
Connection
↓
Multi/Handler
↓
Session
A handler provides the listener component required to receive a compatible session.
Understand the Reverse TCP communication model in which the authorized target initiates a connection back toward the configured listener.
Target
|
| Outbound TCP Connection
↓
Attacker / Listener
LHOST
LPORT
LHOST represents the address used by the listener, while LPORT represents the TCP port on which the listener waits for the incoming connection.
1. Configure payload
2. Configure listener
3. Execute payload in authorized lab
4. Target initiates connection
5. Handler receives connection
6. Session is established
Reverse connections are important to understand because many security tools and real-world attack techniques use outbound connections from a compromised host.
Understand the Bind TCP communication model in which the target listens for an incoming connection.
Attacker
|
| Incoming TCP Connection
↓
Target Listener
Unlike a reverse connection, the target creates a listening endpoint and the connecting system initiates the connection toward that endpoint.
The primary difference is the direction in which the session connection is initiated.
Target → Attacker
Attacker → Target
Understanding both connection models helps security professionals recognize different network communication patterns during penetration testing and incident investigation.
Understand the Meterpreter environment and perform controlled enumeration after establishing an authorized laboratory session.
Meterpreter is an advanced Metasploit payload that provides an interactive session with capabilities useful for authorized security testing and post-exploitation assessment.
sysinfo
getuid
pwd
ls
ipconfig
ps
netstat
The enumeration can provide information about:
- Operating system
- Architecture
- Current user
- Working directory
- Filesystem
- Network interfaces
- Running processes
- Network connections
Meterpreter demonstrates how a successful session can provide additional visibility into the security state of an authorized laboratory system.
Perform controlled post-exploitation enumeration after obtaining an authorized Meterpreter session.
sysinfo
Used to identify operating system and architecture information.
getuid
Used to determine the security context of the current session.
pwd
ls
Used to understand the current location and filesystem structure.
ipconfig
netstat
Used to identify network interfaces and active/listening connections.
ps
Used to identify running processes and services.
Post-exploitation enumeration helps an assessor understand the impact of a successful compromise without unnecessarily modifying or disrupting the target system.
| Feature | Reverse TCP | Bind TCP |
|---|---|---|
| Listener | Attacker | Target |
| Connection Initiated By | Target | Attacker |
| Direction | Target → Attacker | Attacker → Target |
| Main Concept | Callback connection | Target-side listener |
| Typical Lab Purpose | Demonstrate reverse connection | Demonstrate bind connection |
┌───────────────────────┐
│ msfvenom Payload │
└───────────┬───────────┘
↓
┌───────────────────────┐
│ Multi/Handler │
└───────────┬───────────┘
↓
┌────────┴────────┐
↓ ↓
Reverse TCP Bind TCP
↓ ↓
└────────┬────────┘
↓
Meterpreter Session
↓
Post-Exploitation
↓
Evidence & Report
Detailed practical evidence will be maintained under the evidence/ directory.
Planned evidence sections:
- msfvenom Payload
- Multi/Handler
- Reverse TCP
- Bind TCP
- Meterpreter
- Post-Exploitation
Screenshots from the authorized laboratory environment will be stored under the screenshots/ directory.
Metasploit-Bind-Reverse-Shell/
│
├── README.md
│
├── evidence/
│ ├── 01-msfvenom-payload.md
│ ├── 02-multi-handler.md
│ ├── 03-reverse-tcp.md
│ ├── 04-bind-tcp.md
│ ├── 05-meterpreter.md
│ └── 06-post-exploitation.md
│
└── screenshots/
├── 01-msfvenom-payload.png
├── 02-multi-handler.png
├── 03-reverse-tcp.png
├── 04-bind-tcp.png
├── 05-meterpreter.png
└── 06-post-exploitation.png
- Metasploit Framework
- msfvenom
- Payload concepts
- Multi/Handler
- Reverse TCP
- Bind TCP
- Meterpreter
- Linux enumeration
- Network enumeration
- Post-exploitation
- Security documentation
- Evidence collection
This practical demonstrates the relationship between payloads, listeners, communication direction, sessions, and post-exploitation.
The major concepts learned are:
Payload
↓
Listener
↓
Connection
↓
Session
↓
Enumeration
↓
Security Assessment
Understanding these components provides a foundation for analyzing how exploitation frameworks establish and manage sessions during authorized penetration testing.
This project is intended strictly for authorized cybersecurity education and laboratory testing.
The techniques, tools, payloads, and commands documented in this repository must only be used against systems for which explicit authorization has been obtained.
No unauthorized systems are targeted.