Metasploit › Module 9 › Lesson 4
Post Lab
search/info/show options on allowed post module — SESSION $LAB only per brief.
Visual · msf_post_lab
Lab: post literacy without persistence. Original Cyberlium.
Opening
One allowed post module — then snapshot revert.
With $LAB session active per brief: search post, info an allowed gather module, show options, set SESSION to your lab id, run if brief permits — otherwise document options only. No credential dumping beyond lab creds. Revert VM after.
1. Module selection
Pick from brief allowlist.
info confirms data touched.
Command guide
Try these commands — Module selection
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Post modules — https://docs.rapid7.com/metasploit/working-with-post-modules/ Exploit-DB — https://www.exploit-db.com/
═══ INSTALL ═══
Linux (Debian/Ubuntu): Kali: preinstalled, or: sudo apt install metasploit-framework
macOS: Prefer Kali/Linux VM — brew install metasploit (heavy)
Windows: Use Kali VM or WSL with metasploit-framework — not raw Windows host
═══ LINUX / macOS ═══
Command — copy this
msfconsole -q -x 'search type:post platform:linux; info 0; exit' 2>/dev/null || echo 'Review post module docs — snapshot revert after lab'
Primary tools to practice this lesson: msfconsole. Reference sites: Post modules (https://docs.rapid7.com/metasploit/working-with-post-modules/); Exploit-DB (https://www.exploit-db.com/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. SESSION binding
set SESSION from sessions -l.
Verify $LAB VM label.
3. Teardown
No persistence planted.
Kill session, revert snapshot, secure output.
4. What you ship: post lab notes
search/info/show options + SESSION id + revert confirmation.
5. What you record before the next lesson
Redacted post lab path.
6. Wrong vs right: stranger hosts vs YOUR lab VM
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Run hashdump on a domain controller you do not own.
Right
Brief-bound post literacy. Next: quiz.
Mission: post lab
1) search/info allowed post module. 2) show options; set SESSION for $LAB. 3) Run if allowed; revert snapshot; no persistence.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Which post modules are allowlisted?”
Knowledge Check
APPLY: Post lab requires:
Multiple choice
Knowledge Check
APPLY: True or False: Persistence is part of this lab.
True or False
Knowledge Check
APPLY: After post lab:
Multiple choice