
Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign workflows, Hail Mary, sessions, report export, and team mode.
Hayduk is a free, open-source Metasploit GUI for authorized penetration testing. It brings the Armitage workflow to your browser: map hosts, browse modules, manage Meterpreter and shell sessions, and export campaign reports.
Download one binary. Run it. Connect to Metasploit. No Java, Go, or Node.js installation is required to run a release binary. The browser UI is included.
Hayduk connects to a separate Metasploit Framework instance through msfrpcd. It does not bundle Metasploit.
Download the latest release · Quickstart · Try the Docker lab · Team mode

Interface shown with illustrative campaign data.
You need a Hayduk release binary, a browser, and a running Metasploit Framework instance. For workspace features such as hosts, services, credentials, and loot, Metasploit also needs a connected database.
The steps below assume Hayduk and Metasploit run on the same machine. If you need a ready-made Metasploit setup with a database and disposable targets, use the Docker lab.
Open the latest release and choose the archive matching your operating system and processor. Extract the archive into a folder. There is no Hayduk installer or separate UI setup.
On the machine running Metasploit, open a terminal and run:
msfrpcd -P 'yourpassword' -S -f -a 127.0.0.1 -p 55553
Replace yourpassword with your own password. Keep this terminal open. This command binds RPC to localhost on port 55553; -S disables SSL for this local connection.
If you already run msfrpcd, use its existing connection settings instead of starting another instance.
Open another terminal in the extracted folder.
Linux and macOS:
./hayduk
Windows PowerShell:
.\hayduk.exe
Hayduk opens the UI in your browser. If the browser does not open, copy the full URL printed in the terminal, including ?token=.... The port is assigned automatically.
In Connect to msfrpcd, enter the settings from step 2:
| Field | Value |
|---|---|
| Host | 127.0.0.1 |
| Port | 55553 |
| User | msf |
| Password | The password you set above |
| use SSL | Unchecked |
Click Connect. A cold Metasploit instance can take about half a minute to respond; connection progress appears in the dialog.
Keep Hayduk running while you use the UI. Press Ctrl+C in its terminal to stop it.
Use a system or network you are authorized to test. Scans run from the connected Metasploit instance, so targets must be reachable from that machine.
Click a module to configure it. Right-click hosts, sessions, table rows, and modules in the tree to open their action menus.
Use the campaign summary cards to open hosts, services, sessions, or credentials. Discover hosts, Scan services, and Export report are also available directly above the network map.
The network map adapts host columns to the available canvas. Choose Focus to expand the map and host inspector. Arrange hosts replaces saved positions with an automatic layout. Host cards show open service counts and access state; violet paths identify pivot routes.

Demo uses illustrative campaign data.
| Capability | What you can do |
|---|---|
| Network topology | Explore adaptive subnet groups, host service counts, and pivot routes. Drag hosts, zoom, or expand the map in Focus mode. |
| Metasploit modules | Browse the module tree, inspect reliability ranks, configure options, and select payloads. |
| Campaign workflows | Discover hosts, scan services, and find exploit candidates matching known services. |
| Session management | Interact with Meterpreter and shell sessions, upgrade shells, and terminate sessions. |
| Credentials and loot | Review workspace data and use recovered credentials in login workflows. |
| Hail Mary | Launch matching exploits against selected hosts, with paced launches and an event log. |
| Reporting | Export a self-contained HTML report for campaign review and client delivery. |
| Team mode | Share a campaign with multiple operators on a trusted network. |

Graph focus mode with illustrative campaign data.
The repository includes a disposable Metasploit lab with a database and optional target containers. Run it to try the workflow from the demo against live targets.
You need Git, Docker, and Docker Compose. Run these commands from a shell that supports the repository's .sh scripts:
git clone https://github.com/jolovicdev/hayduk.git
cd hayduk
scripts/msf/up.sh --with-vulnbox
The script prints the target container IP addresses when the lab is ready. Start your downloaded Hayduk binary and connect with Host 127.0.0.1, Port 55553, User msf, Password testpass123, and use SSL unchecked. Use a printed target IP for your first scan.
To start only Metasploit and its database, run scripts/msf/up.sh without --with-vulnbox.
When finished, run this from the repository root. It removes the lab containers and their volumes, including lab database data:
scripts/msf/down.sh
Run the downloaded binary with a specific interface address that your operators can reach: