Hunting Metasploit
Last updated
Last updated
Metasploit is a commonly used exploit framework for penetration testing and red team operations
Look for suspicious ports such as 4444
and 5555
which is used by Metasploit by default
This method of hunting can be applied to other various RATs and C2 beacons
Use Get-WinEvent
along with XPath
queries, filtering out events with NetworkConnect
and DestinationPort
https://attack.mitre.org/software/