Description
Detect Metasploit exploit/multi/handler listeners and other reverse payload handlers by fingerprinting their wire behavior. Several techniques are combined:
* Staged reverse handlers "talk first": on connect they transmit the stage with a 4-byte length prefix whose endianness identifies the family - little-endian (pack 'V') for Windows native (metsrv) - big-endian (pack 'N') for Python/PHP/Java/Android - Linux/OSX native stagers send the raw machine-code stage with no length prefix, and unix staged shells send a tiny execve("/bin/sh") shellcode. * Reverse command shells "talk first" with an "echo <token>" probe. Echoing the token back marks the shell valid and can capture an operator's AutoRunScript / follow-up commands. * reverse_http(s) Meterpreter handlers answer any unknown URI with the default "It works!" body and Server: Apache. HTTP servers (web_delivery, fetch handlers, exploit module servers) return a distinctive 404 page. * reverse_tcp_ssl handlers stage over TLS; an SSL probe reads the stage/echo through the handshake. * reverse_udp handlers send the stage in response to any datagram, so an optional UDP probe (SCAN_UDP) catches them too.
Transports that are not TCP/UDP (reverse_sctp, reverse_named_pipe/SMB) and silent stageless payloads that wait for the client cannot be fingerprinted and appear as a silent open port.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/msf/handler/detectmsf undefined(detect) > show actions ...actions...msf undefined(detect) > set ACTION < action-name >msf undefined(detect) > show options ...show and set options...msf undefined(detect) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub