Learn the Metasploit Framework inside out (Udemy.com)

This course structure is based on the PTES. You'll learn Metasploit, its limits, and how to work around them

Created by: Adriano Gattabuia

Produced in 2018

icon
What you will learn

  • You will have a solid understanding of the Metasploit framework and how to work around its limitations.
  • You'll also have the right frame of mind to carry out penetration tests efficiently and effectively.

icon
Quality Score

Content Quality
/
Video Quality
/
Qualified Instructor
/
Course Pace
/
Course Depth & Coverage
/

Overall Score : 94 / 100

icon
Course Description

This course will cover all of the fundamental aspects of the Metasploit framework, tying a subset of the phases of the Penetration Testing Execution Standard (PTES) methodology to the course structure.

These will be specifically information gathering, vulnerability assessment, exploitation and post-exploitation.
The course also goes beyond the basics by dealing with social engineering, privilege escalation, antivirus evasion, persistent backdoors, trojanizing executable files, remote desktop, web penetration testing, port forwarded reverse shells, the Beef-XSS Framework, event log management.

To follow this course you will need to be confident using generic software programs, know the basics of the Linux command line and a little of system administration.
If something isn't clear or doesn't work on your system you can always hit me up and we'll solve the problem.
Concerning hardware requirements: a host machine with at least 8 GB of RAM with a moderately fast processor, 70 GB of hard-drive space for the vulnerable virtual machine and other 30GB for the Kali VM is a good setup to have, but not mandatory: you can also alternatively install the vulnerable machine on another PC in your home network and work with Kali on your main machine.
The course is laid out in 7 main sections:
  • Section 1: setup of our environment and introduction to the Penetration Testing Execution Standard (PTES), which is a state of art methodology to carry out a penetration test. Other Metasploit variants like the Metasploit framework on Windows, the Metasploit community edition and Armitage will be covered.
  • Section 2: fundamental commands of Metasploit and how it works, how to automate repetitive tasks, how to run exploits and Metasploit modules.
  • Section 3: information gathering on the target machine with nmap and the other tools available in Metasploit to check which services are installed and effectively map the the attack surface.
  • Section 4: vulnerability assessment. We'll check which of the services fingerprinted are likely to be vulnerable. We'll learn how to install the Nessus vulnerability scanner and integrate it with Metasploit to populate its workspace.
  • Section 5: finally exploit of seven Metasploitable3 services using Metasploit exclusively, web penetration testing will also be covered.
  • Section 6: exploiting services via Social Engineering. We'll mainly create vectors for Social Engineering engagements, unsuspecting payloads for the victim to execute on their machine to obtain remote command execution. We'll create trojanized files, we'll greatly lower the antivirus detection rate and we'll use the Beef-XSS Framework together with Metasploit to deliver more complex attacks.
  • Section 7: monitoring the user on his machine, logging his keyboard activity, performing privilege escalation, generating persistent backdoors and log management.
  • Section 8: the course outro and credits.
Who this course is for:
  • Anyone interested in penetration testing who would like to learn the Metasploit Framework inside out and learn how it can be integrated with other pentesting tools.

icon
Instructor Details

placeholder

I've been studying for a lifetime and have been working as both a software developer and as a penetration tester for the past six years.
I've started teaching through the Prime Radiant Security project at the start of 2018.
I have devoured tons of video courses and books in my life, I'm here to share an extension of the knowledge born out of real life problems I have managed to solve, in the most efficient way possible.
I believe that theory and practice should be carefully balanced in order to avoid further research to understand specific subjects on one hand and to avoid boredom or frustration on the other.

icon
More elastic search courses

Apache Kafka Series - Learn Apache Kafka for Beginners v2

$11.99

Spring Boot Microservices and Spring Cloud

$11.99

The Flask Mega-Tutorial (Python Web Development)

$11.99

Part 2: AWS Certified Solutions Architect (and CD,SO) - 2021

$11.99

Using Elasticsearch and Kibana

$11.99

AWS Certified Data Analytics Specialty - Hands On!

$11.99

icon
Reviews

4.7

10 total reviews

5 star 4 star 3 star 2 star 1 star
% Complete
% Complete
% Complete
% Complete
% Complete

By George Dimitrov

Great

By Josh McMahon

Great course!

By Oswaldo Ríos

Muy buen contenido, aprendí cosas para utilizar después en pentests, en algunas ocasiones se va muy rápido el instructor, pero está bien, el curso dura "poco" pero al estar haciéndolo tardas mucho más tiempo que las 4 horas que dice tener.

Muy recomendable :)

This was an AWESOME course! I look forward to more by Adriano.

really love this course.

I knew a bit about the MSFCONSOLE but this has gone on to a new level and really has helped put it all into perspective. Better than trying to structure your own lessons from youtbe. videos alone. Thank you.

I came to refresh on a tool, Metasploit, and this course also presents the necessary mindset to be most effective. Enjoyed and recommend!

Muy buen contenido, aprendí cosas para utilizar después en pentests, en algunas ocasiones se va muy rápido el instructor, pero está bien, el curso dura "poco" pero al estar haciéndolo tardas mucho más tiempo que las 4 horas que dice tener.

Muy recomendable :)

I really appreciated the how straight forward this tutorial was. It rarely had a command that was not explained and otherwise the instructor pointed the student into the right direction versus spending some time explaining every detail. The most important thing I wanted to learn from this course wasn't metasploit but rather the thought process behind using it. This instructor showed me his though process and I feel that I have a deeper understanding of the pen testing workflow. Thanks prime! I'll look for you on youtube!

Topics are not explained properly, i was expecting a better explanation of the topics.