MSFvenom Cheat Sheet
Enhanced, practical msfvenom reference covering payload generation across all platforms, staged vs stageless selection, encoding, encryption, bad-character handling, template injection, advanced handlers, and real-world delivery techniques.
Understanding Payload Types
MSFvenom produces two fundamental payload categories. Choosing correctly impacts detection, reliability, and network behavior.
| Type | Naming Pattern | Size | Behavior | Best For |
|---|---|---|---|---|
| Staged | .../reverse_tcp (no _reverse prefix) | Small | Delivers a tiny stager; Metasploit uploads the full stage after initial connection | Size-constrained exploits, buffer overflows, limited bandwidth |
| Stageless | ..._reverse_tcp (underscore prefix) | Large | Complete payload in one shot; no second-stage download | Production ops, stable C2, evading network inspection |
Key rule: Prefer stageless unless you have a specific reason (exploit size limits, known firewall constraints). Stageless eliminates the stager→stage roundtrip, reducing network artifacts and failure points.
Discovery & Reconnaissance Commands
Before generating any payload, enumerate what's available. Metasploit updates frequently — always check your local installation.
Tip:
--list-optionsreveals hidden configurable variables (exit functions, retry counters, custom headers for HTTP/S) that dramatically improve reliability.
Payload Naming Quick Reference
MSFvenom payload names follow a predictable structure. Understanding it helps you guess valid payloads before listing them.
| Component | Examples |
|---|---|
platform | windows, linux, osx, android, java, php, python, cmd |
arch | x86, x64, aarch64, armle, mipsbe, mipsle |
payload | meterpreter, shell, meterpreter_reverse |
transport | tcp, http, https, tcp_dns, tcp_rc4 |
Naming Gotchas:
- ▹Staged:
meterpreter/reverse_tcp— note the slash between payload and transport - ▹Stageless:
meterpreter_reverse_tcp— note the underscore replacing the slash - ▹
reverse= callback to attacker;bind= listener opens on target
Windows Payloads
::Reverse TCP (Staged & Stageless)
::Reverse HTTP/HTTPS (C2-Friendly, Firewall Evasive)
Handler note for HTTPS: Set
HandlerSSLCert /path/to/cert.pemandStagerVerifySSLCert false(or provide the CA cert for true verification).
::Named Pipe & Domain Fronting Transports
::PowerShell-Based Delivery
::Office Document & HTA Vectors
::DLL Outputs (for Sideloading / Hijacking)
::Bind Shells (Target Opens Listening Port)
::Service & MSI Formats
Linux Payloads
::Reverse TCP (Staged & Stageless)
::Lightweight Shell Payloads (Non-Meterpreter)
When size matters or Meterpreter isn't needed:
::Bind Shells
::ARM & MIPS (Embedded/IoT)
macOS Payloads
Android Payloads
Embedding tip: The
-xtemplate method requires the original APK to not have strong integrity checks. Some modern apps will crash if tampered with. Test thoroughly.
Web Application Payloads
::PHP
WAF evasion: Many WAFs flag Meterpreter magic bytes. Prepend benign PHP code:
echo '<?php // Copyright 2026' > shell.php && cat payload.php >> shell.php
::Java (JSP / WAR)
WAR deployment: Upload via
/manager/htmlon Tomcat, then access/app/(WAR name becomes the path).
::ASP / ASPX
::ColdFusion
Scripting & Interpreter Payloads
These generate code for interpreted languages — useful when you have code execution but can't drop binaries.
Execution oneliners:
- ▹Python:
python3 -c "$(cat rev.py)"orpython3 rev.py- ▹Ruby:
ruby rev.rb- ▹Node:
node rev.js- ▹Perl:
perl rev.pl- ▹Lua:
lua rev.lua
Encoders, Evasion & Anti-Virus
::Important Reality Check
Encoding helps with bad-character avoidance and minor signature obfuscation, but it is not a reliable AV/EDR evasion technique on modern endpoints. Combine encoding with other techniques for real operations.
::Listing & Selecting Encoders
::Encoder Selection by Goal
| Goal | Encoder | Notes |
|---|---|---|
| Polymorphism (signature evasion) | x86/shikata_ga_nai | Changes every generation; effective against static signatures |
| Bad char: null bytes | x86/xor_dynamic | Produces null-free output |
| CMD/batch delivery | cmd/powershell_base64 | Base64 wraps for PowerShell cradles |
| Size constraint | x86/countdown | Very small decoder stub |
| Modern x64 binary | x64/xor_dynamic | Good balance of size and effectiveness |
Encryption Options
MSFvenom supports encrypting the payload body. The handler decrypts automatically. Useful when your dropper/loader expects encrypted input.
Warning: Encryption may behave differently with staged payloads. Always test the specific payload + format + handler combination before operational use.
Bad Characters & Restrictions
Bad characters are bytes that break your delivery vector (null terminators in string functions, newline in HTTP headers, etc.).
::Specifying Bad Characters
::Common Bad Character Sets
| Scenario | Bad Characters | Why |
|---|---|---|
| String buffer overflow | \x00 | Null terminator ends string copy |
| HTTP header injection | \x00\x0a\x0d | Null, newline, carriage return break HTTP |
| Unicode buffer | \x00-\x2f | Many non-printable break wide-char functions |
| URL parameter | \x00\x20\x26\x3d | Null, space, &, = break URL parsing |
::NOP Sleds (Buffer Overflows)
Template Injection & Trojanization
Inject payload into a legitimate executable. The original program still runs (if -k is used), reducing suspicion.
::Basic Template Injection
::How Template Injection Works
| Flag | Behavior |
|---|---|
-x <file> | Use <file> as the executable template |
-k | Keep template functionality — payload runs in a new thread; original exe executes normally |
(no -k) | Payload replaces the entry point; original program does not run |
Operational note: Signed binaries lose their signature after template injection. The file will show as unsigned, which can trigger SmartScreen/AppLocker.
Shellcode Generation & Injection
Generate raw shellcode for custom loaders, process injection, or exploit development.
::Advanced Shellcode Options
::EXITFUNC Reference
| Value | Behavior | Use Case |
|---|---|---|
process | Terminate the entire process when payload exits | Standalone executables |
thread | Terminate only the payload thread; host process continues | DLL injection, thread-based injection |
seh | Uses Structured Exception Handler to return | Exploit development (stack/heap overflows) |
none | No explicit cleanup | Specialized injection scenarios |
Advanced Handler Configuration
The handler (exploit/multi/handler) must match your payload settings exactly.
::Basic Handler Setup
::Critical Handler Options
::HTTP-Specific Handler Options
Multi/Redirect Handlers
Route callbacks through redirectors to protect your team server IP.
::DNS Redirector
::CDN / Domain Fronting
::SSH Tunnel Handler
Staged vs Stageless — When to Use Which
| Factor | Staged | Stageless |
|---|---|---|
| Binary size | Smaller (1-5 KB typical) | Larger (100-300 KB typical) |
| Network reliability | Requires 2 connections; fragile on unstable networks | Single connection; more resilient |
| Firewall/Proxy | Needs direct socket; may fail through strict HTTP-only proxies | HTTP/S variants traverse most corporate proxies |
| Detection | Stager signature in memory; 2-stage artifact | Full payload in initial binary; single artifact |
| Meterpreter features | Full feature set (loaded on stage) | Full feature set (embedded) |
| Use case | Exploits with size limits (BOF, constrained RCE) | Phishing, USB drops, scheduled tasks, services |
| Naming | meterpreter/reverse_tcp | meterpreter_reverse_tcp |
Decision flow: If you have a buffer overflow with 100 bytes of space → staged. If you're sending a phishing email attachment → stageless. If you're unsure → stageless.
Real-World Delivery Techniques
::Email Phishing Attachments
::Web Delivery (No File Drop)
::USB / Physical Drop
::LOLBAS / Living Off The Land
Troubleshooting & Common Errors
::Error: Payload generation failed / Invalid payload name
::Error: Invalid format / Format not found
::Error: Handler receives no callback
| Check | Action |
|---|---|
| LHOST reachable? | nc -zv <LHOST> <LPORT> from target network |
| Firewall on target? | netsh advfirewall firewall or iptables -L |
| Handler running? | msf6 > jobs — handler should show as active |
| Payload matches handler? | Check PAYLOAD name character-for-character |
| Staged vs Stageless mismatch? | Staged payload needs staged handler; stageless needs stageless handler |
| HTTPS cert issues? | Try with StagerVerifySSLCert false first |
::Error: AV detection immediately
- ▹Don't rely on msfvenom encoding alone for AV evasion
- ▹Use custom loaders with process injection (VirtualAlloc → WriteProcessMemory → CreateRemoteThread)
- ▹Consider in-memory execution (PowerShell reflection, .NET assembly loading)
- ▹Sleep/obfuscation techniques before payload execution
- ▹Sign your binary with a valid code signing cert where possible
::Checking Generated Payload Details
Quick Reference Tables
::Output Formats
| Format | Platform | Use Case |
|---|---|---|
exe | Windows | Standard Windows executable |
exe-service | Windows | Windows service executable |
exe-small | Windows | Smaller executable (limited features) |
dll | Windows | Dynamic link library for sideloading |
msi | Windows | Windows installer package |
msi-nouac | Windows | MSI that bypasses UAC prompt |
elf | Linux | Standard Linux executable |
macho | macOS | Standard macOS executable |
apk | Android | Android application package |
jar | Java | Java archive (cross-platform) |
war | Java web | Web application archive (Tomcat/JBoss) |
jsp | Java web | JavaServer Pages |
asp | Windows web | Classic ASP |
aspx | Windows web | ASP.NET web form |
php | PHP web | PHP script |
vba | Windows | Visual Basic for Applications macro |
vbs | Windows | VBScript |
hta-psh | Windows | HTML Application with PowerShell |
ps1 | Windows | PowerShell script |
raw | Any | Raw shellcode bytes |
c | Any | C byte array |
csharp | Any | C# byte array |
python | Any | Python byte array |
js_be | Any | JavaScript byte array |
hex | Any | Hexadecimal string |
::Architecture Flags
| Architecture | Platforms | Notes |
|---|---|---|
x86 | Windows, Linux | 32-bit Intel/AMD; widely compatible |
x64 | Windows, Linux, macOS | 64-bit; preferred for modern systems |
aarch64 | Linux, macOS | ARM 64-bit (Apple Silicon, ARM servers) |
armle | Linux, Android | ARM 32-bit little-endian (Raspberry Pi, mobile) |
mipsbe | Linux | MIPS big-endian (routers, embedded) |
mipsle | Linux | MIPS little-endian (some embedded) |
::Common LHOST/LPORT Scenarios
| Scenario | LHOST Value | LPORT Value | Notes |
|---|---|---|---|
| Direct LAN | Your LAN IP (e.g., 192.168.1.10) | Any free port | Simplest; works on same network |
| Public VPS | Public VPS IP/domain | 443 or 8443 | Register a domain for legitimacy |
| CDN Front | CDN domain (e.g., abc.cloudfront.net) | 443 | Use HttpHostHeader for backend |
| SSH tunnel | localhost or tunneled port | Tunnel local port | Forward via ssh -R |
| DNS redirect | Redirector domain | 443 | Socat/nginx on redirector forwards to TS |
Sources & Further Reading
- ▹Metasploit Unleashed — Free Metasploit course: https://www.offensive-security.com/metasploit-unleashed/
- ▹MSFvenom Official Documentation — https://docs.metasploit.com/docs/using-metasploit/basics/how-to-use-msfvenom.html
- ▹Metasploit Payloads Reference — https://github.com/rapid7/metasploit-framework/wiki/How-to-use-msfvenom
- ▹LOLBAS Project — Living Off The Land binaries: https://lolbas-project.github.io/
- ▹PayloadsAllTheThings — Comprehensive payload collection: https://github.com/swisskyrepo/PayloadsAllTheThings
- ▹Staged vs Stageless Deep Dive — https://docs.metasploit.com/docs/using-metasploit/basics/understanding-payloads.html
NetExec (nxc) Cheat Sheet
Reference for NetExec (nxc). Covers multi-protocol enumeration (SMB, LDAP, WinRM, MSSQL, RDP, WMI, SSH, VNC, FTP), safe password spraying, credential harvesting, BloodHound CE collection, execution methods, and detection telemetry.
File Transfer Techniques
Cheatsheet for moving files across Linux, Windows, restricted shells, and inspected networks. Built for CTF players, bug bounty hunters, and internal pentesters.
Linux Privilege Escalation: Basics & Exploitation
Kill chains for sudo abuse, SUID/capabilities, PATH hijacking, cron exploitation, NFS no_root_squash, and runtime process hunting with pspy. Built for Red Teamers and CTF players who skip the theory.
