Description
Upgrades an authenticated SMB session to a Meterpreter session using PsExec techniques. This module uploads a service-wrapped executable payload to the ADMIN$ share via the existing authenticated SMB connection, then creates and starts a Windows service that executes the payload. This mirrors the approach used by exploit/windows/smb/psexec. Requires administrative privileges on the target.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use post/windows/manage/smb/to_meterpretermsf undefined(to_meterpreter) > show actions ...actions...msf undefined(to_meterpreter) > set ACTION < action-name >msf undefined(to_meterpreter) > show options ...show and set options...msf undefined(to_meterpreter) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub